Home / Companies / Bugcrowd / Blog / September 2019

September 2019 Summaries

6 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
StackPath is a platform of secure edge services that enables developers to protect, accelerate, and innovate cloud properties ranging from websites to media delivery and IoT services, with security being a core part of its DNA since inception. The company has built a comprehensive Vulnerability Management Program, but sought to scale the impact of its solutions by formalizing external security feedback through Bugcrowd's managed Vulnerability Disclosure Program in 2018. This partnership has afforded StackPath the time to better connect with the researcher community and orchestrate responses to submissions, including both high-priority and "non-critical" vulnerabilities that have proven valuable for security and development training efforts. The company values the contributions of its security researchers, providing a safe harbor to protect both their safety and the integrity of testing processes, and is grateful for the commitment of white hat hackers in making the digitally connected world a safer place.
Sep 27, 2019 482 words in the original blog post.
The benefits of crowdsourced vulnerability discovery programs are significant, with potential annual impact of two full-time resources in under a week and 10x more high-priority vulnerabilities than traditional testing methods. However, implementing such programs can be challenging due to various hurdles, including getting the rest of the organization on board, managing finances, ensuring trust in the crowd, integrating with development teams, and addressing concerns about security and ROI. To overcome these challenges, it's essential to develop a plan of action, achieve organizational alignment, and select a crowdsourced security platform that meets specific needs and requirements.
Sep 12, 2019 1,429 words in the original blog post.
Bugcrowd has released its second round of updates to Bugcrowd University (BCU), a free and ungated library of educational hacking tutorials. The new collection includes five modules that cover high-impact bug types rated as P1-P3 on the Vulnerability Rating Taxonomy, such as Server Side Request Forgery, XML External Entity Injection, GitHub Recon and Sensitive Data Exposure, and Recon and Discovery. These modules are designed to help hackers hone their skills in techniques that can result in large bounty payouts. The modules are led by security experts and community members, including Jasmin Landry, Jay Turla, Alyssa Herrera, Aditya Gujar, Majd Aldeen Atiyat, Sajeeb Lohani, and Vortex, who share their knowledge on advanced tools like Burp Suite, SSRF bugs, XML External Entity Injection vulnerabilities, GitHub Recon, and Recon and Discovery. The modules are available for researchers to learn more about these techniques and improve their bug hunting skills.
Sep 10, 2019 431 words in the original blog post.
Bugcrowd is a crowdsourced cybersecurity platform that connects developers with a global community of researchers to identify bugs and vulnerabilities in their applications. The platform offers a marketplace where customers can interact with researchers, and provides a means for organizations to remediate issues through recommended best practices and integration with GitHub. The power of the crowd is a key aspect of Bugcrowd's innovation, as it allows for a diverse set of perspectives and creativity to identify vulnerabilities that might be missed by internal teams. The platform measures security effectiveness by tracking vulnerabilities and response times, and adapts to changes in the security landscape through the help of its global community of researchers. DevSecOps is a major trend in the cybersecurity landscape, and Bugcrowd's crowdsourced approach can help automate the human element of this process while reducing vulnerabilities.
Sep 06, 2019 1,169 words in the original blog post.
We are excited to announce our August 2019 Hall of Fame winners, who tied for first place with Private user and todayisnew at 280 points each. The top performers were recognized for their outstanding work, which earned them bonuses ranging from $3,000 to $1,000. We appreciate all the hard work done by our users to make our programs successful and value their continued partnership. To encourage more bug submissions, we are highlighting bugs with critical security impact, such as remote code execution or elevation of privilege, which will earn the most kudos points.
Sep 05, 2019 173 words in the original blog post.
Bugcrowd's Next Gen Pen Test (NGPT) program offers a dynamic and continuous coverage approach to security testing, combining the benefits of crowdsourced programs like bug bounties with the structured coverage and compliance artifacts required by organizations. The program differs from traditional bug bounty programs in its methodology-driven testing approach, providing researchers with a framework for objective assurance and standardized reporting. Researchers can participate in NGPT through two roles: on-demand engagement or grant-funded methodology-driven testing, both of which provide opportunities for finding valuable bugs and receiving compensation for their time and findings. The testing timeframe typically lasts two weeks, and continuous access to Bugcrowd's dedicated Researcher Success team is available throughout the engagement. By leveraging NGPT, organizations can meet compliance initiatives while benefiting from the economy and speed of a bug bounty program.
Sep 03, 2019 542 words in the original blog post.