August 2017 Summaries
7 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd has appointed Ashish Gupta as its new Chief Executive Officer, succeeding the company's founder. The appointment marks a significant milestone for the crowdsourced security testing platform provider, which has grown to over 100 employees and more than 60,000 researchers in its crowd. With this change, the founder will transition to Chairman of the Board and Chief Technology Officer, allowing him to focus on his vision for the business and its impact on the security industry. The new CEO brings a strong track record of executive experience and entrepreneurial spirit, aligning with Bugcrowd's mission to make the internet safer through innovative solutions that benefit many. This appointment is seen as an exciting development for Bugcrowd, with the team, Board, and founder expressing enthusiasm for Ashish's leadership and vision.
Aug 28, 2017
631 words in the original blog post.
The Bugcrowd team has released the latest version of their Vulnerability Rating Taxonomy (VRT) 1.2, which includes significant changes such as priority adjustments, new classifications for issues, and minor modifications to improve clarity and alignment with industry standards. The VRT has been packaged into a Ruby Gem, allowing developers to easily integrate it into their applications and workflows. The team encourages public feedback and welcomes questions and suggestions at [email protected].
Aug 09, 2017
322 words in the original blog post.
The Dash Bug Bounty program has launched privately on the Bugcrowd platform, where selected researchers are invited to study the Dash Core software for bug identification. The program will initially run privately and then be opened to the public, allowing any white-hat hacker or security researcher to participate. The bounties range from $100 to $10,000, with potential earnings of up to $15,000 for significant bugs. The program is funded by Dash Masternode Operators through the Dash Budget system, making it one of the best-funded bug bounty programs in the cryptocurrency industry. Other applications, such as CoPay wallet and Dash Evolution, may be added after consultation with the Core Team. The program is managed by Jim Bursch and coordinated with the Dash Core Team through Holger Schinzel, aiming to provide users with a safer and more secure network.
Aug 07, 2017
228 words in the original blog post.
BSidesLV was great this year, with conversations with security researchers and the debut of new shirt designs and collateral. At Black Hat, Bugcrowd had a booth featuring their design and product video, and held talks on the HUNT methodology at both events. The week also included RiskyBiz parties, Zerofox Level Up Black Hat Party, RockHouse 'House' Party, QueerCon Pool Party, and DEF CON's Car Hacking Village, which hosted a Capture the Flag event with a pick-up truck prize. Bugcrowd gave away 50K pieces of swag and had over 10K attendees across events. The week marked progress in building relationships between hackers and those who need their help, and Bugcrowd exists to facilitate this cooperation. The company's VP of Product discussed attack surface discovery at Recon Village, while Head of Trust and Security Jason Haddix teamed up with a security engineer to debut the HUNT methodology.
Aug 07, 2017
728 words in the original blog post.
The release of our newest integration with Slack now allows you to receive actionable bounty notifications immediately! Organizations are transitioning to agile software development and need to develop applications quickly, efficiently, and securely. Our platform, Crowdcontrol, enables companies to integrate bug bounty programs into their SDLC by integrating with everyday tools like Slack, ensuring organizations release secure software fast. Setting up the Slack integration is quick and easy, allowing notifications to be sent automatically as direct messages or channel posts, providing specific information and links to redirect users into Crowdcontrol. The integration aims to make it easy for teams to identify critical program activities and take action quickly.
Aug 04, 2017
237 words in the original blog post.
Bugcrowd has announced its July 2017 Hall of Fame winners, with ahmedehane taking top spot due to his performance on kudos programs. mongo and jstnkndy came in second and third respectively. To recognize their hard work, Bugcrowd is rewarding them with bonuses. High severity bugs that result in critical security impact are the most valuable, earning researchers significant points. Submitting these types of bugs not only rewards the researcher but also increases their chances of being invited to private bounty programs. The August Hall of Fame results will be announced soon.
Aug 02, 2017
242 words in the original blog post.
At Bromium, we believe that security should enable business productivity, not hinder it. We're using application isolation and control to protect against cyber attacks while improving productivity for end users. Our partnership with Bugcrowd allows us to identify security flaws through a bug bounty program, giving us access to world-class researchers and expert penetration testing. This effort aims to strengthen our security model by identifying weaknesses in hardware-enforced virtualization-based security and containing threats at the endpoint with real-time threat intelligence.
Aug 01, 2017
352 words in the original blog post.