March 2020 Summaries
7 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
It's 11pm. Do you know where your assets are? Do your attackers? In our latest webinar, Bugcrowd Founder, Chairman, and CTO, Casey Ellis is joined by Jeremiah Grossman of Bit Discovery to discuss how their partnership helps organizations gain visibility and control over previously unknown attack surface in as little as 5 minutes. Most organizations are missing around 40% of their owned assets due to rapid IT expansion, business transformation, M&A, or complex accounting practices. An information mismatch between attacker and defender creates opportunity for malicious exploit, where scanners trained on known-knowns will never surface real risks that lie just out of sight. Automation plus human ingenuity trump either alone, with humans strategically inserting in cost and resource efficient ways. Acceptance is the first step in moving on, as most organizations don't know their entire attack surface, which is no longer acceptable to customers, partners, and employees.
Mar 30, 2020
455 words in the original blog post.
As the new Manager of Quality Assurance and Training at Bugcrowd, Luke Stephens (hakluke) aims to improve the platform's experience for hackers and program owners. He plans to lead technical oversight in submission appeals, push for faster triage times, and coordinate with the marketing team to provide educational content. As a seasoned researcher with significant experience on bug bounties, he is well-positioned to drive improvements in the appeals process, which will include reducing wait times for submissions. Luke also emphasizes the importance of frequent communication with the hacker community, encouraging them to share their thoughts and suggestions through various channels such as Discord, Twitter, and Slack. Overall, his goal is to build a supportive, knowledgeable, and active hacker community that benefits all users.
Mar 24, 2020
397 words in the original blog post.
We're excited to introduce the reimagined Bugcrowd Ambassador Program, which brings together passionate security enthusiasts from around the world. The new ambassadors include Abartan from Nepal and Australia, Alfie from Kenya, Anon_Hunter, a full-time bug bounty hunter, Chevon, a bug bounty hunter and Adjunct Professor, D_J, glc, who recently passed the Offensive Security Certification Professional exam, Carlos Santiago, a seasoned security expert with 8 years of experience, Kent Bayron, also known as @Kntx, Labda, a self-taught penetration tester, lopseg, Matt, a passionate infosec advocate, prodigysml, pwn, a researcher and bug bounty hunter, sherlocksecure, a Cyber Security Engineer and Architect, sritarun3, a security researcher and bug bounty hunter, udit_thakkur, an ethical hacker and self-taught security researcher, and two new additions D_J and JR0ch17. These ambassadors will help promote the Bugcrowd community and foster collaboration among security enthusiasts.
Mar 18, 2020
958 words in the original blog post.
We sat down with Cloudinary’s CISO, Netanel Fisher, to understand more about how he took control of Cloudinary’s media management security with Bugcrowd.
Cloudinary values the trust placed in its platform by developers and businesses globally, taking responsibility seriously to protect customer data. The company prioritizes information security, complying with widely accepted standards and regulations, and showcasing its commitment through a bug bounty program. This program adds value in vulnerability management, providing 24/7, 365-day coverage from thousands of researchers.
Cloudinary partnered with Bugcrowd to enhance its security posture, leveraging the platform's expertise to deploy and evolve the bug bounty program. With Bugcrowd's support, Cloudinary addresses vulnerabilities more quickly and efficiently, having the partnership to help along the way.
Mar 09, 2020
384 words in the original blog post.
This year's RSA Conference focused on the "Human Element," emphasizing that security professionals are responsible for safeguarding every aspect of the digitally-connected world and protecting vulnerable people. The conference highlighted three key themes: Security Personification, Cloudpocalypse, and The Same But Different. Vendors showcased edgier messaging, personifying their products as intelligent and secure, while also acknowledging the importance of human expertise in security. The event also featured a "builders vs. breakers" panel discussing how organizations can leverage crowdsourced security to secure assets proactively. Additionally, Bugcrowd's 4th annual afterparty was a highlight, with a synth-wave band, retro arcade games, and airbrush tattoos. The conference concluded by emphasizing the need for organizations to balance human element with new efficiencies and scale afforded by technology.
Mar 06, 2020
1,369 words in the original blog post.
The increasing concern about election security has highlighted the vulnerability of populations to manipulation through disinformation strategies, particularly in times of high anxiety like the current Coronavirus pandemic. Effective voter turnout and confidence can be significantly impacted by convincing messages on social media, making it crucial for voters to rely on trusted news sources and verified social handles. The importance of transparency and communication about election security measures cannot be overstated, as a lack of trust in the process can lead to decreased voter participation. Ensuring the integrity of voting infrastructure through vulnerability disclosure and management is vital to maintaining public trust and confidence in the electoral process.
Mar 05, 2020
462 words in the original blog post.
Joinable Programs`, a new feature from Bugcrowd, aims to make it easier for researchers to find and join previously private programs by adding program teasers to the catalog, listing eligibility requirements and allowing logged-in users to see if they meet the criteria. Users can easily filter search results to show only "joinable" programs, view details to gauge their suitability, and share programs with others. This change makes it easier for researchers to access a wider range of programs, reducing barriers to entry and increasing participation in bug bounty hunting. `Joinable Programs` is designed to streamline the process of finding and joining programs, making it more accessible to researchers and promoting a more inclusive community.
Mar 03, 2020
309 words in the original blog post.