April 2020 Summaries
13 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Attack surface management is evolving rapidly and requires a smarter approach. Automation is crucial but must be complemented by human intuition to tackle this problem at scale. Scanners can identify low-hanging fruit, but humans are needed to focus on edge cases and make judgment calls. Tailoring tactics to seasonal activities and contextualizing for less risk are also essential. Agility in pivoting tools and techniques, as well as digesting expansive views of information, are critical components of a comprehensive attack surface management strategy. By combining human ingenuity with software scalability, organizations can reduce unknown attack surfaces by up to 60% and 98%.
Apr 29, 2020
1,403 words in the original blog post.
Bugcrowd is introducing its Classic Pen Test solution, which provides on-demand access to the value of the Crowd through a more predictable project-based pricing schedule that eliminates variable incentivization. This new offering allows organizations to benefit from crowd-sourced testing without straying from their business parameters. The Classic Pen Test differs from Bugcrowd's Next Gen Pen Test in its approach, providing set-up within 72 hours on average, 360-degree evaluation of pen testers, real-time vulnerability view, and seamless integration with developer workflows. The solution also offers remediation advice, fully managed services, and QSA-assessed compliance reports. Bugcrowd aims to bridge the gaps caused by traditional deployment models, delivering compliance-driven testing with flexibility, visibility, and results that organizations need.
Apr 28, 2020
839 words in the original blog post.
This article discusses the third step in managing an organization's attack surface, which involves translating asset risk outcomes into business value. The process includes eliminating irrelevant assets, remediating high indicators of risk, and digging deeper to ensure security. Organizations should consider adding assets with high business criticality to active testing programs or continuous monitoring to reduce risk. A repeatable framework is also essential for maintaining control over the attack surface, and organizations experiencing significant changes may need to initiate deeper assessments more frequently. The article highlights Bugcrowd's Attack Surface Management portfolio as a powerful solution for managing an organization's attack surface.
Apr 22, 2020
940 words in the original blog post.
Pen testing is often focused on delivering a statement of compliance, and traditional models have made business sense due to their simplicity and universality. However, these models may not deliver everything pen tests were meant to provide, such as ensuring security of mission-critical assets and detecting vulnerabilities. Crowdsourced approaches to pen testing can help address these limitations by leveraging a large pool of vetted talent, automation, and incentivization. These approaches can reduce costs, improve speed-to-value, and increase the volume and criticality of surfaced vulnerabilities, making them more attractive for organizations looking for continuous coverage without sacrificing results. By adopting crowdsourced pen testing solutions, businesses can benefit from improved compliance, transparency, vulnerability detection, and cost-effectiveness.
Apr 21, 2020
1,201 words in the original blog post.
The hacking community has been significantly impacted by the COVID-19 pandemic, with many conferences being cancelled or going online due to social distancing measures. However, this shift has also presented opportunities for increased accessibility and collaboration among hackers. The LevelUp conference, started in 2017 as a free online hacking con, has transformed into a vital platform for security enthusiasts to connect and learn from each other. With its online format, LevelUp allows for greater anonymity, international participation, and unlimited attendees, making it an essential event for the community during these uncertain times.
Apr 19, 2020
560 words in the original blog post.
Attack surface management is becoming increasingly important as organizations grow and undergo business transformation or M&A. Traditional programmatic attack scanners are no match for motivated attackers, but human ingenuity can help provide a "Hacker's Advantage". Bugcrowd's Attack Surface Management portfolio offers two uniquely valuable solutions: Asset Risk and Asset Inventory. Asset Risk uses a global Crowd of vetted security experts to find and prioritize previously unknown internet-facing attack surface, while Asset Inventory is a software-based continuous scanning solution fueled by an ever-growing pre-indexation of the entire internet. By combining these two solutions, organizations can improve inventory accuracy, better inform priority rankings, and more rapidly reduce risk across their business.
Apr 14, 2020
1,004 words in the original blog post.
Bugcrowd has navigated the challenges of the COVID-19 pandemic while maintaining a strong team, researcher community, and business performance, with hundreds of thousands of distributed cybersecurity researchers contributing to strengthening cybersecurity for leading organizations. The company is uniquely positioned to deliver security solutions that meet customers' requirements for any attack surface and from anywhere, leveraging its Crowdsourced Security-as-a-Service model and platform that intelligently creates a closed loop security workflow. With new growth funding of $30 million, Bugcrowd plans to grow its go-to-market scale, develop its platform further, and secure new partnerships to accelerate speed to value and market, addressing the increasing demand for continuous vulnerability testing solutions with human intelligence.
Apr 10, 2020
735 words in the original blog post.
The LevelUp virtual conference, scheduled for May 9th 2020, will focus on "Hacking The New Normal" amidst the COVID-19 pandemic. The event features a lineup of technical and career-focused speakers covering security research, bounty hunting, and cybersecurity topics. Two of the first two announced speakers are Louis Nyffeneger, who will discuss vulnerabilities in various programming languages, and Rhys Elsmore, who will share insights on bug bounty hunting strategies, including decision-making models to maximize impact and success. The conference aims to help attendees "level up" their skills and knowledge in these areas.
Apr 07, 2020
558 words in the original blog post.
The current state of digital security highlights the gap between how organizations defend their digital ecosystems and how attackers operate. While organizations focus on securing priority assets, unknown or un-prioritized assets become vulnerable to exploitation by hackers. Automated discovery tools are being used to identify these vulnerabilities, but they face challenges such as lag time, limitations in applying logic and learning frameworks, inability to make logical pivots, verification of accuracy, and prioritization of discovered assets. Moreover, attackers use similar scanning technologies, creating a disadvantage for defenders. To fill this gap, organizations should consider crowdsourced security solutions that combine the scale of scanners with human ingenuity to find, validate, and prioritize assets before malicious attacks.
Apr 07, 2020
1,235 words in the original blog post.
Zilliqa has partnered with Bugcrowd to launch a bug bounty program, leveraging the collective power of security researchers from around the world to identify and fix vulnerabilities in their high-performance blockchain platform. This partnership has enabled Zilliqa to achieve comprehensive security coverage across its infrastructure, streamline the bug reporting process, and improve turnaround times for fixing vulnerabilities. By engaging a wider audience through Bugcrowd's platform, Zilliqa has not only enhanced its network security but also built credibility with its community members and prospective partners.
Apr 06, 2020
407 words in the original blog post.
The coronavirus pandemic is causing some organizations to worry about their crowdsourced security programs and whether they can handle high submission volumes. Fortunately, Crowdcontrol equips security teams with features like Auto-Accept, which validates and accepts vulnerabilities, and Auto-Reward, which proactively pays security researchers for valid findings. Additionally, Crowdcontrol's Auto-Push feature integrates remediation workflows into existing tools like Jira and GitHub, while Auto-Resolve updates the remediation status of valid findings in real-time. The company also offers CrowdMatch, a sourcing engine that helps organizations match and manage security researchers on-demand. By providing repeatable workflows and access to expertise, Bugcrowd aims to protect business continuity during uncertain times.
Apr 03, 2020
280 words in the original blog post.
The COVID-19 pandemic has accelerated the shift to remote work, presenting numerous security challenges for organizations as hackers seek to exploit vulnerabilities in corporate systems. As a result, security teams are facing increased pressure to maintain coverage and compliance off-site, while also improving their work-from-home security policies. To mitigate these threats, organizations can implement strategies such as setting up a 'security@' email address or #security channel, encrypting data at rest, and ensuring the use of virtual private networks (VPNs). By adopting the right cybersecurity measures, companies can conserve resources and prioritize critical fixes to fortify their attack surface. Security teams are also being supported by platforms like Bugcrowd, which provides a solution stack to expedite vulnerability management and maximize operational efficiency.
Apr 02, 2020
626 words in the original blog post.
The COVID-19 pandemic has brought about unprecedented changes, with many people hunkering down at home due to social distancing measures. The tech industry has been fortunate in that many jobs can be done remotely, but others have not been so lucky, resulting in millions of lost jobs. Despite the uncertainty and bleak outlook, there is a silver lining: this period of isolation can be a catalyst for reinvention, growth, and working towards preparing for when things pass. In the security space, bug bounties and crowdsourced security are becoming increasingly popular, with more researchers submitting to programs than ever before, and organizations looking for cost-effective solutions to identify security vulnerabilities. Bugcrowd is positioning itself as a resource for both clients and researchers, offering support, education, and opportunities for success in this growing field.
Apr 01, 2020
1,057 words in the original blog post.