Home / Companies / Bugcrowd / Blog / January 2019

January 2019 Summaries

14 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
A Vulnerability Disclosure Program (VDP) is a framework that encourages responsible disclosure of security vulnerabilities by external parties, promoting a proactive approach to cybersecurity. Companies with VDPs demonstrate their commitment to protecting digital assets, build trust with the security researcher community, and meet compliance requirements. By providing an easy channel for vulnerability reporting, companies can mitigate risks and give customers peace of mind, ultimately becoming more secure as they work with external security researchers at scale. With increasing pressure from legislation, standards, industry peers, consumers, and good-faith hackers, VDPs are becoming the norm, and it's essential for organizations to be prepared to receive vulnerability data with clear policies, robust communication channels, and backend processes.
Jan 31, 2019 601 words in the original blog post.
Tony is a Bugcrowd Ambassador who has been involved in cybersecurity since his high school days when he was introduced to computer classes and later discovered the world of cybersecurity through his grandfather's scripts. He continued his education by attending community college, where he helped build out their cybersecurity program, and then transferred to the University of Maryland – University College, graduating with a major in Cybersecurity. After receiving his degree, Tony became involved in bug bounties and participated in various competitions, including Hack the Pentagon and SANS Netwars. He found Bugcrowd through a friend and joined as an ambassador, continuing to work on improving his skills while helping vendors improve their security. In his free time, Tony enjoys hiking, traveling, and gaming, and prioritizes time management to balance his personal life, work, and bug bounties.
Jan 30, 2019 1,070 words in the original blog post.
IoT security is a pressing challenge as 25 billion IoT devices are expected to connect the world by 2021, with many unregulated and insecure. Companies like Fitbit and Arlo have taken proactive measures by inviting ethical hackers to test their devices before market release. Consumers are now demanding responsible data handling, with 87% of consumers planning to take their business elsewhere if they don't trust their data is being handled responsibly. The Japanese government has also taken decisive action to improve cybersecurity, attempting to hack into internet-connected devices in homes and offices as part of a 5-year program ahead of the Olympics. Employee negligence remains a significant cybersecurity risk, with social attacks accounting for most breaches. A robust security posture is critical, with vulnerability disclosure becoming best practice due to its ability to identify vulnerabilities through collective creativity and expertise of ethical hackers.
Jan 30, 2019 509 words in the original blog post.
The Pentagon's Defense Digital Service is working to improve the Department of Defense's technology and digital services, with a focus on cybersecurity. The recent report from the combat testing office highlights the military's cybersecurity challenges, including a lack of expertise and tools to assess software-intensive weapons systems. This issue is not unique to the Pentagon, as organizations across industries face similar problems. The solution lies in adopting new approaches, such as crowdsourced security, which has already been implemented by the DoD. This approach involves proactively engaging with security experts from around the world to identify vulnerabilities before adversaries. Despite challenges, there is good news - more organizations are taking a proactive approach to cybersecurity, and this trend is expected to continue. The key takeaway is that cybersecurity professionals are in high demand, and their expertise is essential to stay ahead of cyber attackers.
Jan 29, 2019 706 words in the original blog post.
A bug in FaceTime has been discovered, allowing callers to listen to the audio of the person being called before they pick up. The bug was found by a 14-year-old high school student from Tucson, Arizona who was chatting with friends about Fortnite when he stumbled upon it while calling his friends. Apple has shut down the back-end services that provide the vulnerable functions and expects to fix the issue by the end of this week. As a precaution, users are advised to disable FaceTime on their devices until the issue is fully fixed. The bug highlights the importance of security testing and education, as well as the need for proactive measures to protect against vulnerabilities. Apple's approach to security has been praised, with sympathy extended to the company's security team who have likely had limited rest since the news broke. Users are advised to disable FaceTime on their devices until a fix is confirmed, and to take steps to protect themselves and loved ones from potential exploitation of the vulnerability.
Jan 29, 2019 699 words in the original blog post.
Happy Data Privacy Day! Data Privacy Day is an annual awareness day to spotlight and foster education around online privacy and data protection, held every year on January 28 by the National Cyber Security Alliance and Stay Safe Online. Consumer data privacy is taken for granted by big tech companies like Google and Facebook, which sell access to consumer data to third parties for advertising purposes, revealing too much about a person's private identity. At Bugcrowd, data privacy is seriously taken and crowdsourced security is used to find and fix vulnerabilities in code before cyber attackers do, with the company keeping its Crowd's data safe through identity checks and not storing confidential information on its servers. Security and privacy are paramount, and progress in data privacy has only just begun, making it imperative to maintain good privacy practices year-round.
Jan 28, 2019 415 words in the original blog post.
The List, a directory of public bug bounty and vulnerability disclosure programs, has evolved to become the industry's top resource for finding such programs, thanks to Bugcrowd's crowdsourced efforts since 2013. The List is now open-sourced under CC 4.0, allowing anyone to use or contribute to it, and has been moved to the disclose.io Safe Harbor project. This move aims to accelerate the adoption of good disclosure policies and Safe Harbor for good-faith hackers, with features such as program filtering and a column recognizing Safe Harbor language terms. The List is now a community tool that can be reused under a CC 4.0 license, and anyone can contribute and update it, spreading its value far and wide and increasing the frequency of updates.
Jan 18, 2019 564 words in the original blog post.
Nicole Anderson-Au is a Cal Poly student studying Computer Science who has been fascinated with logic puzzles and investigation since she was young. Her passion for programming was encouraged by her father, a software engineer, and she started taking classes in programming at a community college after high school. She discovered The White Hat – Ethical Hacking Club during a college tour and joined the CTF team, becoming persistent and eventually rising through the ranks to become the Vice President of the club. Nicole is now interested in cybersecurity and has participated in bug bounties, including the Bugcrowd sponsored event, where she gained experience with real-life hacking scenarios. In her free time, she enjoys playing volleyball, swing dancing, and participating in CTFs.
Jan 17, 2019 880 words in the original blog post.
Bugcrowd has announced its December 2018 Hall of Fame winners, recognizing top performers in the platform's paid programs. The winners were determined by their points earned, with a private user taking first place with 495 points in the P1 P2 P3 P4 Paid Programs Leaderboard. Bugcrowd is also introducing new incentive programs for 2019 and offering bonuses to its top performers, including $3000 for first place, $2000 for second place, and $1000 for third place. The platform values its researchers' hard work and contributions, and invites them to submit high severity bugs to earn bigger rewards and potentially get invited to private bounty programs faster.
Jan 16, 2019 304 words in the original blog post.
The DevSecOps movement aims to bridge the gap between Security and Development teams by blurring their lines and sharing goals and accountabilities. However, many organizations struggle with this due to misalignment caused by different languages, priorities, and approaches. The current status quo often results in a reactive and inefficient process, where security is periodically assessed and passed back to Dev for analysis and resolution, leading to inflated workloads and increased risk of exploitation. To improve this, it's essential to start at the bottom by understanding the root causes of the chasm, which is often due to different languages and priorities. The solution lies in creating a common language, automating processes, and educating teams on secure coding practices. By doing so, Security and Development can work together more effectively, reducing friction and improving productivity. Ultimately, shared foundations and clear understanding are key to building great relationships between these two teams.
Jan 15, 2019 997 words in the original blog post.
This week, Australia's disaster alert system was targeted by cyber attackers who sent out false emergency texts and emails, potentially affecting thousands of citizens. Meanwhile, a vulnerability in Skype allowed authentication bypass, but it has been patched. Security concerns also surround Amazon Ring Security Cameras, with sources citing dismal privacy practices and unencrypted customer videos. AT&T has announced it will stop selling location data, following calls for a federal investigation into unauthorized information-sharing. A recent McAfee report found that 58% of consumers don't secure their personal devices, highlighting the need for individual responsibility in device security.
Jan 11, 2019 422 words in the original blog post.
Mikhail Egorov, also known as 0ang3el, is a Russian security researcher with 6 years of experience. He became passionate about cryptography and puzzles at the age of 15 after reading a magazine on mathematics and puzzles. Mikhail pursued a degree in cryptography and programming and later self-educated himself in infosec through online courses and bug bounty platforms like Bugcrowd. He started using Bugcrowd in 2014 and has been actively contributing to the platform ever since. In his free time, he enjoys traveling, hiking, and birdwatching. Despite the challenges of balancing work and personal life with his bug bounty activities, Mikhail finds it motivating and an additional source of income that has significantly impacted his life.
Jan 10, 2019 628 words in the original blog post.
The first edition of the 2019 Bug Bytes has been released, covering various cybersecurity incidents and breaches that occurred in Australia, Germany, the US, and elsewhere. A data breach in the Victorian Government directory affected 30,000 public servants' work details, while a hacking incident hit Germany's Linke party, compromising personal data from hundreds of politicians. In the US, a malware attack disrupted newspaper deliveries across the country, and Marriott International reported a data breach that compromised 383 million customer records, including passport numbers. Meanwhile, researchers discovered privilege escalation vulnerabilities in the CleanMyMac X utility software, which was patched by MacPaw and Cisco Talos. The House Democrats have also proposed legislation to improve election security, including voting machine vendor cybersecurity standards and paper ballot requirements.
Jan 05, 2019 397 words in the original blog post.
With the launch of the Bugcrowd Ambassador program, Rey Bango, a Bugcrowd Ambassador, shares his story of how he transitioned from being a software developer to becoming a cybersecurity professional. His journey began after witnessing the devastating impact of WannaCry on the healthcare sector in 2017, which sparked his curiosity and desire to learn about security. He attended conferences like BlackHat and DEF CON, built a research lab, and learned various skills through online courses, including penetration testing. Now, as an Ambassador for Bugcrowd, Rey advocates for finding vulnerabilities to keep family and friends safe and contributes to the development of safer web applications.
Jan 03, 2019 915 words in the original blog post.