Home / Companies / Bugcrowd / Blog / September 2017

September 2017 Summaries

7 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Establishing a public vulnerability disclosure channel allows customers to proactively manage security risks and demonstrate their commitment to fixing vulnerabilities in their software. Bugcrowd's Crowdcontrol platform enables this by providing an easy-to-use interface for accepting vulnerability disclosures from researchers worldwide, while also harnessing the power of Bugcrowd's vulnerability triage and validation services. The new Embedded Submission Form feature streamlines the process for organizations to launch their own disclosure program by hosting it directly on their website, making Crowdcontrol the most flexible and powerful offering for public vulnerability disclosure programs.
Sep 27, 2017 402 words in the original blog post.
The new CEO of Bugcrowd is excited to join a brilliant team and help steer the ship through the next phase of growth, building on the pioneering work in crowdsourced cybersecurity and security testing. The company's focus on interconnectivity at scale requires security assessment and remediation at scale, leveraging the collective skills of thousands of security researchers to address critical software vulnerabilities before adversaries can exploit them. Bugcrowd is expanding its lead in the market, with leading companies like MasterCard, Tesla, Atlassian, and Pinterest relying on it for managed bug bounty programs. The new CEO aims to contribute to the company's continued success and drive further market leadership and scale.
Sep 22, 2017 1,365 words in the original blog post.
The SecureDrop engineering team welcomes contributions from security researchers to ensure the whistleblowing process is as safe as possible for sources. Testing by external security researchers helps minimize risk, and we're encouraging ethical behavior through our bug bounty program hosted by Bugcrowd, offering rewards up to $2,500 for security issues found in SecureDrop. This month's malware attack highlighted the need for responsible security research, and we've clarified unacceptable behavior to ensure users are protected while still allowing creative attacks like the one demonstrated this month. We're also accepting security issues through PGP-encrypted email if preferred, and our bug bounty program is open to researchers who want to alert us to vulnerabilities in SecureDrop technology stack.
Sep 19, 2017 554 words in the original blog post.
Ibotta has expanded its partnership with Bugcrowd to improve its security strategy and protect user accounts through crowdsourced vulnerability testing. This partnership supports the company's core values of integrity and out hustle by leveraging the skills of over 60,000 trusted security researchers. Ibotta uses Bugcrowd's private bug bounty program to identify and patch potential exploits in its codebase, allowing it to maintain speed while prioritizing user security. The partnership has shown immediate results, with previous one-time programs finding exploitable vulnerabilities that were rapidly patched, and ongoing programs providing a fresh set of eyes on the company's security issues every week.
Sep 18, 2017 746 words in the original blog post.
Bugcrowd has announced its August 2017 Hall of Fame winners, recognizing top performers mongo and sandeepv, as well as a private user who rounded out third place. To incentivize their performance, the three researchers have received bonuses totaling $4,000. Submitting high-severity bugs with critical security impacts can earn significant kudos points and even lead to invitations to private bounty programs.
Sep 07, 2017 225 words in the original blog post.
We're excited to announce our bug bounty program is moving from private to public, opening up its doors to over 60,000 registered and verified Bugcrowd security experts worldwide to detect issues on behalf of Dash and be rewarded in bug bounty payments. We take the security and quality of our software seriously due to past vulnerabilities like the $50 million USD stolen in The DAO hack. A crowdsourced approach to security assessment alleviates the pain point of demand for security professionals outweighing supply, harnessing the power of the Crowd to scale and optimize vulnerability assessment programs. With rewards ranging from $100 to $10,000, we invite top researchers to "hack" the Dash blockchain and reward them fairly for identifying vulnerabilities. Our goal is a safer, stronger network, and working with Bugcrowd and funding the best bug bounty program in cryptocurrency is an example of our commitment to meeting high security standards.
Sep 06, 2017 373 words in the original blog post.
The Car Hacking Village (CHV) at DEF CON hosts a Capture the Flag (CTF) hacking competition that attracts new people to automotive security. The event has grown in popularity, with over 150 registrants and nearly 50 teams participating this year. CHV uses cloud-based infrastructure, specifically AWS Lambda and API Gateway, to manage the competition, which reduces costs compared to traditional server-based deployment. This approach is suitable for lightweight web applications like CTFd, allowing for cost-effective usage even during peak loads. The event's organizers enjoyed the challenge of deploying the infrastructure and had a better experience than last year.
Sep 01, 2017 751 words in the original blog post.