Home / Companies / Bugcrowd / Blog / June 2022

June 2022 Summaries

5 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Ankit Singh, a Computer Science Engineering graduate, has transitioned from an Information Security Auditor role to become a full-time ethical hacker. He is passionate about web application hacking and enjoys exploring new attack vectors. Ankit attributes his success as a bug hunter to understanding technology and the creative approach of exploration that comes with it. He advises newcomers to learn everything they can about technology first, followed by practical experience through publicly disclosed bug reports. Ankit hunts primarily on Bugcrowd, appreciating their cooperative attitude towards the crowd. As a role model, he credits his mother for her unwavering support and sacrifice throughout his life. When not hacking, Ankit enjoys exploring nature, wildlife, painting, martial arts, meditation, and spirituality. He is also an avid dinosaur enthusiast.
Jun 30, 2022 1,252 words in the original blog post.
Social engineering is a serious threat that targets humans as a soft spot in the attack surface that can't be defended by technology alone.` Many organizations are surprisingly unprepared for social engineering due to lack of organizational awareness, outdated or inconsistent identity verification protocols, and shallow security practitioner skill sets. To address this, Bugcrowd has announced a strategic reseller partnership with SocialProof Security to provide social engineering prevention training, protocol review, and specialized penetration testing services. With these new services, customers can train employees to notice and report attacks, strengthen identity verification methods, and validate the effectiveness of training and protocol updates with a social engineering pen test. Additionally, Bugcrowd offers a comprehensive cybersecurity portfolio that includes a multi-solution Security Knowledge Platform for pen testing as a service, bug bounty, vulnerability disclosure, and attack surface management.
Jun 23, 2022 346 words in the original blog post.
Bugcrowd has introduced researcher submission templates to streamline communication between researchers, customers, and the platform, providing a standardized framework for crafting submissions, including details on business impact, steps to reproduce, and guidance on safe reproduction methods. The templates are now available with over 100 options, covering various VRT categories, and can be found on GitHub, where users can also contribute new templates and provide feedback.
Jun 14, 2022 677 words in the original blog post.
Submissions often fall under the same category, which means researchers are rewriting reports from scratch over and over again, losing time in submissions and triage. This can be inefficient and slow down the process of getting rewarded. To address this, Bugcrowd is introducing Researcher Submission Templates to speed up the submission process, resulting in faster triage times and rewards. The templates aim to provide clear and concise submissions that match researchers with the right programs, improving overall experience for both parties.
Jun 08, 2022 442 words in the original blog post.
Alexander Pick, a 39-year-old researcher, hardware hacker, and software security enthusiast, has been fascinated with technology since his childhood, starting with his C64 computer. He began learning programming and hacking through online tutorials and IRC communities, eventually landing a full-time job in the cybersecurity space. Outside of hacking, he enjoys other technical hobbies like HAM radio and spending time with his family, including his wife and 2-year-old daughter. Alexander attributes his success to hard work, persistence, and staying curious, advising others to start with something they're interested in and not be afraid to fail. He also emphasizes the importance of taking breaks and prioritizing mental health, citing traveling with his family as a key way to recharge.
Jun 04, 2022 674 words in the original blog post.