Home / Companies / Bugcrowd / Blog / April 2022

April 2022 Summaries

5 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
The article provides guidance on navigating and utilizing the Bugcrowd Support portal for researchers and customers. It emphasizes the importance of providing excellent support while personalizing and humanizing the experience. The article highlights various resources available, including self-service solutions, documentation, and community forums, to help users find answers to their questions or needs before reaching out to the support team. It also explains how to reach out to the Bugcrowd Support team through the portal, provides information on what the team can assist with, and outlines the service level objectives (SLOs) for response times. The article aims to create a productive and efficient support experience while acknowledging that the infosec industry is still relatively new and the support team is learning alongside users.
Apr 28, 2022 1,045 words in the original blog post.
Crowdsourced security relies on collaboration between organizations and security researchers, which requires mutual trust, respect, and shared goals. This collaboration is essential for the success of crowdsourced security programs, such as Bugcrowd, where researchers are incentivized to provide valuable submissions in exchange for rewards. However, when interactions become unprofessional or abusive, it can deter talented researchers from participating. It's essential to remember that everyone involved is a human being with needs, wants, and desires, and treating each other with kindness and respect is crucial, even in disagreement. Bugcrowd has established a Code of Conduct that emphasizes the importance of being kind, respectful, and professional in all interactions, both within and outside the platform.
Apr 27, 2022 1,343 words in the original blog post.
Gartner predicts that by 2025, less than 50% of enterprise APIs will be managed due to explosive growth in APIs surpassing the capabilities of API management tools. The lack of proper management and security for APIs increases the attack surface for security teams, making it easier for attackers to breach organizations. Shadow and zombie APIs are a significant concern as they can lead to potential soft targets in an organization's attack surface. Attackers love these forgotten and neglected APIs, and according to Salt Security's research, API attacks were up 348% in the first six months of 2021. To combat shadow and zombie APIs, organizations need visibility and assurance that their APIs are resilient to attack. Traditional application security solutions alone are not enough, and a combination of Pen Testing as-a-Service solution, Bug Bounty solution, and Attack Surface Management solutions can provide effective protection for APIs.
Apr 27, 2022 540 words in the original blog post.
The Bugcrowd Security Knowledge Platform is now available through Red Hat Marketplace, an open cloud marketplace for enterprise customers to discover, try, purchase, deploy, and manage certified container-based software. The platform leverages the global ethical hacker community to offer multiple security use cases, including Penetration-Testing-as-a-Service (PTaaS), vulnerability disclosure programs, bug bounty programs, and attack surface management. This crowdsourced security approach has already shown its value in identifying exposure points before they can be exploited by malicious adversaries, such as during the Log4j incident where over 1,200 raw reports were submitted and validated on the platform. Red Hat Marketplace simplifies the process of finding and purchasing tools like Bugcrowd Security Knowledge Platform that are tested, certified, and supported on Red Hat OpenShift, a leading enterprise Kubernetes platform. This allows companies to easily deploy and manage these technologies on Kubernetes-native infrastructure with improved portability and confidence.
Apr 21, 2022 431 words in the original blog post.
The Bugcrowd Security Knowledge Platform helps organizations continuously identify vulnerabilities that other approaches may miss, providing a unique feature called the Industry Versus Organization Comparison Report. This report allows customers to benchmark their program's performance against industry peers, enabling them to augment or improve its overall performance and maximize value from the platform. By comparing their organization's performance with industry benchmarks, Bugcrowd customers can identify areas for improvement and make data-driven decisions to optimize their security programs.
Apr 05, 2022 223 words in the original blog post.