Security News

Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook
2020-05-21 06:02

In 1965, Gordon Moore published a short informal paper, Cramming more components onto integrated circuits. Based on not much more but these few data points and his knowledge of silicon chip development - he was head of R&D at Fairchild Semiconductors, the company that was to seed Silicon Valley - he said that for the next decade, component counts by area could double every year.

Login with Facebook Bug Earns $20K Bounty
2020-05-14 12:17

Facebook has awarded a security researcher $20,000 for discovering a cross-site scripting vulnerability in the Facebook Login SDK, which is used by developers to add a "Continue with Facebook" button to a page as an authentication method. He discovered an issue there in the Facebook Login SDK for JavaScript.

Microsoft opens IoT bug bounty program
2020-05-11 09:27

The company has launched a $100,000 bug bounty for people who can break into Azure Sphere, its security system for IoT devices. The latest, the Sphere Security Research Challenge, lets bug hunters talk directly to Microsoft's technical team as they try to break into Sphere.

Microsoft announces limited Azure Sphere bug bounty program
2020-05-06 08:37

Microsoft has announced a new security research / bug bounty program aimed at testing and improving the security of Azure Sphere, its comprehensive IoT security solution. Through the Azure Sphere Security Service, the MCU can securely connect to the cloud and web, and the service makes sure that the booted software is genuine, that OS security updates are downloaded and installed securely and automatically.

Critical GitLab Flaw Earns Bounty Hunter $20K
2020-04-29 16:39

A critical GitLab vulnerability, which could be leveraged by a remote attacker to execute code, recently netted a researcher a $20,000 bug-bounty award. The flaw was reported to GitLab by software developer William Bowling via the HackerOne bug bounty platform on March 23.

Zoom Revamps Bug Bounty Program
2020-04-16 14:25

Zoom announced on Wednesday that it has teamed up with Katie Moussouris' company, Luta Security, to revamp its bug bounty program. Zoom announced on April 1 that it would be making significant changes to its bug bounty program, after experts raised concerns about Zoom security and researchers reported finding potentially serious vulnerabilities in the video conferencing service.

Tencent Ups Top Bug-Bounty Award to $15K
2020-04-15 16:17

The Tencent Security Response Center is launching an expanded bug-bounty program, via the HackerOne white-hat platform - and the company has increased its top reward to $15,000. Tencent, a China-based global internet service provider, is opening up its existing bug-bounty program to HackerOne's community of 600,000+ bug hunters, to widen the company's vulnerability reporting and technical sharing efforts, it said in a launch notice on Tuesday.

Tencent Partners With HackerOne for Bug Bounty Program
2020-04-15 04:20

HackerOne announced on Tuesday that the bug bounty program of Chinese technology giant Tencent is now accessible through its platform. More than 600,000 hackers registered on HackerOne can join Tencent's bug bounty program to hunt for vulnerabilities in the company's products.

Bug Bounty Programs Are Being Used to Buy Silence
2020-04-03 11:21

Used properly, bug bounty platforms connect security researchers with organizations wanting extra scrutiny. CSO's investigation shows that the bug bounty platforms have turned bug reporting and disclosure on its head, what multiple expert sources, including HackerOne's former chief policy officer, Katie Moussouris, call a "Perversion."

Epic Games floats $1m bounty to ID source of 'commercial smear' claiming Houseparty chat app has been hacked
2020-03-31 18:30

Group video chat app Houseparty has offered a $1m bounty to identify what it claims is an organised campaign to falsely depict it as a hackers' backdoor. Announced at 4am UTC on the firm's Twitter account, the million-dollar bounty is being offered to "The first individual to provide proof of such a campaign," with Epic Games, the firm behind Houseparty, alleging this effort is "a paid commercial smear to harm Houseparty."