March 2019 Summaries
13 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Today we released the ESG Research Insights Report, Security Leadership Study – Trends in Application Security, revealing what CISOs are looking to prioritize in the year to come. The report highlights challenges with current application security testing methods and crowdsourced security adoption and benefits. Nearly 90 percent of security leaders plan to run a crowdsourced security program, citing reduced cost and expanded coverage as core benefits. DevSecOps adoption is also on the rise, with over 80 percent of organizations integrating cybersecurity processes in CI/CD processes. Security leaders are prioritizing investments in public cloud-hosted applications, mobile applications, and application security tools that can scale continuously with development processes.
Mar 28, 2019
405 words in the original blog post.
The Netflix security team has been working closely with the security research community through their responsible disclosure and bug bounty programs, which were recently made public to strengthen partnerships and enable researchers worldwide to participate. Since the public launch, they have engaged with 657 researchers and rewarded over $100,000 for over 100 valid bugs. The team prioritizes a good researcher experience, maintaining an average triage time of less than 48 hours, and has received interesting submissions that highlight the value of their program in identifying security issues and improving the overall security of Netflix services. They are committed to continuing to engage with researchers and expanding their bug bounty coverage to their studio app ecosystem, aiming to maintain a high-quality researcher experience and secure Netflix's services.
Mar 21, 2019
704 words in the original blog post.
Justin Gardner is a Bugcrowd Ambassador from Richmond, Virginia, who started learning about computers and programming at the age of 12. He took a break due to concerns about potentially illegal activities, but later formed a security club in college where he met another ambassador, Tommy DeVoss. Justin's passion for hacking led him to become a penetration tester at 21, thanks to his bug bounty experience. He now balances work and personal life by scheduling time for hacking and prioritizing family. Justin recommends various tools, including TomNomNom's scripts, GoBuster, MassScan, and Burp Suite, which he finds fast and effective. He also shares a quick tip: escalating bugs can bring more severe vulnerabilities to light. As a beginner, Justin advises reading Pete Yaworski's "Web Hacking 101" book, watching Bugcrowd University content, and attending LevelUp conferences. Bug bounties have positively impacted Justin's life by giving him a passion for hacking, enabling him to start his life debt-free and invest in retirement, and landing his first full-time job as a penetration tester. In his free time, Justin enjoys spending with family, playing games, working out, and pursuing entrepreneurial ventures.
Mar 21, 2019
1,202 words in the original blog post.
The ARK team has opened its private Bugcrowd security bounty program to the public, allowing over 100,000 eyes to review and test the ARK core codebase, potentially leading to improved security and faster bug fixes. The platform has proven successful in helping companies like Netflix and Tesla identify vulnerabilities, and the team is now seeking contributions from security researchers and penetration testers. To participate, researchers can learn about recent issues and use them as a starting point for testing strategies on ARK's Security Vulnerabilities repository, and access important resources such as API documentation and development network links to help them get started. The goal of crowd-sourced security is to harness white hat security researchers to find and eliminate vulnerabilities, providing rapid and focused results, and the team believes that this approach will enable it to reach a wider group of individuals with an interest in cyber security.
Mar 20, 2019
792 words in the original blog post.
A successful bug bounty program is a continuous and iterative process that starts before its launch date and involves scoping, implementation, identification of findings, remediation of issues, and iteration based on learnings. Scoping includes defining resources, technical scope, clear goals and objectives, and establishing a program brief that outlines targets, focus areas, incentives, and expectations. Implementing the program requires setting up integrations, workflows, and templates to streamline the process, while also determining how and where the program will live. Identification of findings involves triage and validation by a team, followed by rewarding submissions according to the program brief's rewards structure. Remediation of issues involves working with development teams to fix bugs, prioritize criticality, and ensure future security vulnerabilities are avoided. The program continues to iterate based on learnings, reassessing results and outcomes to adjust scope, rewards, and other aspects as needed to meet goals and objectives.
Mar 20, 2019
1,214 words in the original blog post.
A critical flaw in Switzerland's electronic voting system has been discovered by researchers through a bug bounty program, highlighting the importance of secure voting systems. Meanwhile, numerous tech companies have inadvertently leaked sensitive data through public links to file-sharing services like Box and Google Drive. A malware attack on 200+ apps in Google Play has also been reported, as well as a major outage affecting Facebook and Instagram, which was initially blamed on a server configuration change rather than a cyberattack. The series of outages raises concerns about the coincidence of these events occurring simultaneously.
Mar 15, 2019
527 words in the original blog post.
Bugcrowd's latest Vulnerability Rating Taxonomy (VRT) version, 1.7, has been released with updates addressing the automotive industry's security misconfigurations and other vulnerabilities. The taxonomy is a living document that evolves based on community feedback through an open-source GitHub repository. This update includes specific security misconfiguration vulnerabilities for the automotive sector, reflecting the growing number of critical vulnerabilities reported in this industry. Other updates to VRT 1.7 include new P2 and P4 variants, updated remediation advice links, and customization options for customers with different priorities and needs. The changes will be implemented into Bugcrowd's Crowdcontrol platform the week of March 25th.
Mar 14, 2019
510 words in the original blog post.
Bugcrowd has announced the launch of a new integration with ServiceNow for Crowdcontrol, which enables seamless handoff between Security and Development teams to resolve vulnerabilities faster. The integration automates workflows in IT, Security, and more, providing enhanced submission data and remediation advice to aid in rapid remediation. This solution supports multi-instance setups, allowing customers to scale while preserving their existing data architecture. It also features a self-service model, enabling users to build and manage the solution as needed. The integration reduces Security overhead and enables Development teams to fix vulnerabilities faster.
Mar 12, 2019
230 words in the original blog post.
Bugcrowd has announced its February 2019 Hall of Fame winners, recognizing top performers who contributed significantly to the platform's success. Mikee took first place with 440 points, followed by todayisnew in second place with 430 points and euler42 rounding out third with 300 points. Bugcrowd is awarding bonuses ranging from $1000 to $3000 to its top performers as a token of appreciation for their hard work. The platform values the contributions of its researchers and encourages others to submit high-severity bugs that can result in critical security impact, potentially leading to private bounty programs invitations.
Mar 12, 2019
190 words in the original blog post.
Bugcrowd`, a platform offering bug bounty programs and public vulnerability disclosure, has been criticized for its initial recommendation of Non-Disclosure as the default policy in its product documentation. However, the company clarifies that it is actually pro-disclosure and supports both Co-ordinated Vulnerability Disclosure (CVD) and Non-Disclosure models, with CVD being the default for public programs and Non-Disclosure being used for private or Next Generation Penetration Testing offerings. Bugcrowd aims to normalize vulnerability disclosure through its support of CVD while also supporting NDAs to maximize use-cases for connecting whitehat hackers with cybersecurity problems. The company emphasizes the importance of context and transparency in vulnerability handling, acknowledging that the topic can be confusing without proper understanding.
Mar 11, 2019
698 words in the original blog post.
The RSA Conference saw a notable increase in diversity among attendees, with an estimated 20 percent of the audience being women, thanks to efforts such as updated keynote submission practices, new training offerings, and additional keynote speaker slots. A security researcher advocate spoke at BSidesSF on tips for fixing the diversity gap in cybersecurity. Equifax CEO Mark Begor and Marriott CEO Arne Sorenson testified before a Senate subcommittee on private-sector data breaches, with critics arguing that senior executives failed to properly preserve assets about the breach. Two smart alarm systems, Viper and Pandora, were found to have major security flaws that could be exploited by hackers. Automakers are becoming increasingly bullish about cybersecurity, with some companies using crowdsourced security programs like Bug Bounty to identify vulnerabilities and fix them.
Mar 08, 2019
454 words in the original blog post.
Crowdsourced security has become a mainstream approach to cybersecurity, with many organizations adopting this model to improve their productivity and creativity. However, successful execution of a crowdsourced security program requires careful planning and management, including identifying objectives, defining logistics, implementing processes for vulnerability remediation, and attracting top researchers. Bugcrowd provides a robust platform and extensive resources to help clients establish and manage world-class programs, with features designed to standardize best practices and ensure customer and researcher success. The company is launching a blog series on best-practices and how-to's to guide clients through the process of getting into crowdsourced security, starting with definitions of key terms such as Crowdcontrol, Program Brief, Payout, Kudos Points, Submission, Triaging, and Vulnerability Rating Taxonomy.
Mar 07, 2019
871 words in the original blog post.
Bugcrowd is kicking off RSA week by reflecting on its theme "Better", emphasizing the need for improved tools, training, budgets, awareness, and more to address cybersecurity skills shortage and make the internet a safer place. Bugcrowd aims to achieve this through crowdsourced security programs, connecting customers with elite hackers, and providing opportunities for hackers worldwide. The company is also dedicated to upskilling researchers and its community through free programs like Bugcrowd University and LevelUp, an online conference. Bugcrowd continues to innovate and support its customers and the crowd, perpetuating a game of cybersecurity that makes the digital world safer.
Mar 04, 2019
667 words in the original blog post.