Home / Companies / Bugcrowd / Blog / November 2022

November 2022 Summaries

3 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Gal Nagli is an AppSec Engineer with two years of experience, who initially worked at Enso Security and later joined Salesforce. He also engages in bug bounties and develops automation tools to identify vulnerabilities in scale. Nagli has started his own Application Security B2B startup named shockwave.cloud, which is based on his research and methodology from his bug bounty journey. He got into hacking due to its perceived "superpowers" of finding critical severity with massive business impact on major corporations. Nagli's skills improved through consistent learning and practicing, and he has been actively hunting for vulnerabilities since 2.5 years ago. Bug bounties have impacted his life positively, allowing him to save financially and travel the world. Nagli considers himself part-time hacker, spending most of his time hacking as a hobby. His biggest challenge was maintaining consistency in finding bugs, but he overcame it by staying distracted with other activities and remembering that bug bounty is just "Gamification". Nagli recommends practical Udemy courses, focusing on small sets of bugs, and reading online documentation. He wishes he learned the importance of surrounding himself with like-minded people who share similar values. To avoid burnout, Nagli uses distractions that don't involve sitting in front of his computer. His goal is to continue finding impactful bugs and helping other companies close their security gaps through his startup product offering or occasionally on platforms.
Nov 11, 2022 1,218 words in the original blog post.
At Bugcrowd, ensuring that security researchers feel safe, valued, and motivated is crucial to the company's success. The triage experience is designed to meet this goal, focusing on fair and impartial treatment for all parties involved, speed and accuracy, and catching and learning from mistakes. To achieve these goals, Bugcrowd has implemented a consistent researcher experience through its in-house triage team, standardized bug and severity classification using the Vulnerability Rating Taxonomy (VRT), and guided communications and outcomes through workflows and templates. These efforts aim to create a predictable and rapid experience for researchers and program owners alike, enabling high-impact submissions and validation of findings.
Nov 10, 2022 771 words in the original blog post.
TX Group AG is the largest private media group in Switzerland, publishing a portfolio of newspapers, magazines, and digital platforms that reach over 80% of the Swiss population daily. The company has been targeted by cyberattackers, including a daily barrage of DDoS attacks in November 2020. In response, TX Group adopted bug bounty programs to improve security, choosing Bugcrowd for its managed platform and customized solution. The program has delivered outstanding results, discovering up to 20 times more vulnerabilities than initial audits and providing a direct link between security investments and results.
Nov 02, 2022 403 words in the original blog post.