August 2020 Summaries
11 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Cybersecurity researchers and ethical hackers play a crucial role in protecting society from bad actors. A conversation between Ashish Gupta, CEO at Bugcrowd, and Adrian Ludwig, CISO at Atlassian, highlights the journey of a security executive who started as an ethical hacker and now manages security for a diverse IT environment. The landscape of cybersecurity has evolved over the years, shifting from a technical issue to an organizational one, where security personnel focus on people, process, and organization. With experience on both sides, Adrian shares insights into the relationship between hackers and security personnel, noting that there's a better understanding now of what attackers do and how they work. To ensure everything gets fixed, Adrian trusts in his team and each member's ability to handle their specific area of responsibility. Crowdsourced security is used to identify blind spots, leveraging diversity and bringing it to the wider community through partnerships and bug bounty programs.
Aug 26, 2020
836 words in the original blog post.
The due diligence process for mergers and acquisitions (M&A) is complex and time-consuming, with security teams often facing tight deadlines to conduct thorough risk analyses. When evaluating potential solutions, organizations should consider factors such as Time to Launch AND Time to Value, Immediate access to the right resources matched by skill and experience, Streaming results from Day 1, A fully-managed approach, Expensive "Surprises", Delivering high-value results quickly, Prioritizing outcomes, Executive and Audit-Ready Reporting, Continuity and Relationship Preservation. Organizations should also look for solutions that provide standardized testing options, deliver a plan for providing gapless coverage, and enable the acquired company to continue leveraging the vendor post-sale. Additionally, solutions like Bugcrowd M&A Assessment can help organizations make quick, yet informed decisions about potential acquisitions and partnerships by providing advanced pen testing services combined with continuous coverage of software-based Asset Inventory solutions.
Aug 20, 2020
791 words in the original blog post.
Bugcrowd is introducing its M&A Assessment solution to help organizations assess risk of vulnerabilities or unknown attack surface in a dual-prong approach that combines software-based attack surface analysis and human-powered vulnerability discovery. The solution leverages the Bugcrowd platform to provide actionable insights on Day 1, enabling organizations to view uncovered assets and vulnerabilities as soon as they are discovered, with final executive reporting and recommendations delivered in under 3 weeks. M&A Assessment offers a unique combination of speed, accuracy, and confidence, making it an attractive option for organizations facing tight deadlines, as it provides a "deep & wide" approach that considers both pen test and asset inventory solutions, and is backed by Non-Disclosure Agreements to ensure confidentiality. The solution also includes real-time results, triage and prioritization of critical vulnerabilities, managed service options, incentivization programs for researchers, and executive reporting with actionable recommendations.
Aug 19, 2020
605 words in the original blog post.
The LevelUp0x07 tournament is a 24-hour challenge launching this weekend, where participants compete against each other in vulnerable code challenges based on the OWASP Top 10. The tournament allows developers to improve their secure coding skills and choose from various software languages. Additionally, a CTF Challenge with 7 flags to find is available until August 22nd, and a Virtual Conference will take place over two days starting at 6:00PM PDT on August 22nd and 5:00PM PDT on August 23rd. The event also includes a partnership with Secure Code Warrior.
Aug 19, 2020
223 words in the original blog post.
Our team has created a Capture the Flag challenge with rewards for LevelUp0x07: Hack Another Day, which starts on August 16th and runs through August 22nd. The challenge is web and mobile-based, testing security skills and collecting all 7 flags, each varying in difficulty. It includes real-world application challenges such as sensitive data exposure, authentication bypass, and JavaScript-based attacks. The challenge is part of a larger mission to stop a worldwide cyberattack using the WannaSpy ransomware, which aims to delete COVID-19 information globally. Agents are encouraged to join our Discord and Twitter for updates and submit their flags to receive rewards.
Aug 16, 2020
246 words in the original blog post.
The Ultimate Guide to Vulnerability Disclosure highlights the importance of Vulnerability Disclosure Programs (VDPs) in reducing risk across publicly accessible assets. VDPs enable organizations to extend security testing beyond routine cycles, surfacing critical vulnerabilities missed by internal testing and improving their overall security posture. By embracing VDPs, organizations can reduce risk, demonstrate commitment to security, and build a strong security brand, attracting investors, partners, and future employees. The report also emphasizes the value of managed programs like Bugcrowd, which provide platforms for accepting, validating, and prioritizing vulnerabilities, ensuring timely remediation and constant communication across stakeholders. With 28% of respondents reporting that VDPs are now mandatory for their industry, it's clear that VDPs have become a baseline security best practice.
Aug 13, 2020
1,139 words in the original blog post.
Bitdefender is a global leader in cybersecurity, protecting over 500 million systems for more than 18 years in more than 150 countries. The company's public bug bounty program aims to identify vulnerabilities in its products and infrastructure, with a current focus on its new billing and subscription platform. The program offers increased rewards for P1 and P2 vulnerabilities found in this area, including $4,650 for P1 and $7,500 for P1, as well as $2,000 for P2 and $4,500 for P2. The program is open to web-focused pentesters with relevant skills, and participants can expect support from the Bitdefender team in validating their reports and remediating discovered vulnerabilities.
Aug 11, 2020
339 words in the original blog post.
Bugcrowd is working to make Information Security a more gender-inclusive space through education, networking, mentoring, directly supporting Women in Security Organizations, and diversity-focused hiring practices. Confronting sexism is challenging but speaking out against bias is necessary for long-term change, and Bugcrowd encourages everyone to join in being inclusive and supportive of women in the community. The company acknowledges the existence of microaggressions and discriminatory language that can create feelings of intimidation and doubt, and provides resources to address these issues such as cyberbullying, bias, and sexism.
Aug 07, 2020
264 words in the original blog post.
While the pandemic presents challenges to in-person gatherings like Black Hat and DEF CON, dedicated security professionals and hackers continue to innovate and adapt. To make the most of this year's virtual lineup, attendees should prioritize digital hygiene by sanitizing their devices and using a burner phone or similar setup for an immersive experience. They can also tune into various panels, demos, events, chats, and meetups featuring notable speakers and security experts, including discussions on vulnerability disclosure in the medical sector, regaining control of a rogue satellite, and securing elections under uncertainty. Additionally, attendees can engage with communities through Discord channels and read interviews with Black Hat 2020 CISO Summit advisory board members to stay updated on current security trends.
Aug 06, 2020
809 words in the original blog post.
Farah, a self-proclaimed beginner in the InfoSec community, has gained popularity with her YouTube channel and bug bounty journey. She started sharing hacking resources on Twitter and LinkedIn in May 2020 and recently launched a full-time pentesting job with Inspira. Farah's content is valuable for anyone looking to improve their hacking skills, and she shares her experiences and tips on how to get into cybersecurity and hunting bugs. With the help of bug bounties, Farah has become more independent and met new people across the globe, working with great companies and landing a full-time job as a pentester. She currently spends 1-2 hours daily hunting bugs and recommends resources like the Web Application Hacker's Handbook and PentesterLab for learning and practice.
Aug 06, 2020
905 words in the original blog post.
The average iPhone app has a large codebase of just under 50,000 lines of code, making it challenging for organizations to identify vulnerabilities before production without compromising on cost or coverage. Vulnerability Disclosure Programs (VDPs) have become an essential security best practice, allowing organizations to discover and address external vulnerabilities in a cost-effective manner.
Aug 05, 2020
94 words in the original blog post.