Hacking, AppSec, and Bug Bounty newsletter
2018-01-26 | AIVD’s Crazy Bear assist for the FBI, New GDPR site by EU Commission, and Lloyds estimates US cloud outage impact at $19B
Friday, January 26
AIVD + FBI: Dutch intelligence service AIVD have provided the FBI with crucial information about Russian interference with the American elections. They hacked into Cozy Bear’s network, and even accessed the security camera feed outside the building their targets worked in.
Keybase extension hostname-validation regular expression issue. [9 upvotes] - $2,000 bounty for this report to Keybase by @edio.
Torrent Viewer extension web service available on all interfaces [5 upvotes] - $200 bounty for this report to Brave Software by @dutchgraa.
BONUS Report today (so much goodness on the Hacktivity, when it rains it pours):
Fastify denial-of-service vulnerability with large JSON payloads [9 upvotes] - no bounty for this report to Node.js third-party modules by @nwoltman.
See also: Slack $4,000 bounty, Coinbase awarded a $10,000 bounty, Mail.Ru paid out over $4K, and Algolia awarded a $3K bounty. Holy hacktivity batman!
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
In #infosec, Pareto’s Principle mandates that you spend 80% of your efforts on ticking checkboxes to yield 20% of the protection. - @jschauma
OTHER ARTICLES WE’RE READING
New GDPR microsite from European Commission: 2018 reform of EU data protection rules
Attn FinServ CISOs: The first New York State (NYS) Department of Financial Services (DFS) CISO Attestation is due on February 15th.
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
This is starting to just get sad.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.