July 2019 Summaries
9 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Arkose Labs has launched a private bug bounty program in partnership with Bugcrowd, a leading crowdsourced security platform, to enhance its defense-in-depth strategy. The private program will be reserved for elite hackers, while the public program remains open to all Bugcrowd's hacker community. Arkose Labs is an authentication system that uses a unique challenge-response mechanism to prevent fraud and has extensive testing processes in place to ensure maximum protection for its clients. By leveraging the expertise of Bugcrowd's Elite Crowd, Arkose Labs gains access to high-impact researchers with specific skill sets, allowing it to tailor its testing pool and retain more control over the program. The private program aims to provide continuous assurance of the stability and strength of its product features and gain insight into potential attack vectors.
Jul 23, 2019
588 words in the original blog post.
The Okta Security Team has launched a new Vulnerability Disclosure Policy (VDP) to standardize their interactions with researchers and establish clear expectations and guidelines. The policy outlines the scope, compensation details, legal considerations, and other details on what to expect when working with Okta to improve its security. Researchers can submit findings through either coordinated disclosure terms or Bugcrowd, with the same scope applying to both methods. The team emphasizes the importance of respecting their current application, user data, and good faith in reporting vulnerabilities, and provides a recommended reporting template to guide submissions. The policy aims to make it easy for researchers to leverage Okta's security expertise and contribute to its mission of protecting customers, partners, and stakeholders.
Jul 23, 2019
519 words in the original blog post.
The Q2 2019 MVP researchers have been announced at Bugcrowd, a platform that recognizes and rewards exceptional security researchers. The MVP program is designed as a stretch goal, with each quarter bringing new exclusive swag to qualified researchers. For the second quarter, researchers who have qualified for the first time will receive a hat and sunglasses, while those who have qualified twice will receive a t-shirt. The announcement also marks an end to the annual program, which ran from January 1, 2019 to December 31, 2019.
Jul 17, 2019
356 words in the original blog post.
We are excited to announce the Q2 2019 Bounty Slayers! After reviewing results in Q2, we noticed excessive duplicate abuse and need to make adjustments to the program to ensure sustainability. As such, we will be counting only "Resolved" and "Unresolved" P1 to P4 submissions starting in Q3, lowering the qualifying number of submissions for Standard and Power Up rewards. We were thrilled with performance and made changes to allow the program to be more sustainable. The winners of the Q2 2019 Bounty Slayers have been announced, including researchers who qualified for Standard or Power Up rewards for the first or second time. Thank you to all participants for their fantastic work! Rewards will be processed shortly and can be learned more about on our website.
Jul 16, 2019
365 words in the original blog post.
The Bugcrowd team has announced the Q2 2019 P1 Warriors program, which rewards researchers who submit valid P1 submissions as part of an ongoing program that began in January 2019. To earn badges and swag, researchers must meet specific requirements, including submitting a certain number of valid P1s. The top researchers in Q2 2019 have been recognized for their exceptional work, with some even qualifying for exclusive rewards such as hoodies. The team at Bugcrowd values and recognizes the contributions of its researchers, who are essential to identifying and resolving security vulnerabilities. Researchers can learn more about the program by visiting a designated webpage.
Jul 15, 2019
364 words in the original blog post.
The healthcare industry is shifting towards digital technologies, but this shift brings unique cybersecurity risks. The number of healthcare data breaches has increased significantly over the past decade, with nearly 60% of the U.S. population impacted by theft or exposure of sensitive records. To mitigate these risks, crowdsourced security solutions have emerged as a valuable resource for healthcare IT teams, providing continuous testing and vulnerability submissions that can help organizations stay ahead of threats. With growing criticality levels and increasing payouts, the market rate for vulnerabilities in healthcare has reached an all-time high, with average payouts exceeding $1,000 per vulnerability. Bugcrowd's crowdsourced security programs enable healthcare teams to focus on big-picture compliance and protection strategies while minimizing the risk of future attacks.
Jul 10, 2019
439 words in the original blog post.
This summary provides an overview of the importance of vulnerability disclosure programs (VDPs) in modern cybersecurity, particularly for companies facing increasing threats and regulatory pressures. A VDP offers a secure channel for researchers to report security issues and vulnerabilities, allowing organizations to strengthen their security posture, demonstrate commitment to protecting customers' data, and respond quickly to known risks. By leveraging crowdsourced security solutions like Bugcrowd's VDP, companies can reduce the risk of incurring fines, improve their security team's efficiency, and minimize the impact of security breaches. With the increasing adoption of VDPs by major companies, it is clear that this approach is becoming a critical component of a layered cybersecurity strategy.
Jul 09, 2019
906 words in the original blog post.
We are excited to announce our June 2019 Hall of Fame winners, Mikee taking first place with 520 points, a private user coming in second with 350 points, and delta0ne rounding out third with 325 points. We are awarding bonuses to the top performers, including $3,000 for first place, $2,000 for second place, and $1,000 for third place. The team values their continued partnership and encourages others to submit high-severity bugs that result in critical security impact to earn kudos points. Huge thanks are given to all participants for their outstanding work and contributions, with the next Hall of Fame results expected in July.
Jul 02, 2019
154 words in the original blog post.
The U.S. Federal Trade Commission (FTC) and Department of Justice (DOJ) have released guidance on the importance of vulnerability disclosure programs (VDPs), which provide a secure channel for researchers to report security issues and vulnerabilities, with major companies like Walmart and Office Depot already adopting this practice. A VDP offers a framework for intake, triage, and workflows for remediation, allowing researchers to report potential security risks in a formalized and consistent way, while also providing a notification mechanism for the reporter. However, managing these incoming reports can be challenging at scale, requiring organizations to designate a key stakeholder or team to provide management, technical review, and escalation of valid vulnerability submissions. This is where VDPs like Bugcrowd's Crowdcontrol come in, which facilitate hundreds of managed programs, vetting vulnerabilities according to objective rating standards, and allowing security teams to focus on reducing risk by remediating identified vulnerabilities.
Jul 01, 2019
770 words in the original blog post.