Home / Companies / Bugcrowd / Blog / July 2018

July 2018 Summaries

3 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Bugcrowd has announced its June 2018 Hall of Fame winners, with todayisnew taking first place and Private User coming in second. The top performers will receive bonuses for their hard work, with todayisnew earning $2,500 and Private User earning $1,500. High-severity bugs that result in critical security impact can earn the most points, and submitting these types of bugs not only increases rewards but also increases chances of being invited to private bounty programs. Bugcrowd is highlighting one researcher, dr0v3r, who has made significant progress from February 2018 to early July 2018, going from ranked 254 to 86 with a 100% bug acceptance rate and an average priority rating of 2.62. Dr0v3r's experience began with playing DOS games on an ancient laptop and has since evolved into participating in bug bounties as a way to learn new technologies and have fun. When asked about his favorite type of vulnerability, dr0v3r mentioned SQLi, Blind XSS, authorization issues, and LFI, preferring to start with more challenging issues first. Dr0v3r's advice for other bounty hunters is to be efficient with their time, enjoy the challenge, and not burn themselves out.
Jul 12, 2018 625 words in the original blog post.
The number of vulnerabilities published in 2017 and 2018 has seen significant increases, with a 128% rise from last year to over 14,713 published vulnerabilities. The threat of data breaches continues to rise, with nearly every American being impacted by the loss of personally identifiable information (PII) data in recent years. Companies are struggling to keep up with the pace of new vulnerabilities, and resources are scarce. Bugcrowd has seen a 21% increase in total vulnerabilities from last year, with 20% of all valid vulnerabilities classified as critical. The platform's managed validation team prioritizes vulnerabilities based on business needs and scope, with response times under 24 hours for critical issues and an acceptance rate of over 92%. The payouts for valid vulnerabilities are also industry-leading, with more than 80% of all payouts exceeding $1,200. Crowdsourced security programs like Bugcrowd's leverage human intelligence at scale to deliver rapid discovery of high-risk vulnerabilities, providing organizations with the coverage necessary in today's modern software development lifecycle.
Jul 11, 2018 527 words in the original blog post.
The concept of "thinking like a hacker" is not limited to cybersecurity, but can be applied to various fields and achievements. Jonny Moseley, an Olympic skier, exemplifies this approach by innovating his training methods to achieve success in freestyle skiing. He hacked his way to the top by creating a custom training regime that focused on jumping fast and landing aerials. This mindset is also essential for Bugcrowd's approach to security, which harnesses human ingenuity and intelligence to find critical vulnerabilities at scale through crowdsourcing. By thinking like hackers, organizations can reduce risk while addressing staffing constraints, resulting in a higher return on investment compared to traditional methods.
Jul 06, 2018 879 words in the original blog post.