toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

227
active users

#bugcrowd

0 posts0 participants0 posts today
Pyrzout :vm:<p>Infosec products of the month: April 2025 <a href="https://www.helpnetsecurity.com/2025/05/02/infosec-products-of-the-month-april-2025/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/05/02</span><span class="invisible">/infosec-products-of-the-month-april-2025/</span></a> <a href="https://social.skynetcloud.site/tags/ArcticWolfNetworks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ArcticWolfNetworks</span></a> <a href="https://social.skynetcloud.site/tags/RunSafeSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RunSafeSecurity</span></a> <a href="https://social.skynetcloud.site/tags/SkyhawkSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SkyhawkSecurity</span></a> <a href="https://social.skynetcloud.site/tags/CatoNetworks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CatoNetworks</span></a> <a href="https://social.skynetcloud.site/tags/IndexEngines" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IndexEngines</span></a> <a href="https://social.skynetcloud.site/tags/SealSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SealSecurity</span></a> <a href="https://social.skynetcloud.site/tags/StellarCyber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>StellarCyber</span></a> <a href="https://social.skynetcloud.site/tags/Bitdefender" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bitdefender</span></a> <a href="https://social.skynetcloud.site/tags/Seemplicity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Seemplicity</span></a> <a href="https://social.skynetcloud.site/tags/AbnormalAI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AbnormalAI</span></a> <a href="https://social.skynetcloud.site/tags/Flashpoint" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Flashpoint</span></a> <a href="https://social.skynetcloud.site/tags/PowerDMARC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerDMARC</span></a> <a href="https://social.skynetcloud.site/tags/1touch" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>1touch</span></a>.io <a href="https://social.skynetcloud.site/tags/Forescout" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Forescout</span></a> <a href="https://social.skynetcloud.site/tags/AppViewX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppViewX</span></a> <a href="https://social.skynetcloud.site/tags/BitSight" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BitSight</span></a> <a href="https://social.skynetcloud.site/tags/Bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bugcrowd</span></a> <a href="https://social.skynetcloud.site/tags/LastPass" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LastPass</span></a> <a href="https://social.skynetcloud.site/tags/PlexTrac" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PlexTrac</span></a> <a href="https://social.skynetcloud.site/tags/Swimlane" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Swimlane</span></a> <a href="https://social.skynetcloud.site/tags/Veracode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Veracode</span></a> <a href="https://social.skynetcloud.site/tags/CyberQP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberQP</span></a> <a href="https://social.skynetcloud.site/tags/Entrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Entrust</span></a> <a href="https://social.skynetcloud.site/tags/Exabeam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Exabeam</span></a> <a href="https://social.skynetcloud.site/tags/Saviynt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Saviynt</span></a> <a href="https://social.skynetcloud.site/tags/Varonis" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Varonis</span></a> <a href="https://social.skynetcloud.site/tags/Cyware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyware</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/Jit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Jit</span></a></p>
Alex :nonbinary_flag:<p>Uh, anyone else get a password reset email from <a href="https://infosec.exchange/tags/bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bugcrowd</span></a> ?</p>
KrebsOnSecurity RSS<p>MasterCard DNS Error Went Unnoticed for Years</p><p><a href="https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2025/01/ma</span><span class="invisible">stercard-dns-error-went-unnoticed-for-years/</span></a></p><p> <a href="https://burn.capital/tags/HowtoBreakIntoSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HowtoBreakIntoSecurity</span></a> <a href="https://burn.capital/tags/az" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>az</span></a>.mastercard.com <a href="https://burn.capital/tags/PhilippeCaturegli" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhilippeCaturegli</span></a> <a href="https://burn.capital/tags/ALittleSunshine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ALittleSunshine</span></a> <a href="https://burn.capital/tags/awsdns" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>awsdns</span></a>-06.ne <a href="https://burn.capital/tags/CloudFlare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudFlare</span></a> <a href="https://burn.capital/tags/mastercard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mastercard</span></a> <a href="https://burn.capital/tags/akam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>akam</span></a>.net <a href="https://burn.capital/tags/Bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bugcrowd</span></a> <a href="https://burn.capital/tags/akam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>akam</span></a>.ne <a href="https://burn.capital/tags/Seralys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Seralys</span></a> <a href="https://burn.capital/tags/Akamai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Akamai</span></a> <a href="https://burn.capital/tags/google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>google</span></a> <a href="https://burn.capital/tags/Azure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Azure</span></a></p>
ITSEC News<p>MasterCard DNS Error Went Unnoticed for Years - The payment card giant MasterCard just fixed a glaring error in its domain name se... <a href="https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2025/01/ma</span><span class="invisible">stercard-dns-error-went-unnoticed-for-years/</span></a> <a href="https://schleuss.online/tags/howtobreakintosecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>howtobreakintosecurity</span></a> <a href="https://schleuss.online/tags/az" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>az</span></a>.mastercard.com <a href="https://schleuss.online/tags/philippecaturegli" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>philippecaturegli</span></a> <a href="https://schleuss.online/tags/alittlesunshine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>alittlesunshine</span></a> <a href="https://schleuss.online/tags/awsdns" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>awsdns</span></a>-06.ne <a href="https://schleuss.online/tags/cloudflare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloudflare</span></a> <a href="https://schleuss.online/tags/mastercard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mastercard</span></a> <a href="https://schleuss.online/tags/akam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>akam</span></a>.net <a href="https://schleuss.online/tags/bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bugcrowd</span></a> <a href="https://schleuss.online/tags/akam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>akam</span></a>.ne <a href="https://schleuss.online/tags/seralys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>seralys</span></a> <a href="https://schleuss.online/tags/akamai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>akamai</span></a> <a href="https://schleuss.online/tags/google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>google</span></a> <a href="https://schleuss.online/tags/azure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>azure</span></a></p>
Harry Sintonen<p>A company appears to be abusing <a href="https://infosec.exchange/tags/BugCrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BugCrowd</span></a>’s <a href="https://infosec.exchange/tags/bugbounty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bugbounty</span></a> program to hide essential details of a critical vulnerability. The company itself has rated the vulnerability as low severity. This has led many to disregard the vulnerability, which may have resulted in unpatched systems that remain vulnerable.</p><p>"I would like to remind you that as a researcher using the BugCrowd platform to submit this issue you are bound by the BugCrowd standard disclosure terms and you may not blog or disclose any information on the exploitation of this vulnerability."</p><p>I were to follow these rules, it would mean that countless of client systems could remain vulnerable to this critical vulnerability.</p><p>I’ve mostly had good experiences with bug bounty programs before this incident. Sure, I’ve had some disagreements at times, but I’ve never seen a program being abused like this before.</p><p><a href="https://infosec.exchange/tags/responsibledisclosure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>responsibledisclosure</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a></p>
Yellow Flag<p>Just a reminder: with those bug bounty platforms like Bugcrowd, HackerOne or whatever, as a security researcher you are not their customer, you are the product.</p><p>If there is a conflict they will tend to side with their customer, meaning the company running the bug bounty program. Good luck proving that you have a right to disclose that vulnerability. They will pressure you into not disclosing as long as the company is opposed. So if you still want to decide anything it’s better not to grow too attached to that account because it will be used as leverage against you.</p><p>And they will try very hard to filter reports before these reach the company. If your report is more difficult to understand than the typical report for this program – good luck reaching the company, you’ll need it. It’s very likely that your report will be closed as “out of scope” with all appeals falling on deaf ears. The bug bounty platforms are paid for filtering, not for letting reports through just because they have doubts about them. You might need to think about other ways to reach the people actually in charge.</p><p><a href="https://infosec.exchange/tags/Bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bugcrowd</span></a> <a href="https://infosec.exchange/tags/HackerOne" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HackerOne</span></a> <a href="https://infosec.exchange/tags/BugBounty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BugBounty</span></a></p>
Pyrzout :vm:<p>Bugcrowd raises $102 million to boost AI-powered crowdsourced security platform <a href="https://www.helpnetsecurity.com/2024/02/12/bugcrowd-funding-102-million/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2024/02/12</span><span class="invisible">/bugcrowd-funding-102-million/</span></a> <a href="https://social.skynetcloud.site/tags/Industrynews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Industrynews</span></a> <a href="https://social.skynetcloud.site/tags/Bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bugcrowd</span></a></p>
Norobiik @Norobiik@noc.social<p>OpenAI has launched a bug bounty to encourage people to find and disclose vulnerabilities in its <a href="https://noc.social/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> services (including ChatGPT). Rewards range from $200 to $20,000, and reports can be submitted via <a href="https://noc.social/tags/Bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bugcrowd</span></a>. Notable exceptions include jailbreaking ChatGPT or causing it to generate malicious code or text.</p><p><a href="https://noc.social/tags/OpenAI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenAI</span></a> offers bug bounty for <a href="https://noc.social/tags/ChatGPT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ChatGPT</span></a> — but no rewards for <a href="https://noc.social/tags/jailbreaking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>jailbreaking</span></a> its <a href="https://noc.social/tags/chatbot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>chatbot</span></a> | <a href="https://noc.social/tags/GenerativeAI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GenerativeAI</span></a> <a href="https://noc.social/tags/BugHunt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BugHunt</span></a> | The Verge</p><p><a href="https://www.theverge.com/2023/4/12/23679964/openai-bug-bounty-chatgpt-no-jailbreak" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theverge.com/2023/4/12/2367996</span><span class="invisible">4/openai-bug-bounty-chatgpt-no-jailbreak</span></a></p>
d0pp3l6ang3r :verified: :donor:<p>Aryt few more entities potentially impacted. <a href="https://infosec.exchange/tags/svb" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>svb</span></a></p><p><a href="https://infosec.exchange/tags/algolia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>algolia</span></a><br><a href="https://infosec.exchange/tags/apptio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apptio</span></a><br><a href="https://infosec.exchange/tags/asana" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>asana</span></a><br><a href="https://infosec.exchange/tags/bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bugcrowd</span></a><br><a href="https://infosec.exchange/tags/cloudbees" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloudbees</span></a><br><a href="https://infosec.exchange/tags/confluent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>confluent</span></a><br><a href="https://infosec.exchange/tags/crowdstrike" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crowdstrike</span></a><br><a href="https://infosec.exchange/tags/datadog" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>datadog</span></a><br><a href="https://infosec.exchange/tags/docusign" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>docusign</span></a><br><a href="https://infosec.exchange/tags/envoy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>envoy</span></a><br><a href="https://infosec.exchange/tags/fastly" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fastly</span></a><br><a href="https://infosec.exchange/tags/firehydrant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>firehydrant</span></a><br><a href="https://infosec.exchange/tags/glassdoor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>glassdoor</span></a><br><a href="https://infosec.exchange/tags/glean" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>glean</span></a><br><a href="https://infosec.exchange/tags/greenhouse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>greenhouse</span></a><br><a href="https://infosec.exchange/tags/hashicorp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hashicorp</span></a><br><a href="https://infosec.exchange/tags/intello" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>intello</span></a><br><a href="https://infosec.exchange/tags/jfrog" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>jfrog</span></a><br><a href="https://infosec.exchange/tags/lacework" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>lacework</span></a> <br><a href="https://infosec.exchange/tags/Learnably" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Learnably</span></a> <br><a href="https://infosec.exchange/tags/LucidSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LucidSoftware</span></a><br><a href="https://infosec.exchange/tags/Marketo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Marketo</span></a> <br><a href="https://infosec.exchange/tags/meetup" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>meetup</span></a><br><a href="https://infosec.exchange/tags/Namely" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Namely</span></a> <br><a href="https://infosec.exchange/tags/Nasuni" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nasuni</span></a> <br><a href="https://infosec.exchange/tags/notion" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>notion</span></a><br><a href="https://infosec.exchange/tags/Pagerduty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pagerduty</span></a> <br><a href="https://infosec.exchange/tags/Pluralsight" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pluralsight</span></a> <br><a href="https://infosec.exchange/tags/Postman" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Postman</span></a> <br><a href="https://infosec.exchange/tags/Rippling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Rippling</span></a> <br><a href="https://infosec.exchange/tags/Signiant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signiant</span></a><br><a href="https://infosec.exchange/tags/Smartsheet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Smartsheet</span></a><br><br><a href="https://infosec.exchange/tags/Sprinklr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sprinklr</span></a> <br><a href="https://infosec.exchange/tags/SumoLogic" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SumoLogic</span></a> <br><a href="https://infosec.exchange/tags/Tableau" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tableau</span></a> <br><a href="https://infosec.exchange/tags/Teem" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Teem</span></a> <br><a href="https://infosec.exchange/tags/TextExpander" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TextExpander</span></a> <br><a href="https://infosec.exchange/tags/Threatstack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Threatstack</span></a> <br><a href="https://infosec.exchange/tags/Twitch" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Twitch</span></a> <br><a href="https://infosec.exchange/tags/Wiz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Wiz</span></a> <br><a href="https://infosec.exchange/tags/Zendesk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Zendesk</span></a> <br><a href="https://infosec.exchange/tags/Zylo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Zylo</span></a></p>
Jonathan Kamens 86 47<p>I mean sure, <a href="https://federate.social/tags/BugCrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BugCrowd</span></a>, we can talk about this if you want, but I'm not really sure <a href="https://federate.social/tags/LinkedIn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LinkedIn</span></a> is the right forum for it. <a href="https://federate.social/tags/oopsie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oopsie</span></a></p>
DROP\ TABLE @@<p><span class="h-card"><a href="https://awscommunity.social/@mastobit" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mastobit</span></a></span> <br>Are you ready? Hey <a href="https://infosec.exchange/tags/bugcrowd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bugcrowd</span></a><br>Are you ready for this?<br>Are you hanging on the edge of your seat?<br>Out of the code the vulnerabilities rip<br>To the sound of the beat, yeah<br>yeah, hey 104 vulnerabilities</p>