January 2025 Summaries
10 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
</doc>`
Cryptography is a critical component of modern technology solutions, with applications ranging from basic web applications to complex cyber systems. Cryptography presents opportunities for hackers, who can exploit design flaws and implementation vulnerabilities in cryptographic algorithms. The three distinct layers of cryptography - underlying mathematics, commonly used libraries, and application-specific implementation - each present unique attack vectors. Symmetric encryption relies on a single key for both encryption and decryption, while asymmetric encryption employs a pair of keys: a public key for encryption and a private key for decryption. Cryptographic hashes produce fixed-length outputs from input data, ensuring data integrity. Key management is critical, with vulnerabilities arising from insecure key generation, exchange, storage, rotation, revocation, and expiry. Brute force attacks exploit variations in processing times or power consumption to compromise sensitive information. Side-channel attacks focus on external characteristics like timing, power consumption, electromagnetic emissions, or acoustic signals to infer cryptographic keys or data. Padding oracle attacks target vulnerabilities in block cipher modes, such as CBC, which require padding of plaintext to match the block size of the encryption algorithm. Timing attacks exploit variations in time taken for certain cryptographic operations to reveal information about encryption/decryption keys or sensitive data. Insufficient entropy in random number generation can lead to predictable outputs, compromising cryptographic implementations. Understanding these nuances is crucial for bug bounty researchers aiming to identify and exploit high-impact vulnerabilities in cryptography.
Jan 30, 2025
4,781 words in the original blog post.
The Digital Operational Resilience Act (DORA) mandates that financial institutions implement a structured, ongoing approach to operational resilience testing. This includes regular vulnerability assessments and penetration testing, threat-led penetration testing for large and significant institutions, validation of third-party systems, real-time monitoring, and continuous improvement. Continuous testing is central to DORA as it helps organizations stay ahead of evolving threats, prevent incidents through proactive identification and mitigation of risks, and provides auditable evidence of compliance with regulatory demands. However, implementing continuous testing requires significant investment in tools, processes, and skilled personnel, which can be challenging for smaller institutions due to the skills shortage and scaling issues. Bugcrowd supports financial institutions in meeting DORA's requirements by providing scalable penetration testing, threat-led simulations, continuous vulnerability management, third-party risk testing, and cost efficiency through a crowdsourced model. The long-term benefits of continuous testing include enhanced resilience, regulatory compliance, and customer trust.
Jan 29, 2025
989 words in the original blog post.
The previous administration's guidance on AI safety and security testing has been repealed, leaving concerns about the impact of this shift on public safety. The new administration is investing $500 billion in private-sector AI infrastructure through Project Stargate, which may foster more innovation but also raises questions about prioritizing risks. As a former principal AI engineer, Joseph Thacker shares his expertise on vulnerabilities such as prompt injections, multi-modal injection, and chain-of-thought attacks, highlighting the need for practical advice and recommendations on addressing these security challenges. The rollback of regulations has sparked concerns, but it also presents an opportunity for more practical guidance on security issues. Thacker advocates for guardrail software, deployable templates, design patterns, pen testing guides, education for government officials, automated security testing, and robust safety measures to ensure AI is wielded wisely as its impact on our lives continues to grow.
Jan 27, 2025
1,310 words in the original blog post.
The EU's Digital Operational Resilience Act (DORA) requires significant upfront and ongoing investments from organizations, particularly financial institutions, to ensure operational resilience. The cost implications of DORA compliance include upgrading cybersecurity infrastructure, conducting regular digital operational resilience testing, hiring or upskilling personnel, and third-party risk management. The global cybersecurity skills shortage will exacerbate these challenges, making it difficult for smaller firms to attract and retain talent. To manage these challenges effectively, organizations can leverage platform-based solutions, adopt a risk-based approach, collaborate with industry groups, and prioritize resources based on risk. By doing so, they can reduce costs and staffing pressures while ensuring compliance with DORA standards.
Jan 23, 2025
1,064 words in the original blog post.
<doc fingerprint="bc199951990975d5">
Two-part blog series covering Multi-Factor Authentication (MFA) definition, attacker methods to bypass MFA, adversary-in-the-middle techniques growth, and actionable ways to prevent MFA bypass. MFA combines factors such as something you know, have, or are, to provide an additional layer of protection beyond traditional password-based systems. However, attackers continue to develop sophisticated methods to bypass MFA by exploiting gaps in implementation, human error, or technical vulnerabilities. Key attacker approaches include conditional access policy, machine-based attacks, phishing and social engineering, phone-based attacks, and insider threats. These methods can be exploited through IP address whitelisting, geo-whitelisting, user-agent whitelisting, cloud tooling bypasses, non-MFA hosts, session token theft, OTPs and seed QR codes exploitation, biometrics and TPMs compromise, stolen devices, phishing and social engineering, phone-based attacks, QR phishing, and insider threats. To prevent MFA bypass, organizations must implement effective security measures, including conditional access policy configurations, machine learning-powered threat detection, phishing and social engineering training, phone-based authentication methods, and insider threat mitigation strategies. Staying informed about emerging threats and vulnerabilities is essential to maintaining the effectiveness of MFA systems.
</doc>
Jan 22, 2025
2,100 words in the original blog post.
The Bugboss Fighter is a unique competition where 50 skilled hackers from the crowd compete against two industry-recognized champions, tess and El Mehdi, in a two-week challenge. The tournament-style event allows rising hacker talent to test their skills against experienced professionals. The competition offers prizes for the top three finishers, with the first place winner receiving $1000. The event starts on February 5th, 2025, and ends on February 19th, 2025. Participants will be invited to an exclusive Discord channel to track scoring, share strategies, and engage in discussions. The competition rules state that the Crowd must out-earn the Bugbosses over the two-week period, while the Bugbosses lose health for each critical vulnerability discovered by the Crowd.
Jan 21, 2025
286 words in the original blog post.
Salt Typhoon is a cybersecurity threat that targets telecommunications firms, using tactics like edge attacks to gain initial access to infrastructure and then pivot to other areas. The attackers are human adversaries with organized campaigns, making it challenging for organizations to identify and eject them from their systems. This compromise has the potential to get really personal information from people, as it can target individuals through their phones. The attacks started on the edge of the attack surface, which is often secured last, and have made it difficult for telecommunications companies to remove the attackers from their infrastructure due to their diverse and vast technology stack.
Jan 16, 2025
386 words in the original blog post.
The Hacking Policy Council, of which Bugcrowd is a founding member, has made significant strides in advocating for policies that strengthen cybersecurity defenses while empowering ethical hackers. In 2024, the council tackled pressing challenges such as promoting vulnerability disclosure policies and bug bounty programs, enhancing AI testing and security protocols, addressing offensive security practices and commercial surveillance, and engaging state attorneys general on charging policies for good-faith security researchers. The HPC's core areas of focus include advocating for responsible security practices, protecting good-faith researchers, driving global harmonization, and innovating in AI and offensive security. Looking ahead to 2025, the council aims to expand vulnerability disclosure programs across sectors, deepen AI security protocols, strengthen international collaboration, promote legal protections for ethical hackers, encourage accountability in offensive security, and foster a shared responsibility for cybersecurity.
Jan 15, 2025
1,148 words in the original blog post.
The Bugcrowd Platform is now enabling customers to customize mappings between the Common Vulnerability Scoring System (CVSS) and its Vulnerability Rating Taxonomy (VRT), allowing for standardization of vulnerability severity levels across both systems. This customization enables seamless use of CVSS on the platform, streamlining how security teams manage vulnerabilities. To set these mappings, users can go to Security Program Settings, select the CVSS v3.1 Calculator option, and adjust a slider to map CVSS scores to Bugcrowd's technical severity levels, which will then be prefilled in submissions with assigned CVSS scores.
Jan 14, 2025
255 words in the original blog post.
This article is about the use of BLE (Bluetooth Low Energy) technology to hack and control various devices, including iMessage on iPhones. The author provides two sketches for using an ESP32 board to send a text message in someone else's last iMessage conversation and to broadcast constant stream of Bluetooth device notifications for under $25. The article also discusses the use of NimBLE-Arduino library to create BLE advertisements that can be used to annoy people or even hack into their devices. The author provides tutorials on how to install and configure the Arduino IDE, write sketches, and compile code using the ESP32 board. Additionally, the article mentions a security vulnerability in iOS that allows for arbitrary SMS sending via the `sms://` URL scheme.
Jan 09, 2025
2,907 words in the original blog post.