Hacking, AppSec, and Bug Bounty newsletter
2018-04-17 | NIST updates the cybersecurity framework, RSA is back to basics, and A bug bounty tip from EdOverflow
Tuesday, April 17
RSA kicks off today. This year, it’s back to basics says Tenable Security CEO, Amit Yoran. And as goes the norm, lots of vendor and industry updates pushed through including the announcement of the Cybersecurity Tech Accord. One other notable announcement, NIST updated their cybersecurity framework (see v1.1) including language about creating a vulnerability disclosure process, third-party risk and protecting your supply chain, and verifying user authentication.
TWEET OF THE DAY
Only Microsoft can state that it took them 43 years to start distributing an operating system which is 27 years old - @martenmickos
OTHER ARTICLES WE’RE READING
IoT hack stories from Darktrace: It was Professor Plum in the lobby with the thermometer.
Daniel Miessler launched a thing: Helios
Logging, Monitoring, and Alerting in AWS (The TL;DR) slides by @jpoforenso from BSidesSF
DOM-based XSS – The 3 Sinks by @brutelogic
White House cybersecurity coordinator Rob Joyce is leaving reports Politico
Bug bounty tip from @EdOverflow: Look for GitLab instances on targets or belonging to the target.
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
The devastating attacks from the past year demonstrate that cybersecurity is not just about what any single company can do but also about what we can all do together.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.