June 2020 Summaries
15 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd launched its Next Gen Pen Test solution in 2018 to address the need for a more structured approach to pen testing. The company's Bug Bounty program provides quick access to security expertise through a "pay-for-success" model, but some organizations may prefer the predictability and compliance artifacts offered by traditional pen testing. Bugcrowd has since introduced Classic Pen Test (CPT) and Next Gen Pen Test (NGPT), which provide a standardized view of security posture and can be deployed on-demand or continuously. The company's products are designed to meet the diverse security needs of its customers, who may use both Bug Bounty and pen testing solutions together, especially in scenarios where new stakeholders, mergers and acquisitions, compliance for specific assets, and customer acquisition are involved. By combining these solutions, organizations can improve their speed to value, reduce time to remediate vulnerabilities, and increase the richness of results.
Jun 30, 2020
1,806 words in the original blog post.
Upwork's senior information security engineer, Alex Bod, discusses how the company's public bug bounty program helps ensure the platform's security and reassure clients by leveraging a crowd-sourced approach to identify vulnerabilities, providing regular reports on the fixes made and the value of the program, and showcasing the commitment to high levels of security through transparent collaboration with Bugcrowd. The program has seen over 429 bugs and vulnerabilities fixed in nearly two years, making it an effective solution for Upwork's critical platform. By working together with Bugcrowd, Alex and his team can provide clients with confidence that their sensitive data is safe and secure.
Jun 25, 2020
564 words in the original blog post.
The COVID-19 pandemic has forced organizations to rethink their security strategies and priorities. Security leaders from various industries have shared their best practices for navigating the business impacts of the pandemic, including protecting employees from phishing attacks, prioritizing team health and well-being, ramping up communications, regularly revisiting processes, documenting changes and decisions, and continuing to leverage beneficial transformations. By implementing these tips, organizations can maintain productivity, security, and employee satisfaction in the new remote work environment.
Jun 25, 2020
1,145 words in the original blog post.
Hackers are not stereotypical characters from Hollywood, but rather everyday people with diverse backgrounds and skills who have turned their passion for security into a sustainable livelihood. The latest report from Bugcrowd provides new insights into the world of hackers, revealing that they come from all walks of life and possess varied skills, ranging from conventional techniques to specialist expertise. These individuals help organizations face complex cybersecurity challenges through their differences, not just similarities, and are increasingly becoming a mainstream movement. The report also highlights the growing economy of on-demand cybersecurity, with hackers preventing $8.9B of cybercrime last year and mitigating a projected $55B by 2025.
Jun 23, 2020
455 words in the original blog post.
Tomorrow is Juneteenth, the day that the United States celebrates the end of slavery. To acknowledge the history of slavery and better support the Black community, Bugcrowd recognizes Juneteenth as an official Bugcrowd holiday and has made tomorrow a day of learning for employees to increase their understanding of how systemic racism has impacted the Black community in the United States and around the world. We recognize that as a company, change must start with each one of us. Slavery may have ended on Juneteeth, but racism continues to be a serious and systemic issue. By taking the time to better educate ourselves and play a more active role in combating racism, we hope the Bugcrowd team can be a part of the solution to help build a more equitable society. Education and understanding are the first critical steps to turn this moment into a movement, and we encourage employees to look for ways to support racial equality in their own communities as a company, we’ll continue to look for opportunities to support diversity, racial justice, equality and change. Today and every day, please join Bugcrowd in building awareness, becoming educated and advocating for change.
Jun 18, 2020
269 words in the original blog post.
Bugcrowd has made significant changes to its payment platform, introducing direct Bank Transfers worldwide, which will lower processing fees and speed up payments for researchers. The change aims to save over $100,000 for researchers in 2020. To facilitate this update, all researchers are required to update their payment settings before receiving their next payment. The new Tax Form management workflow allows researchers to maintain their tax forms in-platform, improving the issuance of end-of-year forms and assisting with tax filings. Bugcrowd will continue to work on platform updates, including more payment-related changes, and offers support for any questions or concerns through its support team.
Jun 17, 2020
248 words in the original blog post.
With COVID-19 shaping the way we work and operate, TransferWise has seen an increase in bug submissions from ethical hackers due to the increased time they have at home. The company's remote work environment has allowed it to maintain its technical security posture, but leaders must now focus on employee well-being and mental health during this challenging time. To address these challenges, key takeaways include implementing a strong vulnerability management workflow, quickly fixing smaller issues, and prioritizing the happiness of staff and employees. TransferWise's teams are equipped with the skills to tackle security challenges due to their remote work setup, but leaders must now focus on supporting their people as much as possible.
Jun 16, 2020
513 words in the original blog post.
This private program at Arkose Labs is focused on machine learning and automation, utilizing computer vision to harden their Enforcement Challenges. The program is designed for researchers with experience in algorithms, machine learning, image analysis, sound analysis, or unique approaches to these fields. It provides a challenging environment to enhance skills and potentially earn bonuses for new analysis techniques. With the current global landscape and economic impact of Covid-19, this program offers an attractive opportunity for individuals to get started with machine learning work online.
Jun 16, 2020
315 words in the original blog post.
Bugcrowd has introduced a new solution to its Pen Test portfolio called Classic Pen Test, which offers a cost-predictable, pay-for-effort model for organizations to quickly launch methodology-driven pen testing. This solution helps address common challenges such as lengthy scheduling delays and a mismatch of skills per engagement by leveraging a crowdsourced, pay-per-test model that allows for unlimited growth in available resources. The solution provides real-time vulnerability results view, 24/7 reporting, fully managed triage, and SDLC integrations to reduce time to value. Compared to Next Gen Pen Test, Classic Pen Test offers a more prescriptive pricing option with a flat, pay-per-test model without the variability of an added incentivization pool. The choice between Classic and Next Gen Pen Test depends on the organization's specific needs, such as reducing risk, meeting compliance objectives, or requiring premium SLAs for vulnerability triage.
Jun 15, 2020
900 words in the original blog post.
Nizam Abdallah is a freelance contractor, bug bounty hunter, and family man based in Australia who runs his own business, Binary Technology Labs, focusing on security, performance, and resilience testing. With 20 years of experience in software development and testing, he has been hunting bugs since 2017, with a focus on hardware and mobile application-centered programs. He has successfully found several vulnerabilities in Netgear devices, including a notable one that permits administrative users to execute arbitrary commands. Nizam's approach to bug bounty hunting involves focusing on specific programs that interest him rather than any program he has access to, and he spends around 20-30 hours per week hunting bugs. When not hunting bugs, he enjoys spending time with his family and playing video games. He recommends using books, blogs, and videos as resources for learning, but also emphasizes the importance of practicing what you've learned by setting up a test lab. Nizam advises new hackers to be patient and persistent, and to focus on understanding not only the application itself, but also the layers it's built upon, including frameworks, programming languages, operating systems, and hardware. He hunts with Bugcrowd due to its supportive team, continuous improvements to the researcher portal, and variety of programs.
Jun 13, 2020
714 words in the original blog post.
At this critical moment in time, the entire country is grappling with the aftermath of George Floyd's murder, leading to widespread civil unrest and a collective awakening as individuals, companies, and society as a whole begin to acknowledge the need for change. As Bugcrowd stands in solidarity with the Black community and all those fighting against systemic racism and injustice, it recognizes that promoting racial equality requires sustained effort and thoughtful action. White Americans must understand their role in perpetuating racism and take steps to address it, acknowledging that racism is a complex system rather than just conscious hate. By having difficult conversations and making a commitment to change, companies like Bugcrowd can chip away at the vicious cycle of racism and discrimination, driving towards a better America where Black Lives Matter.
Jun 10, 2020
499 words in the original blog post.
The Vulnerability Rating Taxonomy (VRT) has been updated to version 1.9, with new entries for commonly submitted reports such as SSTI and Impersonation via Broken Link Hijacking, as well as a revamped Sensitive Data Exposure subcategory with more granular severity baselines. The VRT also includes suggested remediation steps for vulnerabilities of this type. Additionally, the update adds new entries for Flash-based CSRF dedicated issues, which will range from P5-P4. The VRT is a living document that is continually updated thanks to contributions from the broader security community and is designed to provide a baseline priority rating system for vulnerabilities reported within the Crowdcontrol platform.
Jun 10, 2020
715 words in the original blog post.
During these last few weeks my emotions have run the gamut from anger, to sheer disbelief, to anguish, to frustration and more recently hope as the world continued to mourn George Floyd's murder and police reacted unjustifiably to peaceful protesters. I participated in a rally in Palo Alto, California, organized by four teenage students, which highlighted the need for collective action against racism and inequality. The horrific death of George Floyd and Amy Cooper's use of racial biases are reminders that race continues to drive how black people are treated, consciously or unconsciously. A growing acceptance of the need for change was evident at the rally, with many acknowledging their own blind spots and vowing to take responsibility for driving positive change. An individual can make a difference by learning, participating, and helping drive change through personal and corporate actions, such as donating to Black Lives Matter, creating a diversity and inclusion task force, and implementing more balanced talent acquisition processes. A company like Bugcrowd is committed to taking action against systemic racism and injustice, standing in solidarity with the Black community and recognizing that this is not just a moment but a movement.
Jun 08, 2020
846 words in the original blog post.
Ninad is a cybersecurity enthusiast and ethical hacker from India who has been participating in Bug Bounty programs since 2018, focusing on various areas such as web-apps, mobile apps, APIs, and penetration testing. He currently works as an Application Security Engineer at ArisGlobal and hunts bugs part-time. Ninad started learning web development to gain a strong foundation for bug hunting and began working towards his CEH certification. After months of hard work, he successfully found his first bounty, which helped him pay off his education loan and buy a motorcycle. He now spends around 20 hours per week on bug hunting and uses various tools and resources to stay updated with the latest security issues. Ninad's advice for new hackers is to learn how to search effectively, have patience, and focus on understanding application logic and dependencies. When not hunting bugs, he enjoys road trips, watching Netflix, and sharing knowledge through writing blogs.
Jun 04, 2020
926 words in the original blog post.
We are excited to announce our P1 Warriors for Q1: February 1, 2020 – April 30, 2020! Our P1 Warrior program rewards valid P1 submissions and is an ongoing program that began as of January 1, 2019. We recognize the value of our exceptional researchers and reward them with swag and callouts. The top researchers in Q1 2020 have submitted five or ten valid P1 submissions for the first time, qualifying for stickers or challenge coins. Due to COVID-19, we are delaying shipping out the swag but plan to start shipping it in June. We will be sending out order links to those who have qualified for swag and invite researchers to visit our website to learn more about the program.
Jun 01, 2020
280 words in the original blog post.