July 2024 Summaries
9 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Ahoy matey! Cybersecurity professionals are gearing up for a voyage to Las Vegas, Nevada, seeking golden nuggets of cybersecurity insights and opportunities to network. Bugcrowd is hosting several events at Black Hat & DEF CON, including a treasure map that guides attendees to exclusive conferences, parties, and networking opportunities. The company will be represented at the Innovators and Investors Summit, Hack Lab CTF Challenge, Bsides Pool Party, Guidepoint DEF CON Party, AI Village's GRT2 Bias Bounty Program, and Intersecct VIP Event, offering a chance to meet the team, book meetings with executives, and win swag. These events are not in chronological order, but attendees can find more information on the dates associated with each event by visiting the provided links.
Jul 31, 2024
490 words in the original blog post.
The era of WiFi 6 and WPA3 has brought significant improvements in processing speeds and security technologies, but adoption of new protocols and hardware has remained slow, leaving many vulnerable networks still in use. Various types of WiFi attacks exist, including sniffing, injection, and cracking, which can be performed using tools like Wireshark, aircrack-ng, and bettercap. These tools allow attackers to intercept data packets, inject management frames, crack passwords, and even create rogue APs that trick clients into authenticating with real credentials. While WPA3 is not as vulnerable as WPA2, there is limited research on its security design, making it essential to transition to WPA3-protected setups, which are considered secure as long as passwords are not easily guessable.
Jul 24, 2024
1,934 words in the original blog post.
This blog post is a collaborative effort by three security researchers who discovered a novel HTTP Request Smuggling vulnerability, dubbed "TE.0". They found that thousands of Google Cloud-hosted websites using the Load Balancer were vulnerable to this attack, which could compromise sensitive data and resources. The researchers used their own tool, bbscope, to scan for vulnerable targets, and after experimenting with different payloads, they discovered a new smuggling class that could bypass Google IAP authentication and Zero Trust security measures. They reported the issue to Google, initially being met with skepticism, but eventually receiving recognition and a $8,500 bounty. The researchers emphasize the importance of persistence and creative thinking in uncovering vulnerabilities and encourage others to explore their interests deeply.
Jul 17, 2024
1,672 words in the original blog post.
Bugcrowd's recent report "Inside the Mind of a CISO" surveyed 209 security leaders worldwide to understand their current priorities and challenges. The report debunks five common myths about CISOs, including that they are opposed to ethical hacking (73% view it favorably), mainly management professionals (84% have at least six years of experience in the field), only needed by large companies (20% lead teams with fewer than 10 members), unprepared for AI (95% implement AI-based defensive measures), and all believe in the value of AI (58% see risks outweighing benefits). The report also highlights the state of current threats, AI usage, and hiring landscape.
Jul 17, 2024
507 words in the original blog post.
The Bugcrowd Platform has released version 1.14 of its Vulnerability Response Tool (VRT), expanding on its commitment to AI security by adding a new category: Data Bias Vulnerabilities. This update aims to mitigate the risk of AI perpetuating social harm through bias and discrimination, aligning with government regulations such as Executive Order 14110 and the EU Artificial Intelligence Act. The new categories focus on representation bias, pre-existing bias, processing bias, aggregation bias, confirmation bias, systemic bias, context ignorance, and developer biases. Additionally, this update includes several new vulnerability types, including email verification bypass, missing subresource integrity, token leakage via referer, software package takeover, privilege escalation, and removed broken authentication and session management issues. The VRT continues to evolve as hackers, Bugcrowd Application Security Engineers, and customers contribute to its development through Issues and Pull Requests.
Jul 16, 2024
1,175 words in the original blog post.
CISO priorities in 2024 include regulatory obligations due to increasing government oversight and AI policy, addressing burnout caused by the immense burden of potential breaches, closing the cybersecurity skills gap with the adoption of GenAI technologies, focusing on security outcomes rather than traditional security silos and products, taking a risk-driven approach to security alongside compliance, prioritizing professional development to stay sharp on technical skills, managing legal exposure through D&O insurance, and reducing cyber insurance premiums by demonstrating proactive security risk management. These priorities reflect the evolving landscape of cybersecurity challenges and the need for CISOs to adapt their strategies to address them.
Jul 10, 2024
813 words in the original blog post.
George Gerchow, a veteran security industry leader, joins Bugcrowd's Advisory Board with over 20 years of IT and systems management expertise. His extensive background in security, compliance, and cloud computing disciplines will be crucial for the Bugcrowd team as they continue to grow. George brings his experience from roles such as Head of Trust at MongoDB, Chief Security Officer at Sumo Logic, and co-founder of the VMware Center for Policy & Compliance. As a faculty member of the Institute of Applied Network Security and philanthropist, George's commitment to serving on Bugcrowd's Advisory Board alongside other notable board members will be valuable in guiding the organization forward. With his industry insights and expertise, George is expected to provide critical guidance to the Bugcrowd team as they navigate complex regulatory requirements and continue to drive growth.
Jul 09, 2024
366 words in the original blog post.
There is immediate and long-term benefit in investing quality time into an engagement brief, which can lead to better hacker attraction and increased efficiency. A compelling brief should be well-articulated, providing clear guidance, minimizing confusion, and fostering trust between the organization and hackers. Key considerations include including relevant information, optimizing length, and avoiding unhelpful statements. The brief's design, especially the introduction section, is crucial in enticing hackers to participate. Effective communication of scope, target groups, and out-of-scope areas is essential to guide hackers towards the right places, while providing documentation, credentials, and focus areas helps to facilitate a smooth engagement process. By incorporating elements such as gamification, motivation psychology, and showcasing expertise, organizations can create an engaging brief that attracts the right hackers and maximizes value from their managed bug bounty programs.
Jul 08, 2024
2,228 words in the original blog post.
Ross McKerchar, CISO at Sophos, has built and led the company's security team for almost 17 years, overseeing all aspects of cybersecurity posture, including corporate, infrastructure, and product security. He emphasizes the importance of authenticity and transparency in a security program, taking an approach that focuses on addressing issues and demonstrating continual efforts with facts and actions rather than just words. McKerchar believes that security is never 'done' and that organizations must work hard to maintain their security posture. As CISO, he prioritizes building trust both with customers and vendors, using methods such as bug bounty engagements to evaluate vendor security. He also advocates for a "zooming out on risk" approach to see the bigger picture, reducing overall risk and becoming more secure by leveraging multi-layered attack surface management strategies.
Jul 02, 2024
743 words in the original blog post.