Home / Companies / Bugcrowd / Blog / May 2024

May 2024 Summaries

14 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
At a recent Bugcrowd North America Customer Advisory Board Meeting, attendees engaged in interactive discussions with customer leaders about various topics including making AI conversations actionable and leveraging hacker skills in security programs. The importance of finding the right skillset for hackers and pentesters was also emphasized due to the emerging AI attack surface. Additionally, the meeting highlighted the value of collaboration between security minds and the hacking community, as well as the fun and creative aspects of these interactions, such as a cooking class with talented CISOs.
May 29, 2024 526 words in the original blog post.
The UK's Product Security and Telecoms Infrastructure (PSTI) Act, the EU's Network and Information Security 2 (NIS2) Directive, the Digital Operational Resilience Act (DORA), and the Cyber Resilience Act (CRA) are four emerging cybersecurity regulations that will have significant impacts on organizations worldwide. The PSTI Act requires manufacturers to self-attest security vulnerability reporting mechanisms, while NIS2 strengthens and streamlines security requirements for medium and large-sized companies in critical infrastructure sectors. DORA aims to rationalize cybersecurity risk regulations governing financial services entities across EU member countries, and the CRA seeks to ensure that hardware and software products have fewer vulnerabilities throughout their life cycle. To comply with these regulations, organizations must review their products, supply chains, incident response plans, vulnerability management processes, and testing approaches, and consider using Bugcrowd's platform to achieve compliance and elevate their cybersecurity posture.
May 28, 2024 1,224 words in the original blog post.
The Bugcrowd Platform has acquired Informer, a leading provider of attack surface management (ASM) and continuous penetration testing, in a strategic expansion of its capabilities for customers. The acquisition marks the first major move by Bugcrowd following a $102 million fundraise and underscores its dedication to ongoing growth and innovation. With this deal, Bugcrowd enhances its value proposition by bringing together Informer's asset discovery and monitoring capabilities with its existing crowdsourced security platform, creating a more comprehensive solution for customers. The acquisition is expected to disrupt the traditional penetration testing market and give Bugcrowd a sustained competitive edge in the crowdsourced security industry.
May 23, 2024 343 words in the original blog post.
Penetration testing and bug bounty programs are complementary approaches to cybersecurity risk management, with the former focusing on proactive vulnerability assessment and the latter on identifying high-impact vulnerabilities through a crowdsourced approach. Pen testing is typically time-bound, methodology-driven, and done privately, while bug bounty engagements cover finding hidden flaws that pen tests might miss, leveraging ongoing discovery of emerging or hidden vulnerabilities with a freestyle approach. The two approaches differ in intensity, with pen testing being more checklist-driven and bug bounty being more pay-for-impact. A layered strategy combining these approaches can lead to increased efficiency and cost savings, making penetration testing as a service a viable option for organizations seeking to enhance their cybersecurity posture.
May 22, 2024 1,669 words in the original blog post.
Bugcrowd has demonstrated a commitment to innovation and growth, recently releasing new AI solutions after securing $100 million in funding. The company prioritizes transparency, open communication, and fostering an environment that unleashes innovation and ingenuity among its top cybersecurity talent. A strong focus on creating meaningful career opportunities for employees is also evident, with training programs and clear career paths being rolled out to support employee growth and progression.
May 21, 2024 1,098 words in the original blog post.
Bugcrowd is a crowdsourced security platform that connects hackers with organizations worldwide through pen testing, vulnerability disclosure programs, bug bounties, and more. The platform has a wide range of targets, including web, API, iOS, Android, automotive, and binary apps, and stands out for its standardized bug rating system (VRT) and support team. With no shortage of security risks today, Bugcrowd seamlessly connects hackers with customers in need, resulting in high rewards and a more secure online ecosystem. The platform offers various programs, including public, private, and vulnerability disclosure programs, as well as opportunities for penetration testing and career growth. Bugcrowd values its community and provides a supportive environment, with quick triage times, transparent communication, and a "Make-It-Right" policy to ensure that hackers' efforts are not lost due to misalignment between parties involved. Joining the platform is easy, with resources available for getting started, including a researcher portal, CrowdMatch technology, and comprehensive guides. Overall, Bugcrowd provides an opportunity for hackers to grow their skills while earning rewards and connecting with a community of like-minded individuals.
May 21, 2024 832 words in the original blog post.
In the realm of artificial intelligence, organizations face numerous security vulnerabilities that can compromise their systems and data. To address these concerns, penetration testing has emerged as a crucial tool for identifying potential threats before they cause harm. Penetration testing involves simulating real-world attacks to assess an AI system's security controls, plugins, and overall resilience. This process helps organizations uncover weaknesses in authentication mechanisms, input verification, output validation, and social engineering tactics. As AI systems become increasingly complex, it is essential to employ specialized pen testers who understand the intricacies of these systems and can take a multi-pronged approach to testing their security. By leveraging techniques like red teaming, insider threat simulation, and AI-powered model-based red teaming, organizations can ensure that their AI implementations are secure and reliable. Ultimately, proactively carrying out robust AI pen testing is crucial to harnessing the full potential of AI without compromising security.
May 14, 2024 2,083 words in the original blog post.
The tech industry is racing to integrate AI into their systems and product offerings, but this has led to a growing concern about the risks associated with running AI systems. The Open Worldwide Application Security Project (OWASP) has released its first Top 10 for Large Language Model Applications, highlighting security vulnerabilities such as prompt injection, insecure output handling, model denial of service, insecure plugin design, excessive agency, sensitive information disclosure, training data poisoning, overreliance, model theft, and supply chain vulnerabilities. These risks can be exploited by threat actors to execute malicious instructions, reveal confidential data, disrupt AI programs, and cause financial losses for companies. To help organizations prioritize these vulnerabilities, the Bugcrowd VRT is an open-source taxonomy that aligns customers and hackers on a common set of risk priority ratings. The OWASP Top 10 aims to educate developers, designers, architects, managers, and organizations about potential security risks in AI systems.
May 14, 2024 757 words in the original blog post.
To get private invites at Bugcrowd, researchers must stay active on the platform by hunting, making submissions, and getting paid. The CrowdMatch system automatically curates crowds based on criteria such as researcher skill sets, interests, and availability, and rewards active researchers with more private invites. By submitting valid reports and getting paid, researchers increase their eligibility for private invites and show impact to maximize their inbox activity. Even new or inactive researchers can get back into the hunt by making submissions and showing their skills, and staying informed about future opportunities through Bugcrowd's Twitter, Discord, and blog posts.
May 07, 2024 724 words in the original blog post.
Amazon developed an AI recruiting tool that discriminated against women, with resumes containing words like "women's" being ranked lower than they should have been. The tool was killed within a year, but it highlights the issue of AI bias and its causes, such as representation bias, pre-existing bias, algorithmic processing bias, aggregation bias, and general skewing. AI bias can manifest in various ways, including stereotypes, misrepresentations, prejudices, and derogatory language. It can also have significant impacts on applications, such as chatbots, healthcare, and criminal justice, leading to biased outcomes that exacerbate societal biases. To mitigate AI bias, it's essential to pre-process training data, use evaluation datasets, evaluate models at scale, fine-tune models on unbiased responses, and defend against AI bias through techniques like prompt injection detection and AI bias assessments. By acknowledging the issue of AI bias and taking steps to address it, developers can create more fair and transparent AI systems that serve diverse user groups.
May 07, 2024 2,186 words in the original blog post.
Meet Neiko, also known as Specters, a skateboarder by day, punk music enthusiast by night, and a full-time skilled hacker in between. He was born in Chicago and pursued professional skateboarding before breaking his leg. Specters is deeply entrenched in the world of hacking and cybersecurity, specializing in car hacking and malware analysis. His journey into hacking began as a means to achieve stability and financial security during a tumultuous time in his life. Bug bounties played a crucial role in his journey, providing him with the means to escape homelessness and build a better future. Specters now focuses on giving back to his community through organizations like Hack the Hood and Boards 4 Bros. He is passionate about helping others and offering up a path out, despite facing challenges such as lack of Hispanic representation. Despite burnout, Specters finds solace in outdoor activities and hobbies outside of hacking, including skateboarding, kickboxing, and Counter Strike Global Offensive. His journey is far from over, with goals to buy a house, continue giving back, and contribute to his community through skateboarding and park building.
May 06, 2024 1,169 words in the original blog post.
Bugcrowd is announcing its new VDP Compliance offering, a free-to-use platform that provides a simple and guided method for organizations to publish a disclosure policy alongside a vulnerability portal on their corporate website. This solution is designed to help organizations meet regulatory requirements and standards by providing a secure channel for externally-sourced security feedback from the security community. The platform aims to democratize VDPs, making them more accessible to those who lack internal resources or experience in building their own. With VDP Compliance, organizations can improve security transparency, reduce risk, and enhance their reputation, while also accelerating digital transformation and making better decisions on security initiatives. By providing a free-to-use solution, Bugcrowd is committed to helping organizations around the world build a stronger security posture.
May 02, 2024 610 words in the original blog post.
As AI technology continues to be rapidly commercialized, new potential security vulnerabilities are emerging, making it essential for organizations to test their Large Language Model (LLM) applications and other AI systems for common security vulnerabilities. To address this need, Bugcrowd has launched AI Penetration Testing, a service that helps uncover the most common application security flaws in LLMs and other AI applications using a testing methodology based on the OWASP Top 10. Regular pentesting of AI applications is crucial to maintain trust and protect user data, especially considering the sensitive information handled by these systems. The service includes vetted pentesters with relevant skills, 24/7 visibility into timelines and findings, and a detailed final report, allowing organizations to stay ahead in the field of AI security which is still in its early stages and new vulnerabilities are likely to emerge.
May 01, 2024 510 words in the original blog post.
Bugcrowd is participating in RSA Conference in San Francisco from May 6-9, with a booth at Moscone Convention Center and various expert presentations and events, including an AI safety roundtable dinner and the Secure Software Speakeasy. The company will also be hosting sessions on crowdsourced security, the Inside the Mind of a Hacker report, and more. Bugcrowd's leadership team is available for meetings in advance to discuss challenges and learn about the platform. The event offers opportunities for networking with security professionals and learning about AI safety and security.
May 01, 2024 466 words in the original blog post.