HomeSecurityThe pandemic increased vulnerability submissions and bug bounties

The pandemic increased vulnerability submissions and bug bounties

Vulnerability submissions have increased over the past 12 months, with critical issue reports submitted to the Bugcrowd platform seeing a 65% jump.

vulnerability submissions

The data comes from the Bugcrowd platform and reflects the increase in bug bounty payments as ethical hackers hunt for more critical vulnerabilities, combining bugs and developing a proof-of-concept exploit code.

The Bugcrowd platform says that companies offering consumer and media services receive reports of critical issues in less than a day.

For organizations in the government and automotive sectors, high-risk bugs are submitted in a few days.

This year, vulnerability submissions through the Bugcrowd platform saw a 50% increase, while priority 1 reports (the most critical) saw a 65% increase.

Web apps remain a top choice for hackers, although attackers are diversifying their targets to remain competitive.

Between January and October 2020, organizations in financial services received more vulnerability submissions than in all of 2019. Payouts for P1 vulnerabilities in this sector doubled in the second quarter of this year.

Hackers also stepped up their attacks, leading companies to increase payouts for serious issues. Overall, payouts for critical vulnerabilities (P1) increased by 31% from Q1 to Q2. The same was true for P2 bugs between Q2 and Q3.

At the top of the list of the most vulnerable vulnerabilities submitted through the Bugcrowd platform are human-controlled “broken” access controls, eliminating cross-site scripting (XSS).

Subdomain acquisition also moved up two spots on the list, from sixth to fourth – the reason behind the jump was hackers' increased use of automation in searching for bugs.

Although zero-day get all the attention as they are usually associated with attacks by an APT group, more often than not these adversaries rely on known exploits.

Bugcrowd notes that the changes recorded this year are in line with the challenges of remote working imposed by the pandemic. After spending more time at home, bug hunters were able to be more active and find higher severity bugs, as well as submit better quality reports.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS