February 2023 Summaries
4 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
In light of recent high-profile hacks and incidents, it is crucial to maintain or even increase cybersecurity budgets in 2023. The short-term cost of a breach averages $4.35 million, with the global cost of cybercrime estimated to reach $10.5 trillion annually by 2025. Long-term costs include brand damage, regulatory fines, legal fees, and increased insurance premiums or cancellation. The U.S. Federal government is investing more in cybersecurity this year, recognizing the importance of protecting against cyber threats.
Feb 27, 2023
558 words in the original blog post.
The Bugcrowd Security Knowledge Platform integrates the crowd into any security use case or workflow by utilizing a robust API and outbound webhooks systems that allow for configuring capabilities to satisfy specific organization needs. The platform provides out-of-the-box capabilities for popular workflows, including inbound integrations with SDLC tooling such as Atlassian Jira or IBM SOAR, and offers notifications on important events via email or the web. New features include notification settings for submissions assigned any severity and for multiple submission states, allowing customers to take immediate action on potential security issues.
Feb 09, 2023
265 words in the original blog post.
Erik de Jong is a cybersecurity expert with a passion for securing the internet. He trained as an electrical engineer, specializing in embedded systems and communication between computer systems, before transitioning to a career in cybersecurity. Erik's interest in hacking began at age 7 when his dad taught him how to write simple computer programs. He has been researching and writing exploits on and off for about 15 years, with a significant portion of that time spent working as a part-time hacker. Erik credits bug bounties with having a major impact on his life, allowing him to buy a house and pursue his passion for cybersecurity. When not hunting for bugs, Erik works full-time as a security engineer at an internet service provider, where he is responsible for the overall security of the organization. He finds joy in finding ways to apply technical solutions to improve human behavior and workflow. Despite the challenges of managing expectations with vendors and avoiding burnout, Erik remains committed to personal growth and staying motivated through planning and self-care. With a focus on learning new skills, including reverse engineering software written in Go and serverless computing, Erik is always looking for ways to challenge himself and stay engaged in the cybersecurity community.
Feb 07, 2023
2,045 words in the original blog post.
The penetration testing industry is discovering the value of crowdsourcing, which allows buyers to curate precisely the right pentest team for their needs, diversify their view of the attack surface, and unlock a scaled pay-for-impact incentive model that reduces risk. However, some pen testing vendors are adopting a "crowd washing" strategy, making their offerings sound more modern and impactful than they really are by misrepresenting their capabilities or using buzzwords like "cloud" to rebrand old products. To avoid these tactics, buyers should look for providers with a credible track record, pay-for-impact incentives, and a platform that can deliver on the operational details of crowdsourcing at scale.
Feb 07, 2023
699 words in the original blog post.