July 2023 Summaries
4 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
The U.S. Securities and Exchange Commission (SEC) has adopted new rules for Cybersecurity Risk Management, Governance, and Incident Disclosure, mandating transparent and timely disclosure of cyber risks and incidents to the public. Organizations must now disclose material cyber incidents within four days of determining their criticality, outline their processes for assessing and managing material risks, and provide board oversight for cyber risk management. To comply with these new rules, organizations must have in place processes, plans, and policies for identifying, assigning criticality to incidents, mitigating weaknesses, and remediating vulnerabilities. The SEC's new rules introduce a balancing act between transparency and security, which may pose challenges for companies, but also provide opportunities for hackers and security experts to help organizations expand their security capabilities quickly.
Jul 27, 2023
696 words in the original blog post.
Cybersecurity is not a box to be checked but a constant battle between attackers and defenders trying to keep organizations secure. Many organizations are turning to crowdsourced security models, such as bug bounty programs, penetration testing, and vulnerability disclosure programs, which connect them to the ethical hacker community. To evaluate crowdsourced security vendors, it's essential to prioritize key criteria, including vendor reputation, pricing transparency, and ability to address specific security needs.
Jul 24, 2023
251 words in the original blog post.
Aleo has partnered with Bugcrowd to launch its first bug bounty program, inviting hackers from around the globe to test its security defenses and help shape a more secure blockchain ecosystem. The program offers an initial reward pool of $500,000 USD, divided into two tiers, with rewards ranging from $5,000 to $25,000 for discoveries of critical vulnerabilities. To participate, hackers must join the Bugcrowd platform and follow detailed instructions and guidelines. This collaboration between Aleo and Bugcrowd aims to foster a strong and secure blockchain ecosystem, with a focus on security at the forefront.
Jul 20, 2023
478 words in the original blog post.
The 2023 edition of Inside the Mind of a Hacker has been released, featuring analysis of 1000 survey responses from hackers on the Bugcrowd Platform and millions of proprietary data points on vulnerabilities collected across thousands of programs. The report aims to clear through the fog around hackers and crowdsourced security, helping organizations understand how to partner with hackers as an extension of their often under-resourced security team. It also delves into the use of generative AI by hackers, highlighting that many top hackers consider it a tool to leverage, not a threat, and that CISOs are taking its potential cybersecurity risks seriously. The report features new statistics and learnings, including the fact that 89% of hackers believe companies are increasingly viewing them in a more favorable light, and that even in an uncertain economy, the motivations of hackers remain altruistic.
Jul 12, 2023
528 words in the original blog post.