June 2023 Summaries
5 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd has achieved CSA STAR Level 1 (L1) accreditation, solidifying its commitment to high security standards for its customers. This certification is a testament to the company's robust security practices and rigorous risk management. The Cloud Security Alliance's STAR certification program combines industry-leading best practices with proprietary cybersecurity control frameworks to create a comprehensive cloud security control set. By achieving L1 accreditation, Bugcrowd demonstrates its dedication to transparency and accountability while maintaining a robust security posture and detecting vulnerabilities in its platform. This certification enables the company to offer customers a higher level of trust and assurance in its services.
Jun 30, 2023
390 words in the original blog post.
As researchers identify vulnerabilities in applications, they may encounter duplicate findings that can be challenging to evaluate. Bugcrowd's approach to duplicate evaluation considers three key principles: touching the code or making a change, similar issues being distinct; and many instances not necessarily indicating systemic problems. In scenarios where multiple SQLi vulnerabilities are reported across different queries and resources, it is essential to realize that each vulnerability may require a separate fix, even if they appear to be of the same type. Similarly, reflected XSS vulnerabilities with common parameters can be unique findings, but their similarity should not lead to duplication. In cases where CSRF vulnerabilities are identified on multiple pages or endpoints, many instances do not equate to systemic problems, and each finding may require a separate fix. By considering these principles and evaluating context, clients can ensure fair recognition and reward for unique findings while avoiding unnecessary duplication.
Jun 29, 2023
1,759 words in the original blog post.
Axis Communications, an industry leader in video surveillance and IoT security solutions, is spearheading the way for device cybersecurity by developing a multi-layered approach that focuses on enabling a smarter and safer world. The company has integrated cybersecurity considerations into its entire development lifecycle, working with external security researchers and ethical hackers to improve product security. By partnering with Bugcrowd's platform and solutions, Axis Communications has created a comprehensive cybersecurity protection strategy for its customers, leveraging the "crawl, walk, run" philosophy and CrowdMatch capabilities to engage skilled external security researchers who understand IoT device knowledge. This approach has helped identify, confirm, patch, and disclose multiple vulnerabilities in Axis OS, while maintaining comprehensive protection for customers through integrated programs of activity using the Bugcrowd platform. By prioritizing cybersecurity and engaging with a crowd-sourced security model, Axis Communications is building trust with its customers and contributing to a smarter, safer, and more cybersecure world.
Jun 27, 2023
621 words in the original blog post.
BusesCanFly is a captivating blend of student, hardware reverse engineer, and software vulnerability researcher with an insatiable thirst for the extraordinary. They got into cybersecurity by accident, fueled by endless curiosity and a lifelong sense of mischief, which eventually turned into a great hobby and career. BusesCanFly has been hunting bugs for roughly four or five years, with bug bounties introducing them to incredible people they're proud to call friends. They work part-time on hacking projects, spending anywhere from 0-20 hours a week depending on availability. Despite the challenges of deep diving into hardware and software vulnerabilities, BusesCanFly has found success and learned valuable lessons along the way. To avoid burnout, they remind themselves of their goals and motivate themselves with the knowledge that their love for doing cool things is what drives them. Outside of hacking, BusesCanFly enjoys rock climbing, 3D printing, and relaxing in the sun. They're grateful for the experiences and friendships they've had through Bugcrowd and are eager to continue exploring the world of cybersecurity.
Jun 27, 2023
792 words in the original blog post.
Infosecurity Europe is approaching, featuring Bugcrowd, with various opportunities for attendees to meet senior team members, including co-founder Casey Ellis and new hires Vlad Nisic. These include discussions on crowdsourced cybersecurity, networking events, and fireside talks with a customer and hacker. The event takes place from June 20-22 at ExCeL London, and details can be found by clicking the provided link to reserve your spot.
Jun 16, 2023
233 words in the original blog post.