HackerOne says an employee stole vulnerability reports submitted through its bug bounty platform and disclosed them to seven companies for financial rewards
Sunday, July 03, 2022 // (IG): BB //Weekly Sponsor: Zanes Hand Made (leather works) Slashdot : How Bug Bounty Platform HackerOne Handled Its Own ‘Internal Threat’ Actor Tweets: Jake Williams / @malwarejake : Frontrunning their own bug bounty is not something I expected to see... https://twitter.com/... Catalin Cimpanu / @campuscodi : HackerOne discloses security incident. The company says that a “then-employee had improperly accessed security reports for personal gain” and shared details about a vulnerability outside the platform https://hackerone.com/... https://twitter.com/... @wpalant : Still waiting for one that will sell reports as zero-days to threat actors. With bug bounty platforms getting increasingly popular, it's only a matter of time. And it will be way harder to detect and to trace than it was here. https://twitter.com/... John Opdenakker / @j_opdenakker : Malicious insiders, a nightmare for a company. https://www.bleepingcomputer.com/ ... #infosec Jesse Powell / @jespow : We've been criticized for not having a 3rd party run our bug bounty program but this is exactly why we run it ourselves. Resubmitting bugs for the bounty is the least bad thing that can happen. Worst case, the stolen bugs are sold to more serious hackers or directly exploited. https://twitter.com/... @_no__ : Imagine submitting a bug report, watching it sit pending review to be closed as a dupe for someone to take your entire bug report and collect your bounty. https://twitter.com/... @_mg_ : If DoorDash allowed drivers to query customer details of everyone signed up, not just their active order, people would lose their minds. But bug bounty employees accessing critical vulns of customers they aren't even working on? Just a policy stopping it, no technical controls https://twitter.com/... Cam / @secretlyhidden1 : Crazy. I always made jokes about this and finally has happened. Kudos to hackerone for their work on identifying this quickly. Makes me wonder about the scenarios that don't get caught. This is for sure a type of threat that all companies with BB programs need to watch https://twitter.com/... Kevin Beaumont / @gossithedog : Kinda interesting - somebody mentioned security researchers selling their bug bounty exploits on dark web in parallel, but maybe it was this. https://hackerone.com/... @k8em0 : Insider threats affect every business. Transparency is praiseworthy. Yet conveniently forgetting that “policy & contractual” controls are not the same as technical access controls every time something comes up around triage access abuse is its own open bug requiring resolution. https://twitter.com/... Ionut Ilascu / @ionut_ilascu : Another example of the danger of insider threats. Company identified the culprit only when a customer received from the rogue employee a bug report similar to one that had been submitted through HackerOne on the same vuln. https://twitter.com/... Steve Manzuik / @hellnbak_ : This might be the first public headline of something like this that I've seen but there are many a large companies without proper authn/authz on their bug databases and not the first stolen / resold bugs. https://www.bleepingcomputer.com/ ... Jonathan Scott / @jonathandata1 : Yea, we have been saying this for years. Marking a report critical then dropping it to informational, and then marking it as a duplicate and not letting you see the duplicate...I've been saying @FBI needs to investigate @Hacker0x01 for a long time. https://twitter.com/...