Home / Companies / Bugcrowd / Blog / March 2023

March 2023 Summaries

8 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
The UK's Computer Misuse Act is being updated to address evolving cyber threats and ensure that hacking activities with good-faith/benevolent motives are not prosecuted. The government is consulting on a potential statutory legal defence for hackers with benevolent intentions, which could "advance our whole of society approach to cyber security". However, there is also concern about unintended consequences. Bugcrowd believes the UK needs to adopt similar protections to those in the US, where legitimate security research activities are supported and protected. The consultation closes on April 6th, 2023, and Bugcrowd encourages individuals and organisations to contribute their views to ensure a safer online environment.
Mar 28, 2023 412 words in the original blog post.
Crowdsourced security is only as successful as the hackers and researchers with whom it collaborates, and matching and activating the right individuals is crucial to success. While focusing on the number of researchers can be logical, considering the diversity of perspectives within a crowd provides more comprehensive results. Different hacker roles, including Beginners, Recon Hackers, Deep Divers, Generalists, and Specialists, bring unique value to crowdsourced security programs. Each role has an important role to play in a given program, and understanding these roles is essential for maximizing contributions. Bugcrowd's engineered approach intelligently sources and activates the right role types and skills for programs at the right time, unlike other providers that rely on leaderboards or coarse-grained methods.
Mar 22, 2023 1,109 words in the original blog post.
The P1 Warrior Program is a recognition of researchers who submit valid P1 submissions, enhancing the security posture of various industries. The program rewards researchers for their contributions since January 1, 2019, with incentives based on the number of valid P1 submissions made. This year's winners have demonstrated significant knowledge and effort in identifying and submitting high-severity bugs, earning them the title of Level 5 or Level 4 Warriors. The Bugcrowd community is eager to see what next year will bring, and researchers are encouraged to sign up for a researcher account to join the hunt and start their hacking journey.
Mar 21, 2023 235 words in the original blog post.
Bugcrowd, a platform that attracts top researchers to discover and resolve complex bugs, recognizes hackers who consistently excel across its bounty programs with the MVP program. The program rewards researchers who reach the top of priority percentiles for an entire quarter, as seen in 2022's winners, who were recognized for their exceptional technical skills and remarkable submissions. The Bugcrowd team is in awe of these exceptional contributors, who contribute to a safer internet, and sincerely appreciates them for their efforts. The MVP program is exclusive and comes with swag rewards, and researchers can earn this status by consistently performing well across the platform. Researchers with 4, 3, or 2 MVP quarters in 2022 were recognized as winners, and Bugcrowd encourages all users to sign up and start their hacking journey to potentially join them.
Mar 21, 2023 312 words in the original blog post.
The Bugcrowd community has been recognized for its outstanding work in making the internet a safer place through various awards, including the Top Program Awards, Best Communication Award, Researchers' Choice Award, and others. The winners of these awards are selected based on their contributions to the Bugcrowd platform and their commitment to security testing. This year's top performers include FIS, HP Printers, Bsysop, OrwaGodfather, Mzamat, Tess, and elmahdi. The awards aim to recognize the hard work and dedication of researchers, program owners, and community members who have made significant contributions to Bugcrowd's mission.
Mar 21, 2023 1,202 words in the original blog post.
The text discusses the exciting world of hacking and its potential rewards, including being part of a vibrant community and earning significant income. However, it acknowledges that starting this journey can be intimidating due to scattered resources and lack of practical application opportunities. To address this issue, Bugcrowd has partnered with Katie Paxton-Fear (InsiderPhd) to create an ultimate hacking series designed for learners at all levels. The comprehensive course covers various aspects of hacking and is divided into 6 phases, ensuring a sequential learning experience. Additionally, live sessions with top hackers will be conducted after each phase to answer questions and provide hands-on examples. This engaging series aims to help users develop foundational knowledge in hacking through weekly video tutorials, write-ups, live demonstrations, and the Bugcrowd Platform. The first drop is scheduled for Sunday, March 19th, at Bugcrowd University, with further updates available on Twitter, Instagram, and Discord.
Mar 15, 2023 366 words in the original blog post.
Bl3ep, also known as Jo, is a human who enjoys finding things, breaking things, and lying for fun and profit. She got into cybersecurity through her tertiary education in Information Security and Criminology. Her interest in hacking was sparked by a YouTube talk on DEFCON Las Vegas, which sounded like a potential career path that could keep her interested for decades. Bl3ep finds inspiration from other women in the field, including Zemmiph0bia, momowowo, pamoshea, and pink_tangent. She has been hunting bugs since university and has found bug bounties to be helpful financially. As a female hacker, she enjoys the challenge of constantly learning and improving her skills, which brings diversity to the field. Bl3ep's biggest challenge is staying consistent in her hacking routine, but she overcomes it by making it a disciplined part of her daily life. She recommends online courses, virtual labs, and Capture the Flag challenges as resources for learning. For young women interested in bug bounties, Bl3ep advises to stop thinking about doing it and start, reach out to like-minded people for guidance, and prioritize self-care and mental health. In her personal life, she enjoys gardening, painting, locksport, pole dancing, and making charcuterie. She identifies as a red teamer and is still exploring career aspirations.
Mar 08, 2023 1,160 words in the original blog post.
Hackers on the Hill`, a program that brings together hackers and policymakers to address technology policy matters, held its first meeting at the White House, marking an important milestone in bridging the gap between the tech industry and government. The event brought together around 30 hackers, including security researchers, to provide input on the National Cyber Strategy, a document that aims to rebalance responsibility for cybersecurity and elevate it as a team sport. The inclusion of coordinated vulnerability disclosure in the strategy and the invitation from the hacker community to shape its formation demonstrate a significant shift towards valuing the contributions of good-faith hackers in the fight against cyber threats. This event is a testament to the growing recognition of hackers as an important part of the Internet's immune system, and it marks an exciting evolution in the relationship between builders and breakers in cybersecurity.
Mar 03, 2023 704 words in the original blog post.