July 2017 Summaries
6 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
The Bugcrowd community has more than doubled in size over the past year, growing from 26,782 to over 60,000 researchers, and this growth has led to an increasing need for education and professional development opportunities. The first Bugcrowd LevelUp conference was held recently, bringing together 20 expert hackers who shared their knowledge with peers and a global audience of over 700 people. The event featured keynote presentations from Bugcrowd's founder and CEO Casey Ellis, as well as Head of Trust & Security Jason Haddix, who discussed various topics including bug hunter methodology and security best practices. The conference was well-received by the community, with many attendees praising its quality and value, and Bugcrowd is committed to continuing to support and educate the growing security researcher community.
Jul 21, 2017
311 words in the original blog post.
This week in Las Vegas will see some of the most prominent information security events take place, including BSides, Black Hat, and DEF CON. Bugcrowd will be present at all three events, showcasing its crowdsourced security testing capabilities for enterprises. The company's own team members will also be presenting several sessions on topics such as bug hunting, attack surface discovery, and car hacking. Additionally, Bugcrowd will host various events throughout the week, including a capture-the-flag event in partnership with the Car Hacking Village.
Jul 17, 2017
765 words in the original blog post.
The security industry is facing a resource shortage, with companies accelerating their cloud presence and growing API ecosystems, leading to an increase in bug bounty programs. Enterprise bug bounty adoption has reached an all-time high, with payouts exceeding $6 million and average payouts increasing to $451. The highest payouts are for hardware/IoT targets, while mobile applications offer the lowest. As programs mature, organizations must consider how to adjust their payout structures to avoid stalling or losing researcher participation. Companies like Apple are learning to manage pricing vulnerabilities effectively, reducing the risk of hackers selling serious vulnerabilities to other companies. A wide scope with interesting targets is crucial for attracting talent and staying competitive in the bug bounty market.
Jul 14, 2017
497 words in the original blog post.
Atlassian has launched its first public bug bounty program, expanding existing programs for Trello and StatusPage to include JIRA and Confluence Cloud, with plans to add more products in the future. The new program uses Bugcrowd, a provider of crowd-sourced security testing, to provide nearly 60,000 external cybersecurity researchers to test Atlassian's products. These researchers use well-defined guidelines to perform their research, which is then shared through a standardized reporting mechanism and triaged by Bugcrowd's application security engineering team.
Jul 12, 2017
232 words in the original blog post.
The bug bounty model has seen significant growth in enterprise adoption, with the number of valid vulnerabilities exceeding 52,000 in 2017 and critical vulnerabilities increasing by 25% from 2016. The industry with the most critical vulnerabilities was leisure, travel, and tourism, while Europe reported the highest number. The average payout for critical vulnerabilities is now $1,776, with SQL Injection being the most reported type of vulnerability. This growth in vulnerabilities is attributed to the emergence of new systems such as IoT and automotive, which present additional security concerns. Managed bug bounty programs are becoming increasingly popular due to the need for quick time-to-action and the resources required to triage and validate incoming vulnerability findings. Companies like Bugcrowd are experiencing significant growth in collaborative interactions with their security teams, providing customers with full-scale bug bounty support and services that facilitate hundreds of managed bug bounties with tens of thousands of vulnerability reports.
Jul 07, 2017
493 words in the original blog post.
Bugcrowd has announced its top performers for June 2017, with mongo taking first place followed closely by Web_Plus and ahmedehane. To recognize their efforts, Bugcrowd is rewarding the top researchers with bonuses. High-severity bugs that pose significant security risks are particularly valued in the bug bounty program, not only offering bigger rewards but also potentially leading to invitations to private programs.
Jul 06, 2017
224 words in the original blog post.