October 2023 Summaries
7 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd's Hack Hack rEvolution event is an annual competition where teams of hackers can participate in various bug bounty programs to test their skills and compete for a grand prize of $10K. The event features 40 available spots, with selection based on aggregate totals of all-time P1s and P2s on the Bugcrowd platform. Teams will be assembled from participating members and must work together to earn points through non-duplicate submissions. Points are awarded differently for P1, P2, and P3 submissions, with bonus programs available for extra points. The competition consists of two challenge rounds, with eliminated teams receiving private program invites and swag. New hackers must work with Bugcrowd known hackers and complete a background check to participate, while last year's winning team will automatically qualify for the Top 8 but must compete in both rounds for final scores.
Oct 26, 2023
817 words in the original blog post.
The UK Government has issued a consultation on updating its 33-year-old Computer Misuse Act, which currently makes hacking of any kind technically illegal. The act's outdated nature is at odds with current policy statements and the growing trend of crowdsourced cyber security platforms like Bugcrowd, where organizations benefit from the skills of hackers for good purposes. Many experts believe that protection for researchers and ethical hackers is essential to support their work and prevent a "losing battle" against cybersecurity attackers. The UK Government has received public consultations on this issue in the past, but its response to the recent CMA consultation may take several months to materialize. Bugcrowd will be closely monitoring the response and representing the interests of the ethical hacker community.
Oct 23, 2023
551 words in the original blog post.
In a 1989 incident, hackers gained access to NASA's Galileo Probe system, displaying a humorous message that read "Your system has been officially WANKed" on the employees' screens two days before the probe's launch. This act of hacktivism was notable for its unusual tone and unexpected timing, highlighting the risks and costs associated with digital activism. The incident has become an iconic example of how hacking can be used to draw attention to a cause, in this case, concerns about nuclearization of space.
Oct 18, 2023
271 words in the original blog post.
This year's Cybersecurity Awareness Month theme is "Secure our World," highlighting the need for collective action to enhance online safety. Security professionals are facing increasingly serious threats and more difficult roles due to the pandemic, with 89% of them believing that security threats have worsened since then. The industry is also plagued by concerning trends, including terrifying consequences that linger beyond October, making this a critical awareness period.
Oct 17, 2023
264 words in the original blog post.
MGM Resorts International and Caesars Entertainment have recently experienced major cybersecurity breaches, with MGM's breach impacting digital systems such as hotel room keys to slot machines, and Caesars' breach resulting in the theft of information from over 1 million Maine residents. The breaches are believed to be the work of a Russia-based ransomware group called ALPHV, which uses social engineering tactics to gain access into organizations. These breaches have resulted in significant financial losses for the companies, as well as reputational damage. Gaming companies and casino giants are likely to continue being targeted by threat actors due to the lucrative nature of these attacks. To prevent such breaches, organizations should conduct tabletop exercises to test their response plans, examine business operations to make it harder for attackers to gain access, and utilize security testing and research communities like Bugcrowd to identify vulnerabilities before they can be exploited.
Oct 12, 2023
790 words in the original blog post.
ExpressVPN has implemented a managed bug bounty program with Bugcrowd to enhance the security of its user experience, uncovering nearly 100 valid vulnerabilities and streamlining reporting processes. The platform's engineered triage feature allows for rapid validation and prioritization of vulnerabilities, enabling ExpressVPN's engineers to focus on remediation instead of filtering noise. By leveraging Bugcrowd's CrowdMatch technology, ExpressVPN has matched skilled hackers with its needs, resulting in a higher number of reviewers with specialized skill sets relevant to the company's scope. The platform's straightforward nature and focus on customer needs have also been key differentiators for ExpressVPN.
Oct 10, 2023
427 words in the original blog post.
This is Cybersecurity Awareness Month, a time when vulnerabilities in cybersecurity are highlighted due to their potential for serious consequences. To celebrate, Bugcrowd has launched a new series called Unsolved Cyber Mysteries, which retells the stories of everyday people affected by extraordinary breaches and data leaks. The first episode focuses on the 1987 Max Headroom signal hijacking, where an unknown person in a mask appeared on TV screens for several minutes, causing widespread confusion among viewers, engineers, and broadcasters. The incident was eventually thwarted by changing the studio-to-transmitter frequency used to transmit the broadcast signal, but not before the hacker had shown himself dancing and making threatening gestures. The episode will explore the motivations behind the attack, its impact, and a breakdown of how it happened.
Oct 06, 2023
431 words in the original blog post.