bugcrowd
26.4K posts

bugcrowd
@Bugcrowd
The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
San Francisco, CA Beigetreten Eylül 2012
6.1K Folgt195.6K Follower

I just published a new #article on Medium.
How I Earned $76,000 Bounty From a Single Program on @Bugcrowd .
#BugBounty #Bugcrowd #CyberSecurity #EthicalHacking @Hacker0x01 @yeswehack @intigriti
anonhunter.medium.com/how-i-earned-7…
English

AI-generated phishing attacks have reportedly increased by 14X, with a significant impact on the manufacturing sector. 🧑🏭
The surge indicates a shift in how attackers are leveraging LLMs to scale their operations. By automating the creation of realistic lures, threat actors can target specific industries with much higher frequency.
This trend emphasizes the need for defensive strategies that can account for the rapid iteration of social engineering tactics. Read more at Manufacturing.net: manufacturing.net/cybersecurity/…
English

AI might be moving faster than your org chart. 👥
When innovation outpaces accountability, risk ownership can get messy. We’re heading to RSAC to discuss how to fix the gap between AI-driven exposure and fragmented controls.
The Panel:
🎙️ @kristinaayanian (Moderator, @Nasdaq)
🎙️ @davegerryjr, (CEO at #Bugcrowd)
🎙️ Umesh Shankar (CVP Engineering, Microsoft AI)
🎙️ Ramin Farassat (CPO, Menlo Security Inc.)
🎙️ John Spiegel (CTO Security, Hewlett Packard Enterprise)
💌 RSVP: luma.com/AIsession?utm_…
Made possible with support from our event partners: @HPE, @menlosecurity, and Unosecur. 🔥

English

✍️ World Poetry Day in cyber?
Yeah, we know. A little absurd.
Now that our social media manager tried to rhyme, please head to the blog because this felt like a crime 🥴: bugcrowd.com/blog/10-cybers…
Happy #WorldPoetryDay from Bugcrowd and our talented Director of Content Marketing 🌟🧡
English

Tools of Efficiency 🛠️
DOM Invader: standard dynamic scanners fail at discovering this because aggressive clobbering instantly breaks site functionality. Use DOM Invader in Burp Suite, but remember you must manually toggle the "DOM clobbering" setting on and reload the browser context to start finding these data flows.
Stay 1337, DOM clobber! 👊🔥
English
bugcrowd retweetet

Last year's hacker roadshow was GREAT! @Bugcrowd took security professionals and ethical hackers on the road and the reception has been phenomenal.
In 2026 @hackthebox_eu Box hops on the orange bus, and we start in London next week! Sign up here lnkd.in/ehM4j5J9

English

Verification is harder when risk is shared across vendors, partners, and platforms 💨
At The Hive during #RSAC, Bugcrowd is hosting a conversation for security leaders focused on how FinTech teams assess vendor exposure, inherited risk, and partner dependencies in complex environments.
Featuring @treyford at Bugcrowd, Jaye Tillson at @HPE, and Pranav Vattaparambil at Unosecur. 🎙️
🛟 Save your seat before it’s full: luma.com/PeerExchange?u…
Good conversations need good company. Thanks to our sponsors for helping make this one happen: Hewlett Packard Enterprise, @menlosecurity, Unosecur!

English

📢 The White House has released a National Cyber Strategy that places a priority on offensive operations.
Bugcrowd CEO Dave Gerry observes that the current document serves as a high-level messaging framework. While it aligns with national needs, the specific details regarding timing, funding, and execution plans will likely follow in subsequent executive orders or legislation. 📜
For the cybersecurity industry, the focus now turns to how different agencies will be tasked with executing these high-level goals. Full story at Dark Reading: darkreading.com/cybersecurity-…
English

New research highlights how connecting Salesforce with third-party applications and APIs can inadvertently expand an organization’s attack surface.
Trey Ford points out that trust relationships are becoming a focal point for attackers. Compromising a single trusted integration can create a ripple effect of risk across the entire ecosystem.
Enterprise teams are encouraged to audit guest user permissions and enforce a policy of least-privilege access for all public API connections.
Read more in CSO Magazine: csoonline.com/article/414366…
English

Coverage reports can look great while exposure quietly stacks up in the background. 😅
That’s the thread behind our upcoming brunch session at The Hive on attack surface gaps and exploit paths across modern stacks. This is a working discussion for buyers and security leaders who want tighter validation.
Moderated by Braden Russell at Bugcrowd, with field perspectives from Dominique DeVaux Jeffords at @TMobile, George Gerchow at Bedrock Data, Nick Terkay at Unosecur, and Deap Ubhi at @AWS.
🍩 Donuts included
📍 The Hive
If you know someone who’d love this session, bring them along. Registration is required, so tag them below 👇
🎟️> luma.com/DonutBrunch?ut…
Big appreciation for our sponsors: @HPE, @menlosecurity, and Unosecur! 🙌

English



