August 2022 Summaries
6 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
In bug bounty programs, an open scope is the single most effective way to help secure an organization's external attack surface by leveraging a crowd to find and identify online exposures. A scope refers to the defined targets that are eligible for testing within a program. There are three main categories of scopes: Limited Scope, Wide Scope, and Open Scope, with expanding towards open scope being crucial as it allows researchers to test without limitations, making security posture more effective. Starting an open scope program requires guidance from a Bugcrowd Success Team, who can provide recommendations and support to help organizations secure their external attack surface.
Aug 31, 2022
442 words in the original blog post.
The adoption of cyber attack liability insurance has increased significantly over the years due to rising cyber attacks, resulting in higher premium costs. Insurers face challenges in understanding and managing risk, particularly with nation-state attackers and advanced persistent threats. The attribution problem makes it difficult to determine who is responsible for a cyber attack, with many cases being hard to attribute accurately. This has led insurance companies like Lloyd's of London to take a conservative approach and place the onus of attribution on policyholders. A lack of visibility into security posture is also driving how insurance companies calculate risk, highlighting the need for a cybersecurity platform that provides rich analytics and access to historical knowledge about vulnerabilities and remediation strategies.
Aug 30, 2022
484 words in the original blog post.
Managing a crowdsourced security program requires intentional effort and consistency to achieve desired outcomes. Unlike traditional approaches, crowdsourced security programs operate on economic principles similar to the rest of the world, relying on supply and demand for researcher participation. To attract and retain researchers, it's essential to create an attractive program that meets or exceeds existing market conditions, offering a level of attractiveness to outweigh other opportunities. This involves putting in work consistently, engaging with researchers respectfully and positively, rewarding quickly and fairly, improving over time, remediating findings, and staying in touch with the community. By following these guidelines and expectations, program owners can create a better atmosphere for testers and more value for their program overall.
Aug 25, 2022
1,980 words in the original blog post.
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, Department of the Treasury, and FinCEN have issued alerts for MedusaLocker and RagnarLocker ransomware families, highlighting the surge in ransomware attacks and the emergence of new business models such as RaaS gangs. MedusaLocker is an expansive family with capabilities including encrypting network drives, remapping them to encrypt content, and using ICMP sweeping to profile networks. It's primarily distributed via spam email and phishing, and has shown flexibility in shutting down security controls. RagnarLocker targets critical infrastructure sectors and has been successful in high-profile ransom attacks on companies such as Capcom and Dassault Aviation. To defend against these threats, organizations need to implement proactive security solutions, social engineering awareness and prevention training, and stay up-to-date with the latest threat intelligence.
Aug 23, 2022
705 words in the original blog post.
The Bugcrowd Security Knowledge Platform is enhancing its payment features with two new additions, Payment Threshold Amount and organization-wide transaction reporting and search. The first feature allows researchers to set a threshold amount for their rewards, which will be paid out in one total sum once the amount is reached, reducing bank fees. This feature also provides flexibility in managing payouts and can be used for tax purposes or to tailor payout schedules. Additionally, customers can now quickly and easily search transactions across all Bugcrowd-powered solutions, enabling them to manage their funds more efficiently. These new features aim to provide a best-in-class experience for both researchers and customers, saving time and money while maximizing funds.
Aug 04, 2022
654 words in the original blog post.
Paolo Arnolfo, also known as sw33tLie, is a full-time hacker who has been fascinated by computers and software since he was younger. He discovered bug bounty platforms three years ago and realized that he could make a living doing what he loved - hacking. Paolo enjoys writing security-related tools and collaborating with other hackers in the community. Bug bounties have made his life better on multiple levels, allowing him to collaborate with others, learn new things, and make new friends. Despite facing challenges such as staying focused and avoiding burnout, Paolo has found success and continues to grow as a hacker. He is currently focusing on automating his bug hunting skills and collaborating with other researchers in the Bugcrowd community. Outside of hacking, Paolo enjoys playing the piano and spending time with friends. He admires Guillermo Gregorio (@bsysop) for his expertise and camaraderie in the field.
Aug 01, 2022
1,212 words in the original blog post.