I wonder what the intersection is between those crying about AI and bug bounty being dead, and those that bought courses on how to do bug bounty. #bugbounty#thoughtfortheday
@hakluke It'd be fair for the platform on request. Researchers get a bit emotional. It'd help build trust in the platform and the program - trust isn't just about the researcher. If many bugs are dup, does program see value? Seems smart to follow up for platform on this point too.
It also didn’t help seeing how few of the “trusted few” pushed back, even with early access to feedback. If Synack is a main income source, it’s probably time to look elsewhere. If you’re just gaming missions, you might be fine. Here are my YoY results.
This year I spent most of my spare time hacking with #SynackRedTeam, but eased off later in the year after some awful changes to "short" tests resulting in less clarity on payouts and reduced pay for more effort... (1/3)
Alongside this was a shift to a mission-based pentest model that feels increasingly exploitative, especially when you factor in the time investment versus what you’re actually paid.... (2/3)
‼️ Meet Ryan Clifford Goldberg, a Digital Forensics and Incident Response manager at Sygnia, he is one of three insiders accused of cybercrimes. He allegedly conducted cyberattacks using ALPHV BlackCat ransomware.
Goldberg and two other insiders ran ransomware operations since 2023 while employed at cybersecurity firms. After an FBI visit, Goldberg confessed. He now faces up to 50 years in prison.
NEED YOUR HELP!
My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,...
but companies keep saying:
"we aren't hiring right now!"
if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team
you're retweet is Extremely appreciated ❤️🔥
soroush, if you see this, don't hate me, had to do it without telling you
As someone who has to to muck in with IR, thrunting and the like... it amazes me how many times it starts with with the most clearly dodgy looking phishing email. 😭
Couple of weeks without finding a bug and I feel like I've forgotten everything I once knew. I need some #bugbountytips and some bug bounty courses ASAP.
@irsdl That's why I use the word 'void', because it's a big black box if you're using someone else's service. You can only hope they do the right things 😂
@irsdl And to that end, say do plug in to your own "thing", how can a business be sure your controls are sufficient to safeguard whatever was kept. And what's to say how another company uses it. Needs a lot of thought for enterprise use.