Home / Companies / Bugcrowd / Blog / December 2018

December 2018 Summaries

15 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
The latest cyber security news highlights several high-profile breaches including those at NASA, Marriott, and other large tech companies, as well as government agencies in the US and Britain, which were targeted by hackers working on behalf of China's Ministry of State Security. The attacks used compromised networks to gain access to clients' computers, and experts warn that even employee data can be a threat if it falls into the wrong hands. Nation state actors are also being linked to automated phishing attacks against secure accounts at Google, Yahoo, Protonmail, and Tutanota over the past two years. In response, lawmakers are making cybersecurity a top priority, with some proposing ideas to ramp up the federal government's response to cyber threats. The McAfee Labs Threat Report reveals a significant increase in IoT device malware, while ARK has partnered with Bugcrowd to protect its ecosystem through access to expert researchers.
Dec 21, 2018 535 words in the original blog post.
Jesse Kinser is a seasoned hacker and Bugcrowd Ambassador with over 10 years of experience in computer systems and security. She began exploring computers at the age of 3, spent her childhood tinkering with an old Windows 95 computer, and discovered her passion for information security while applying to colleges. Jesse worked on various research projects, including a focus on Android security, before joining the Department of Defense where she completed a Master's in Computer Science. After leaving the DoD, she has worked for Fortune 500 companies, including Salesforce, which helped her get into bug bounties. She now works at LifeOmic, a precision healthcare startup in Indianapolis. Jesse advises using toolkits like Burp Suite Pro and Git-tools to improve productivity, focusing on learning from others' experiences, and thinking critically when approaching targets. As an ambassador, she shares her knowledge with the community, offering tips on managing personal life, work, and bug bounties, as well as how bug bounties have impacted her career and hobbies.
Dec 20, 2018 590 words in the original blog post.
ITSPmagazine's podcast episode featured Jasmin Landry and Darrell Damstedt, two penetration testers who also hunt bugs as bug bounty hunters, discussing their strategies for bug hunting, the importance of ethical hacking, and hacker summer camp. They emphasized the need for a strategy when approaching bug bounties due to various opportunities available, including independent bug bounties run by organizations and private/public platforms. The researchers highlighted the value of community building events like Hacker Summer Camp, which bring together top researchers to learn from each other and have fun. Additionally, they discussed the importance of establishing clear language in vulnerability disclosure programs to protect both organizations and security researchers, as seen with Bugcrowd's Disclose.io initiative.
Dec 19, 2018 388 words in the original blog post.
With the holiday shopping season in full swing, the retail and eCommerce industries are embracing crowdsourced security models, with 9% of programs launched in 2018 being ecommerce and retail companies, three times more than the year before. These companies are adopting crowdsourced security to stay ahead of growing consumer awareness and stringent regulations resulting from rising breaches. The top three vulnerabilities found in retail and eCommerce programs in 2018 were Server Security Misconfiguration, Broken Authentication and Session Management, and Sensitive data exposure / sensitive data or password disclosure. Server Security Misconfigurations, such as using default credentials, are common and dangerous, while Broken Authentication and Session Management can lead to full account takeover. Sensitive Data Exposure can result from lack of encryption, weak keys, or password hashing techniques. To stay secure, consumers can take steps such as enabling two-factor authentication, minimizing password reuse, and utilizing password managers like 1Password, LastPass, and Keeper Security.
Dec 18, 2018 836 words in the original blog post.
Here is a summary of Sam Curry, a researcher ambassador in the bug bounty community: Sam Curry is a rising star in the bug bounty community from Omaha, Nebraska. He has been involved in bug bounties for five years and enjoys hacking websites. As a Researcher Ambassador, he will help teach his local hacker community about hacking and bug bounty hunting. Sam uses tools like Burp, Sublist3r, and dirsearch to find vulnerabilities. He recently found a Path Traversal bug on a JavaScript Node application that gave him full access to the application. To manage his time effectively, Sam schedules his day with morning sessions and late-night research. His advice for beginners is to enjoy the process, figure out how things work, and not stress about finding bugs. Sam also recommends following people in the community, reading blog posts, and participating in online forums like /r/netsec on Reddit.
Dec 18, 2018 1,012 words in the original blog post.
It's been an interesting year in security, with many predictions coming true. The increasing difficulty of understanding attack surfaces is a major challenge, driven by the proliferation of IoT devices and cloud adoption. DevSecOps began to take hold this year, with security practices being implemented earlier in the development cycle, offering a more holistic view of vulnerabilities and faster vulnerability fixing. CI/CD drives application development teams to deliver code changes more frequently, making security a first-class citizen. Broken business logic is a vulnerable area, and companies with mature security programs are clearing out low-hanging fruit, discovering new issues. The importance of human creativity and intelligence in identifying and addressing security vulnerabilities will only increase as the attack surface grows. Security will remain critical in the boardroom, with reporting on security metrics becoming essential for companies to show their commitment to improving security. Consumer demand is driving this shift, and we can expect to see more emphasis on security as a differentiator and marketing tool.
Dec 17, 2018 612 words in the original blog post.
The US is facing a significant strategic threat from China through economic and espionage activities, including the theft of research, influence over American discourse, and targeting of Navy contractors. Chinese hackers have also infiltrated companies worldwide with advanced malicious software to extract information, while a bug in Microsoft's login system could be exploited to gain access to someone's account. Additionally, popular avatar app Boomoji exposed personal data of its entire user base due to poor password management, and a report from Bugcrowd found that many ethical hackers have full-time jobs in cybersecurity.
Dec 14, 2018 522 words in the original blog post.
Rachel Tobac, a hacker and CEO of SocialProof Security, got her start in info-security through the SECTF stage at DEF CON, where she was given a chance to live hack a real company over the phone. She won second place three years in a row and went on to start her own company, training companies on human hacking and security awareness. Despite being underrepresented in the field, Tobac believes that women can succeed in info-security with the right support and community. She emphasizes the importance of having female role models and leaders in positions of power, as well as creating a sense of belonging and support for women in the field. Tobac also highlights the need to educate users about security best practices and set them up with clear technical controls to make smart security choices. For those just starting out in info-security, she advises jumping in and getting feedback, rather than self-selecting out due to perceived inadequacy. Additionally, bug bounty program owners should consider adding social engineering to their scope to evaluate under real-world conditions.
Dec 12, 2018 1,251 words in the original blog post.
The Inside the Mind of a Hacker Report highlights key insights into the bug hunting community, including gender imbalance, hacking education, and collaboration. 81% of hackers report that bug hunting experience has helped them get a job in cybersecurity, while 43% learned how to hack via online resources and blogs. Only 4% of the global hacking community are female, with more than 91% being male. The average yearly payouts for top 50 hackers is $145,000 USD, with over 600 valid submissions. Bugcrowd welcomes both beginners and experienced hackers, and has launched Bugcrowd University to provide resources and education. The report predicts that larger groups of whitehat hackers will use crowdsourced security as their primary source of income in the coming year, driving growth and diversification into new sectors.
Dec 12, 2018 656 words in the original blog post.
In 2019, security leaders face significant challenges in identifying vulnerabilities and fixing them before they're exploited. The shift towards virtual environments and orchestration brings new security complexities, including the need for continuous deployment of security measures and compliance goals. As organizations move to cloud-based infrastructure, it's essential to have solid security controls in place to protect against cyber threats. The increasing complexity of modern IT environments requires a closer relationship between business structure and cloud security.
Dec 11, 2018 446 words in the original blog post.
ARK has acquired security and penetration testing services from Bugcrowd, a crowd-sourced security platform, to identify vulnerabilities in its ecosystem. The acquisition allows ARK to tap into a global community of expert researchers who can identify critical issues 80% faster than traditional solutions. This partnership will enable ARK to provide the most secure platform possible to its users, with the goal of reaching maximum security in less time. The use of Bugcrowd's Vulnerability Rating Taxonomy will help ensure consistency and transparency in identifying vulnerabilities, while crowd-sourced security eliminates the imbalance between network attackers' motivations and those of developers and security defenders. The acquisition is expected to begin this week, with the public program starting in early January 2019.
Dec 10, 2018 649 words in the original blog post.
We are addressing concerns about point calculation and leaderboards in Researcher dashboards, currently showing points from both paid and kudos-only programs. Changes are planned to separate the two, and an investigation is underway into a potential bug with P1 and P2 program leaderboard calculations. Bugcrowd has announced its November Hall of Fame winners, recognizing top performers in various programs, including bonuses for first, second, and third place. The organization values their contributions and encourages researchers to submit high-severity bugs to earn bigger rewards and potentially faster invitations to private bounty programs.
Dec 10, 2018 482 words in the original blog post.
This week, Australia passed a modified encryption bill that gives law enforcement the ability to compel tech firms to circumvent encryption, with implications for other nations. In the US, officials warned companies and government officials of potential backlash against US-based companies, while bipartisan legislation was introduced to promote cybersecurity education. Meanwhile, Marriott planned to reimburse some guests affected by the recent breach, Quora suffered a massive cyber attack exposing 100 million users' data, and researchers discovered new malware threats such as DanaBot and GootKit, which may be cooperating with another group. The TSA released a cybersecurity roadmap aimed at prioritizing measures within the agency and across transportation systems.
Dec 08, 2018 478 words in the original blog post.
Developing policy to protect hackers that participate in Vulnerability Disclosure Programs and Bug Bounties is crucial for Bugcrowd. Anti-hacking laws, such as the Computer Fraud and Abuse Act, are built on the assumption that hackers are bad people by default, which doesn't accommodate bounty hunters and good-faith hackers. To bridge this legislative gap, a movement led by Casey Ellis and Amit Elazari has resulted in Disclose.io, a set of legal "band-aids" that standardize guidelines for responsible security testing, safe harbor provisions, and terms & conditions that protect hackers' rights. Bugcrowd is now incorporating Disclose.io messaging into its program briefs, providing customers with tools to create Safe Harbor policies that enable researchers to conduct good faith security research without fear of legal repercussions. The goal is to mature safe harbor policies further, with the aim of establishing a living breathing standard for Safe Harbor, similar to Bugcrowd's Vulnerability Rating Taxonomy.
Dec 03, 2018 355 words in the original blog post.
Next Gen Pen Test offers a unique platform with capabilities to meet organizations' evolving continuous application security needs, delivering up to seven times more security findings than traditional penetration testing, improving both the security posture and development lifecycle. Unlike Bug Bounty, Next Gen Pen Test includes best-in-class reporting, methodology coverage analysis, and access to a pen test crowd, building upon the crowdsourced security model with business process integrations, continuous testing, and team of uniquely experienced researchers. Both Next Gen Pen Test and Bug Bounty derive from the crowdsourced security model, but differ in their approach, with Bug Bounty focusing on crowdsourced incentives and public scope, while Next Gen Pen Test provides a more comprehensive coverage analysis and integrations with development teams.
Dec 03, 2018 591 words in the original blog post.