Home / Companies / Bugcrowd / Blog / June 2017

June 2017 Summaries

8 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
The crowdsourced security movement has experienced significant growth since its initiation in 2012, with Bugcrowd's annual "State of Bug Bounty Report" showcasing this growth. The report highlights a threefold increase in enterprise adoption and demonstrates the effectiveness of the platform in delivering successful interactions between white-hat hackers and traditionally risk-averse businesses. The platform was designed to serve the time-strapped enterprise user and has delivered over 55,000 valid submissions processed through its Crowdcontrol platform to companies across various industries and technology adoption spectrums. Bugcrowd's goal of spreading the crowdsourced security concept beyond traditional tech companies has been achieved, with a focus on delivering results to the market to make this possible.
Jun 30, 2017 393 words in the original blog post.
Our latest Spring Product Release improves vulnerability management for enterprises and supports the long-term success of both security teams and researchers, as they increasingly adopt crowdsourced application security testing models like bug bounties. The platform aims to scale to meet changing enterprise needs while providing an intuitive experience for both organizations and security researchers. The release introduces comprehensive reporting with actionable insights and improved vulnerability management workflow for enterprises, along with updates to the researcher dashboard that provide real-time data to enhance performance. Key features include customizable reporting, powerful enterprise integration, and bug bounty thought leadership initiatives such as open sourcing the Vulnerability Rating Taxonomy on GitHub. These enhancements aim to drive success for both customers and researchers in the bug bounty program.
Jun 22, 2017 581 words in the original blog post.
Bugcrowd is committed to delivering a radical cybersecurity advantage by providing top-notch platform and tools for security researchers to find vulnerabilities in applications, networks, and devices. The company believes that education is key to making the Internet a safer place and has been actively educating developers, researchers, and the public about hacking and internet security through various initiatives. Recently, Bugcrowd collaborated with the Wickr Foundation to host an event where kids aged 7-17 learned about hacking, lockpicking, and social engineering, followed by an educational bus ride to the UC Berkeley CyberSecurity Center. At the center, attendees gained hands-on experience with soldering, lockpicking, and internet discovery tools, building their confidence and knowledge of technology. The event aimed to empower participants to protect themselves and their organizations from online threats, and it is likely that some of these educated individuals will join Bugcrowd's bug bounty program in the future, contributing to making the world a better place through cybersecurity.
Jun 21, 2017 428 words in the original blog post.
The company Bugcrowd has grown significantly over four and a half years, tripling in size in the past year alone. The team has evolved as an organization while maintaining its guiding principles and vision for the future of cybersecurity. A new website reflects this evolution, designed to connect business owners with hackers and provide a meeting place for these groups to share knowledge and work together to make the internet safer. The site features the company's own team members, customers, and researchers, showcasing the company's culture and personality. The updated design makes it easier for program owners and hackers to find the information they need, surfacing more content on the front page.
Jun 16, 2017 325 words in the original blog post.
This post originally ran on the (ISC)² blog on June 1, 2017: Since 2013, (ISC)² has been a partner of Bugcrowd, running a public bug bounty program and offering CPE credits to our members. Bugcrowd is a leading provider of crowdsourced security and bug bounty programs, connecting organizations with more than 50,000 independent security researchers to identify vulnerabilities. As an (ISC)² member, you can participate in Bugcrowd's bug bounty programs in exchange for CPE credits. The program encourages participation to hone security skills and contribute to a safe cyber world. To participate, sign up as a Bugcrowd researcher, find valid bugs, earn credits depending on vulnerability severity, and enter your ISC2 # into your profile settings. Members can earn up to 15 CPE credits annually, with the program providing constant security feedback for Bugcrowd and connecting them with the research community.
Jun 14, 2017 251 words in the original blog post.
Bugcrowd has announced its May 2017 Hall of Fame winners, with mongo taking the top spot and earning a $2,500 bonus for 1541 points. Jstnkndy came in second with 666 points, while a private account secured third place with 571 points. These researchers demonstrated exceptional skills in identifying high-severity bugs that pose critical security risks, such as remote code execution or privilege elevation. Their hard work and dedication will be rewarded with bonuses, and Bugcrowd looks forward to seeing the June Hall of Fame results.
Jun 09, 2017 218 words in the original blog post.
The management of vulnerability reports can be time-consuming for organizations, leading to the need for ease in triaging and validating incoming vulnerability findings. Bugcrowd provides customers with full-scale bug bounty support and services, including expert technical review and escalation of valid vulnerability submissions. The company's team of Application Security Engineers has broad industry knowledge and real-world experience in managing bug bounties and ensuring success. A managed crowdsourced application security testing approach is an efficient and affordable solution due to the prodigious shortage of resources in the cybersecurity space. Bugcrowd has experienced significant growth, with a 67% increase in vulnerability submissions and a 77% increase in bug bounty programs on its platform. The company's team facilitates hundreds of managed bug bounties, escalating high-priority issues within hours and averaging triage within a business day.
Jun 08, 2017 533 words in the original blog post.
It's an exciting time for information security, with black hats attacking more websites and creating new threats, but the security community is rising to meet these challenges. The demand for security professionals has increased, but so has the supply, with a growing number of new generations of security researchers, responders, and leaders coming from around the globe. In response, Centrify has launched a public bug bounty program with Bugcrowd, which will engage a crowdsourced team of over 50,000 security researchers to help improve its security. This move is part of a broader effort to consolidate the knowledge and creativity of the global security community, and to leverage this collective expertise to benefit organizations worldwide.
Jun 07, 2017 308 words in the original blog post.