May 2020 Summaries
7 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
We are excited to announce our MVPs for Q1: February 1, 2020 – April 30, 2020! Our MVP program recognizes hackers that consistently bring their A-game across Bugcrowd bounty programs. To be recognized as an MVP, researchers must maintain a minimum average accuracy rate of 80%, achieve a priority percentile range for either P1s or P2s above 80%, submit at least four qualifying submissions, and have no significant enforcement infractions for six months prior to the end of the qualifying quarter. The Bugcrowd team is proud to recognize its exceptional researchers, including `akmall`, `alxhh`, `arcaneanomie`, and many others, who have demonstrated outstanding work across various bounty programs. Due to COVID-19, the exclusive swag for MVPs has been delayed but is expected to be announced in June and shipped thereafter.
May 29, 2020
379 words in the original blog post.
Niv is a seasoned penetration tester, Bugcrowd researcher, and avid bug hunter with 5 years of experience on various platforms. He holds an OSCP certification and has published his bug hunting stories, detailing the discovery of three unknown vulnerabilities in Schneider Electric's web.Client. Niv began his cybersecurity career as a consulting Penetration Tester in 2014 and later became a Penetration Testing Engineer at CyberArk in 2019. He credits Bug Bounty platforms like Bugcrowd for providing an additional source of income and opportunities to learn about current technologies. Niv emphasizes the importance of understanding how regular users interact with web applications and suggests finding unique vulnerabilities that require out-of-the-box thinking. In his free time, he enjoys watching TV shows and spending time with his family.
May 29, 2020
788 words in the original blog post.
We are excited to announce our Bounty Slayer winners for Q1: February 1, 2020 – April 30, 2020! Before we take a moment to recognize and celebrate our Q1 Bounty Slayers, we do have an important program update: The Bounty Slayers program has been put on hold for the remainder of 2020. We highly value the Crowd's hard work to keep organizations and us safe and secure and want to show our appreciation through Researcher Incentive programs like Bounty Slayer. Even so, we're always evaluating the value of such programs in terms of what they provide the Crowd and if it is the most effective use of resources to enable Researchers on the platform. At this point, we have decided to put this program on hold while we focus our efforts on other areas to help benefit the Crowd like providing more educational opportunities and content. We'll continue to keep it as an option to revisit in the future, but for the remainder of the year it will be on hold. Our Q1 Bounty Slayers winners, including Dipen, Harie_cool, todayisnew, and two private users, each received a $300 reward for qualifying for Q1 with 50 valid submissions at the qualifying priority levels and submission states each quarter in 2020.
May 28, 2020
329 words in the original blog post.
Shelter-in-Place orders have led many organizations to adopt fully-remote operating models without a clear playbook for doing so both quickly and securely. This has resulted in 74% of security leaders feeling rushed during the onboarding or migration process, with only 34% feeling very confident in their organization's ability to track changes to their internet-facing asset inventory. Despite this, 83% of respondents believe their organization will continue remote operations, which could have long-term consequences. The COVID-19 pandemic has also had a significant impact on the security industry, with 77% of hackers considering full-time hacking due to increased free time and motivation. Many security leaders are concerned about the shift to remote work negatively affecting their organization's security posture, with 66% citing executive team concerns about this issue. However, despite these challenges, many organizations have reported no change or an increase in budget for security initiatives, and 17% of security leaders even reported a budget increase. The survey also found that 80% of security leaders plan to conduct as many or more security tests than planned prior to COVID-19, with 72% citing increased concern about threats as the top reason for doing so. Ultimately, an astounding 85% of respondents believe they would be more likely to engage remote testing options versus in-person alternatives even after shelter-in-place restrictions are lifted. This shift towards remote work is likely to have a lasting impact on the nature of work and security segments, with many experts predicting that remote work will continue indefinitely.
May 27, 2020
1,049 words in the original blog post.
What a ride! Thank you to everyone who stopped by our LevelUp0x06 virtual conference last weekend, which featured 8 talks over 7.5 hours covering topics such as bug hunting, career paths and social engineering, with speakers including Thomas Dullien, Josh Schwartz, Katie Paxton-Fear, Chloé Messdaghi, Rhys Ellsmore, Ricki Burke, Jay Turla, Louis Nyffenegger, Stök, Michael Skelton, James McClean, Luke Stevens, Sajeeb Lohani and Casey Ellis. The conference also had on-air talent and moderators who kept everything flowing, with attendees able to check out the talks on Youtube and stay updated by signing up for the Discord channel. A follow-up event, LevelUp0x07, is already in the works.
May 18, 2020
235 words in the original blog post.
Attack surface management is a comprehensive approach to identifying and mitigating vulnerabilities in an organization's assets, encompassing both known asset inventory and real risk. It involves defining the attack surface, prioritizing it, and taking action to reduce risk faster than attackers. The solution requires building a business case that quantifies the risk reduction potential, using metrics such as Return On Security Investment (ROSI). Attack Surface Management (ASM) solutions can save resources by connecting organizations to a global network of reconnaissance experts, automating discovery, and providing rapid inventory population and categorization. ASM also helps mitigate reputational damage caused by subdomain takeovers and other business inconsistencies that scanners may miss. The solution is particularly useful in scenarios like M&A, digital transformation, or sudden shifts to remote work. When choosing the right solution, it's essential to consider both automated discovery and management tools and those that can discover and act on vulnerabilities, as human guidance is often necessary for effective results.
May 13, 2020
1,983 words in the original blog post.
Ricki from Cybersec People has partnered with LevelUp to run a resumé workshop as part of the event LevelUp0x06. The workshop aims to help participants leverage their successes into a stronger, cohesive story that fits into the job they are applying for. It will provide guidance on how to organize work history in a clear and concise manner, tailor narratives, and showcase experience in a way that appeals to potential employers. Participants can submit their CV/resumé and supporting documents to apply for simulated job descriptions, with chosen resumés receiving personalized feedback from Ricki. The workshop is designed to help hackers and security professionals present their non-traditional career experiences in a compelling way.
May 01, 2020
389 words in the original blog post.