/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

HackerOne says an employee stole vulnerability reports submitted through its bug bounty platform and disclosed them to seven companies for financial rewards

Sunday, July 03, 2022 // (IG): BB //Weekly Sponsor: Zanes Hand Made (leather works) Slashdot : How Bug Bounty Platform HackerOne Handled Its Own ‘Internal Threat’ Actor Tweets: Jake Williams / @malwarejake : Frontrunning their own bug bounty is not something I expected to see... https://twitter.com/... Catalin Cimpanu / @campuscodi : HackerOne discloses security incident. The company says that a “then-employee had improperly accessed security reports for personal gain” and shared details about a vulnerability outside the platform https://hackerone.com/... https://twitter.com/... @wpalant : Still waiting for one that will sell reports as zero-days to threat actors. With bug bounty platforms getting increasingly popular, it's only a matter of time. And it will be way harder to detect and to trace than it was here. https://twitter.com/... John Opdenakker / @j_opdenakker : Malicious insiders, a nightmare for a company. https://www.bleepingcomputer.com/ ... #infosec Jesse Powell / @jespow : We've been criticized for not having a 3rd party run our bug bounty program but this is exactly why we run it ourselves. Resubmitting bugs for the bounty is the least bad thing that can happen. Worst case, the stolen bugs are sold to more serious hackers or directly exploited. https://twitter.com/... @_no__ : Imagine submitting a bug report, watching it sit pending review to be closed as a dupe for someone to take your entire bug report and collect your bounty. https://twitter.com/... @_mg_ : If DoorDash allowed drivers to query customer details of everyone signed up, not just their active order, people would lose their minds. But bug bounty employees accessing critical vulns of customers they aren't even working on? Just a policy stopping it, no technical controls https://twitter.com/... Cam / @secretlyhidden1 : Crazy. I always made jokes about this and finally has happened. Kudos to hackerone for their work on identifying this quickly. Makes me wonder about the scenarios that don't get caught. This is for sure a type of threat that all companies with BB programs need to watch https://twitter.com/... Kevin Beaumont / @gossithedog : Kinda interesting - somebody mentioned security researchers selling their bug bounty exploits on dark web in parallel, but maybe it was this. https://hackerone.com/... @k8em0 : Insider threats affect every business. Transparency is praiseworthy. Yet conveniently forgetting that “policy & contractual” controls are not the same as technical access controls every time something comes up around triage access abuse is its own open bug requiring resolution. https://twitter.com/... Ionut Ilascu / @ionut_ilascu : Another example of the danger of insider threats. Company identified the culprit only when a customer received from the rogue employee a bug report similar to one that had been submitted through HackerOne on the same vuln. https://twitter.com/... Steve Manzuik / @hellnbak_ : This might be the first public headline of something like this that I've seen but there are many a large companies without proper authn/authz on their bug databases and not the first stolen / resold bugs. https://www.bleepingcomputer.com/ ... Jonathan Scott / @jonathandata1 : Yea, we have been saying this for years. Marking a report critical then dropping it to informational, and then marking it as a duplicate and not letting you see the duplicate...I've been saying @FBI needs to investigate @Hacker0x01 for a long time. https://twitter.com/...

BleepingComputer Ionut Ilascu

Discussion

  • @campuscodi Catalin Cimpanu on x
    HackerOne discloses security incident. The company says that a “then-employee had improperly accessed security reports for personal gain” and shared details about a vulnerability outside the platform https://hackerone.com/... https://twitter.com/...
  • @_no__ @_no__ on x
    Imagine submitting a bug report, watching it sit pending review to be closed as a dupe for someone to take your entire bug report and collect your bounty. https://twitter.com/...
  • @_mg_ @_mg_ on x
    If DoorDash allowed drivers to query customer details of everyone signed up, not just their active order, people would lose their minds. But bug bounty employees accessing critical vulns of customers they aren't even working on? Just a policy stopping it, no technical controls ht…
  • @secretlyhidden1 Cam on x
    Crazy. I always made jokes about this and finally has happened. Kudos to hackerone for their work on identifying this quickly. Makes me wonder about the scenarios that don't get caught. This is for sure a type of threat that all companies with BB programs need to watch https://tw…
  • @gossithedog Kevin Beaumont on x
    Kinda interesting - somebody mentioned security researchers selling their bug bounty exploits on dark web in parallel, but maybe it was this. https://hackerone.com/...
  • @k8em0 @k8em0 on x
    Insider threats affect every business. Transparency is praiseworthy. Yet conveniently forgetting that “policy & contractual” controls are not the same as technical access controls every time something comes up around triage access abuse is its own open bug requiring resolution. h…
  • @ionut_ilascu Ionut Ilascu on x
    Another example of the danger of insider threats. Company identified the culprit only when a customer received from the rogue employee a bug report similar to one that had been submitted through HackerOne on the same vuln. https://twitter.com/...
  • @jespow Jesse Powell on x
    We've been criticized for not having a 3rd party run our bug bounty program but this is exactly why we run it ourselves. Resubmitting bugs for the bounty is the least bad thing that can happen. Worst case, the stolen bugs are sold to more serious hackers or directly exploited. ht…
  • @hellnbak_ Steve Manzuik on x
    This might be the first public headline of something like this that I've seen but there are many a large companies without proper authn/authz on their bug databases and not the first stolen / resold bugs. https://www.bleepingcomputer.com/ ...
  • @jonathandata1 Jonathan Scott on x
    Yea, we have been saying this for years. Marking a report critical then dropping it to informational, and then marking it as a duplicate and not letting you see the duplicate...I've been saying @FBI needs to investigate @Hacker0x01 for a long time. https://twitter.com/...
  • @malwarejake Jake Williams on x
    Frontrunning their own bug bounty is not something I expected to see... https://twitter.com/...
  • @wpalant @wpalant on x
    Still waiting for one that will sell reports as zero-days to threat actors. With bug bounty platforms getting increasingly popular, it's only a matter of time. And it will be way harder to detect and to trace than it was here. https://twitter.com/...
  • @j_opdenakker John Opdenakker on x
    Malicious insiders, a nightmare for a company. https://www.bleepingcomputer.com/ ... #infosec