Bugcrowd University to provide hands-on training for security researchers

Bugcrowd announced the launch of Bugcrowd University to educate and empower the crowd with the latest skills and methodologies. The first advanced program of its kind, Bugcrowd University provides researcher education and training to improve the state … Continue reading Bugcrowd University to provide hands-on training for security researchers

Bugcrowd launches Disclose.io to provide a safe harbor for white hat hackers

Bugcrowd and Amit Elazari, a University of California, Berkeley doctoral candidate and CLTC grantee, announce the launch of Disclose.io — a project to standardize practices for providing a safe harbor for security researchers within bug bounty and vuln… Continue reading Bugcrowd launches Disclose.io to provide a safe harbor for white hat hackers

Open source project looks to give legal safe harbor for ethical hackers

A new program aims to provide white hat hackers and companies running bug bounty and vulnerability disclosure programs with open source legal guidelines to avoid issues sometimes associated with security research. Launched jointly on Thursday by Bugcrowd and Amit Elazari, a University of California Berkeley doctoral candidate, Disclose.io can be adopted by any organization running a bug bounty or disclosure program. The initiative offers boilerplate language that a company can use as terms between it and security researchers who want to disclose a bug. Bugcrowd asserts that current laws, such as the Computer Fraud and Abuse Act (CFAA) and the Digital Millennium Copyright Act (DMCA) have a chilling effect on security research. Research conducted in order to find software vulnerabilities is often perceived as malicious hacking, Bugcrowd explains. “The ambiguity of existing laws and lack of framework surrounding protocols for ‘good faith’ security testing has sometimes resulted in legal threats, unlawful […]

The post Open source project looks to give legal safe harbor for ethical hackers appeared first on Cyberscoop.

Continue reading Open source project looks to give legal safe harbor for ethical hackers

HP launches printer bug bounty program with Bugcrowd

HP, the Palo Alto, California tech giant, announced Tuesday it will be inviting white hat hackers to probe its printers for bugs that attackers could exploit for malicious purposes. Shivaun Albright, HP’s chief technologist of print security, described the program as complementary to existing security features built into HP printers. “We have some features in our devices to detect when attacks occur,” Albright told CyberScoop. “But if you look at it, recognizing that a device can it protect against all current and future attacks, what we wanted to do was go beyond what’s happening in the industry.” The HP printer bug bounty program will be managed by Bugcrowd, a prominent bug bounty platform. HP’s program will be private, meaning researchers who already have some experience with Bugcrowd will be invited to join. Albright said the program will be a pilot that could lead HP to open it up to the […]

The post HP launches printer bug bounty program with Bugcrowd appeared first on Cyberscoop.

Continue reading HP launches printer bug bounty program with Bugcrowd

Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors

More companies are looking to adopt “safe harbor” language in their bug bounty programs to build trust with participants. Continue reading Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors

Jason Haddix, Bugcrowd – Paul’s Security Weekly #564

As the Vice President of Trust & Security, Jason works with clients and security researchers to create high value, sustainable, and impactful bug bounty programs. Full Show Notes Subscribe to YouTube Channel
The post Jason Haddix, Bugcrowd –… Continue reading Jason Haddix, Bugcrowd – Paul’s Security Weekly #564

Keith Hoodlet: Bug Bounty Hunting – Paul’s Security Weekly #564

Keith will be talking through some of the tools, techniques, and procedures he uses to perform recon, identify targets of interest, and report findings faster and easier. Full Show Notes Subscribe to YouTube Channel
The post Keith Hoodlet: Bug Bounty H… Continue reading Keith Hoodlet: Bug Bounty Hunting – Paul’s Security Weekly #564

Bug bounty payouts double in 2018; India reports the most bugs while U.S. wins highest payouts

Some of the biggest players in various industries have turned to the crowdsourced security model – white hat-driven bug bounty programs – in a race to identify emerging vulnerabilities before the black hats do. The crowdsourced security mod… Continue reading Bug bounty payouts double in 2018; India reports the most bugs while U.S. wins highest payouts

Crowdsourced security trends: Payouts to hackers increase

Bugcrowd has released the 2018 Bugcrowd State of Bug Bounty Report, which analyzes proprietary platform data collected from more than 700 crowdsourced security programs managed by the organization. The data includes all Bugcrowd platform data from Apri… Continue reading Crowdsourced security trends: Payouts to hackers increase