February 2024 Summaries
13 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd has secured $102 million in strategic growth financing to scale its AI-powered security platform, marking a significant milestone for the company. The funding announcement was accompanied by bold marketing efforts, including a billboard unveiling on the Nasdaq tower in Times Square and a tour of the New York Stock Exchange (NYSE). The executive team took a tour of the NYSE, highlighting the historical significance of the building and the company's own place in history. A day later, the team gathered in Times Square to witness the unveiling of their new billboard, which featured bold typography and color blocking inspired by classic print ads. The funding and marketing efforts demonstrate Bugcrowd's commitment to innovation, customer experience, and community engagement, positioning the company as a leader in the crowdsourced security market.
Feb 29, 2024
1,271 words in the original blog post.
The Bugcrowd Technical Customer Success (TCSM) team plays a crucial role in the success of crowdsourced security platforms, bridging the gap between customers and hackers to ensure program launch, growth, and sustained success. As Team Lead of the TCSM team, Elle Green emphasizes the importance of collaboration, understanding customer needs, and providing diverse solutions tailored to individual requirements. The TCSM team's focus is on client satisfaction, consistently exceeding expectations through regular communication, establishing clear expectations, asking questions, providing feedback, and fostering trust. By partnering with a Technical Customer Success Manager, customers can maximize their investment in crowdsourced security programs and achieve optimal benefits from their platforms.
Feb 28, 2024
833 words in the original blog post.
Bugcrowd has spent a decade launching and optimizing its cybersecurity programs for top organizations, resulting in valuable insights into data-driven outcomes. The company invests heavily in knowledge graph technology as the foundation for its rich data models that power its AI platform. A knowledge graph is a representation of relationships between data entities, often revealing insightful connections. In Bugcrowd's case, it powers its Security Knowledge Graph, which enables data-driven outcomes such as crowd matching, engineered triage, and recommendations. The Security Knowledge Graph grows in value as it expands, making it an essential tool for long-term success.
Feb 27, 2024
485 words in the original blog post.
Tango, a company that delivers secure incentive programs for organizations, recognized the need to enhance its security capabilities due to rapid digital transformation and an expanding attack surface. The company enlisted the Bugcrowd Platform's Managed Bug Bounty service to collaborate with hackers and identify vulnerabilities in its services beyond automated tools' reach. This collaboration transformed Tango's approach to identifying new cybersecurity threats, enhanced its security posture, and mitigated potential risks while strengthening customer trust. By integrating vulnerability identification into their DevSec tools and processes, Tango's developers could fortify new features against potential threats, ensuring compliance with security audits and regulations. The partnership exemplifies how aligning security strategies with rapid innovation can address complex cybersecurity challenges, helping Tango secure its operations and prepare for future growth.
Feb 22, 2024
523 words in the original blog post.
Bug bounty programs rely on harnessing the skills of the world’s security talent, known as The Crowd, offering continuous coverage for assets and quickly surfacing novel vulnerabilities. They are effective in reducing cost per vulnerability compared to other security solutions, engaging a diverse group of hackers, allowing for continuous improvement and perpetual learning, providing a cost-effective way to discover vulnerabilities and triage risks, contributing to a reputation for taking security seriously among hackers and the broader security community, offering continuous assurance that allows companies to maintain the highest standard of security for critical assets. Companies can participate in bug bounty programs by partnering with third-party managed providers or creating their own internal program, which should be tailored to their specific needs and priorities. The key to success lies in getting the brief right, setting out clear expectations for hackers, providing a concise and unambiguous brief that sets direction on what success looks like.
Feb 20, 2024
1,849 words in the original blog post.
At the beginning of November 2023, Bugcrowd launched its annual Hacker Cup, a two-month long hacking competition with a theme of "Hack Hack Revolution", which resulted in over half a million dollars worth of vulnerabilities rewarded. The competition was won by Team 12345 consisting of hackers ZwinK, r0ver, and Nim5079, who earned a grand prize of $10K and exclusive swag. Over 70 different bug bounty programs participated, with 15 customers offering bonuses to their bounty payments, making the majority of customers safer with at least one valid vulnerability identified during the testing period.
Feb 15, 2024
362 words in the original blog post.
Rapyd, a fintech company, has successfully launched a public bug bounty program after years of using crowdsourced security and partnering with Bugcrowd to achieve this goal. The company uncovered almost 40 unique vulnerabilities, including 15 critical ones, through their program. To make their program successful, Rapyd found the right hackers for specific programs, built confidence in their security posture across the organization, and leveraged expertise from the Bugcrowd team. By following these tips, other companies can learn how to successfully take a bug bounty program public.
Feb 14, 2024
370 words in the original blog post.
With Valentine's Day approaching, the author reflects on the "unlikely romance" between hackers and security teams, challenging common stereotypes that hackers are faceless cybercriminals. Instead, they describe hackers as experts in programming and problem-solving who work to protect organizations from threats. The author argues that partnering with hackers can help CISOs and security leaders address challenges such as the cybersecurity skills gap and evolving attack surfaces. By leveraging crowdsourced security models, CISOs can extend their team's reach, identify vulnerabilities earlier, and decrease operational risk. To build successful relationships with hackers, CISOs must find quality over quantity, invest in triage capabilities, and foster goodwill through responsive communication and program rewards. Crowdsourced security platforms like Bugcrowd can facilitate these partnerships, enabling CISOs to partner with the hacker community as an extension of their team.
Feb 13, 2024
1,100 words in the original blog post.
Taking on the role of CEO at Bugcrowd marked a transformative journey for the company, with an unwavering focus on its core values. The company has successfully secured $102 million in strategic growth financing, led by General Catalyst, to scale up its AI-powered crowdsourced security platform and drive continued innovation. This investment reflects the commitment to proactive cybersecurity and empowers organizations to identify and remediate security vulnerabilities before malicious actors can exploit them. With this funding, Bugcrowd aims to accelerate its growth across EMEA, APAC, and the U.S., both organically and through strategic M&A opportunities. The company's mission to redefine crowdsourced security is underscored by the dedication of its team, hacker community, and customers, who trust in its innovative approach to proactive security. Bugcrowd has achieved remarkable success in the past year, with notable clients like OpenAI, T-Mobile, and ExpressVPN, and its team has grown significantly, contributing to an overall business growth of more than 40% year-over-year. The company looks forward to continued growth, innovation, and collaboration with its stakeholders.
Feb 12, 2024
461 words in the original blog post.
We’ve officially kicked off our 2024 financial year at Bugcrowd, starting with a bang. The company has seen significant growth, with over 130 new team members joining in 2023 and anticipating even more growth in 2024. This year marks key leadership promotions, including Emily Ferdinando as Chief Marketing Officer, Tanya Gay as Chief Operating Officer, and Cassandra Morton as Senior Vice President of Global Customer Success and Account Management. Bugcrowd has also made a strategic hire in Julian Brownlow Davies as Vice President of the Advanced Services Group, who will lead the company's pen testing-as-a-service industry growth. With these new leadership additions, Bugcrowd is poised to disrupt crowdsourced security and help clients connect with the hacker community to beat threat actors at their own game.
Feb 08, 2024
523 words in the original blog post.
Bugcrowd has had a record-breaking year, with over 200 new clients joining the platform and significant growth in hacker payment volume and customer outcomes. The company has also seen a tremendous amount of growth in its community, including over 50,000 new hackers joining the platform and hundreds of thousands of vulnerabilities submitted. Bugcrowd's focus on driving value for customers and hackers has been a key priority, with the company prioritizing long-term success and transparency in its approach to crowdsourced security. The company has also continued to build its culture, innovate, and inform public policy, while empowering a global ecosystem of trusted partners. Looking ahead to 2024, Bugcrowd is focused on continuing to take care of each other, customers, and the hacker community, with a focus on supporting organizations looking to revamp their legacy bug bounty and pen testing programs.
Feb 06, 2024
843 words in the original blog post.
This director of cybersecurity at a leading data networking organization is seeing significant changes in the threat landscape since the pandemic, particularly in the complexity of security threats and the prevalence of AI-based cyber threats. The cybersecurity skills gap is a major concern for organizations, with the director predicting it will continue to increase in the short term unless adequate resources are invested in cybersecurity personnel. To address this, the organization partnered with Bugcrowd to establish a Vulnerability Disclosure Program, leveraging crowdsourced security expertise to manage vulnerabilities and reduce risk exposure. The partnership aims to proactively demonstrate commitment to security, build productive relationships with the hacker community, and stay ahead of innovation through security testing and remediation.
Feb 05, 2024
542 words in the original blog post.
The Ivanti vulnerability timeline reveals that multiple critical vulnerabilities were discovered in the software products Ivanti Connect Secure and Ivanti Policy Secure, with at least 30,000 instances of these products across the internet creating a significant opportunity for threat actors to exploit them. The US Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies disconnect all Ivanti VPN appliances by February 2, 2024, due to the high risk of exploitation and potential impact. This unprecedented move highlights the severity of the issue and emphasizes the need for organizations across various industries to take immediate action to patch these vulnerabilities and protect themselves against potential attacks.
Feb 01, 2024
293 words in the original blog post.