Home / Companies / Bugcrowd / Blog / April 2017

April 2017 Summaries

10 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
This post explains how Sophos' Responsible Disclosure Program works with Bugcrowd, a platform that helps find and fix vulnerabilities in software products. The program rewards researchers for discovering and reporting security issues, with varying levels of reward based on the severity of the bug. Researchers must submit verifiable evidence to receive recognition or an award, and must use test accounts and systems to avoid affecting real users' security and privacy. Sophos runs a private invite-only bug bounty program with higher risk and complexity applications, and has formalized its approach with Bugcrowd to improve response times and streamline internal processes.
Apr 26, 2017 719 words in the original blog post.
The bug bounty lifecycle is an ongoing process that requires strategic planning and continuous learning. After launching a successful program, the work doesn't stop as it's essential to gather insights and make adjustments to maintain activity over time. Bugcrowd customers can leverage their Crowdcontrol platform to track valuable metrics such as spending, activity areas, and most common bugs. To stay competitive, bug bounty owners must be informed and adjust variables like scope, rewards, and marketing activity to keep the community engaged. This includes reevaluating the bounty scope, adjusting target-specific rewards, and implementing a 'crawl-walk-run' approach to reward increases. Effective communication with the researcher community is also crucial for maintaining relationships and encouraging focused testing. By iterating on their programs and staying attuned to changing needs, bug bounty owners can drive successful outcomes.
Apr 25, 2017 659 words in the original blog post.
Bugcrowd researchers will now receive their payments on Wednesdays instead of Fridays, starting May 10th, 2017. This change aims to provide better support during payday and speed up payment processing. The new payday schedule may result in some researchers receiving payments twice in one week, with a deadline of 12:00 am PT on Wednesday to avoid delays. Researchers can contact `[email protected]` for any questions or concerns about the updated schedule.
Apr 24, 2017 136 words in the original blog post.
We are proud to announce the most intuitive and efficient bi-directional JIRA integration for bug bounty programs! As attack surfaces continue to grow, organizations have turned to centralized software development tools like JIRA to track and manage software bugs. We recognize the importance of integrating vulnerabilities directly into SDLCs, providing automated workflows to streamline vulnerability management from validation to remediation. This release delivers unprecedented visibility and control over the development process, enabling faster quality product releases in one integrated platform. Our bi-directional JIRA integration allows customers to automatically generate JIRA tickets and track bugs through to remediation, ensuring accurate communication between application security and development teams. The setup process is simple and easy, with an intuitive custom field mapping process that delivers accurate and organized auto-ticket generation in JIRA.
Apr 20, 2017 523 words in the original blog post.
The concept of bug bounty programs has been gaining attention, with some questioning whether they can replace traditional penetration testing. The author argues that the current penetration testing model is flawed due to factors such as limited actor involvement, incentivization issues, and inability to keep up with agile development. In contrast, crowdsourced security assessments offered by bug bounty platforms like Bugcrowd aim to provide continuous security coverage and improve ROI, potentially replacing traditional pen testing in some instances. The author plans to address common misconceptions about the penetration testing space and gather perspectives from industry leaders and experts.
Apr 19, 2017 440 words in the original blog post.
The bug bounty lifecycle is a dynamic process that involves strategic planning, program launch, and continuous learning from the experience. Once a bug bounty program is launched, it receives submissions, which are then filtered and validated by experts to ensure only unique and relevant findings are reported. The program's findings are then prioritized and rewarded based on a standardized rating system, with payments made via secure channels. The process also integrates with development tools to facilitate remediation and upkeep of vulnerabilities. As the program continues, it provides valuable feedback for improvement and iteration over time.
Apr 18, 2017 497 words in the original blog post.
The success of any bug bounty program is determined by the pre-launch planning and logistics, which include determining business objectives, setting testing scope, setting initial reward ranges, and aligning internal resources. Effective planning and execution are crucial to attracting the right talent and attention to the program, as well as ensuring that internal resources are ready to implement and run the program. The bug bounty lifecycle is a fluid process that involves strategic planning, program launch, and learning from and iterating the program to achieve long-term success.
Apr 12, 2017 511 words in the original blog post.
The new researcher dashboard for Bugcrowd aims to help improve performance metrics by providing actionable data and tools for researchers to set personal goals, monitor progress, and climb the leaderboard for recognition and rewards. The dashboard is available to all researchers, from beginners to experts, and offers features such as monthly performance bonuses, bonus rewards, and private program access. By using this tool, researchers can continually challenge themselves, track their progress, and increase their chances of being invited to exclusive private programs.
Apr 06, 2017 555 words in the original blog post.
The traditional SDLC model has limitations when it comes to security, particularly in terms of timing and resource allocation. Many organizations have shifted towards building security practices throughout the SDLC to address these challenges. Bug bounties can support and enhance this approach by providing a creative and diverse testing pool, cost-effectiveness, and real-world security assessment in real-time. By identifying areas of highest risk, informing application security strategy and design, improving development training programs, and offering a dynamic vulnerability feedback loop, bug bounties can drastically improve processes and bolster any application security strategy.
Apr 04, 2017 574 words in the original blog post.
Bugcrowd has announced its March 2017 Hall of Fame winners, recognizing top performers arneswinnen, jstnkndy, and harisec for their exceptional work in identifying high severity bugs. These researchers demonstrated outstanding skills and dedication, earning significant bonuses for their efforts. The top three winners received $2,500, $1,500, and $1,000 bonuses, respectively. Bugcrowd encourages others to strive for similar success by submitting high-severity bug reports, which can lead to faster invitations to private bounty programs.
Apr 03, 2017 212 words in the original blog post.