Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Cloudflare Launches a Paid Public Bug Bounty Program

Cloudflare Launches a Paid Public Bug Bounty Program

Cloudflare, an American company focused on web infrastructure and website security, has announced the launch of a new public bug bounty program.

“Today we are launching Cloudflare’s paid public bug bounty program,” said Rushil Shah, a Product Security Engineer at Cloudflare.

“We believe bug bounties are a vital part of every security team’s toolbox and have been working hard on improving and expanding our private bug bounty program over the last few years.”

Also Read: What Is PDPA And What Are The 5 Things You Should Know About

The new public bug bounty program follows a vulnerability disclosure program without cash bounties created in 2014. Through this program, Cloudflare received 1,197 reports, only 13% of them valid because researchers were struggling to understand its infrastructure and products.

In 2018, Cloudflare launched a private bug bounty program focused on providing a better experience for researchers. By mid-January 2022, Cloudflare awarded $211,512 worth of bounties for in-scope vulnerabilities, going up from $4,500 paid in 2018 to $101,075 in 2021.

The company also released a testing sandbox named CumlusFire before releasing the new public bounty program, which provides bug hunters with a standardized playground to test exploits.

Cloudflare’s new bug bounty program

Starting today, bug hunters can report security vulnerabilities found in Cloudflare products through the company’s new public bug bounty program, hosted on the HackerOne platform.

Researchers can find more info on Cloudflare’s products using the company’s Developer documentationAPI documentation, the Learning Center, and materials found on Cloudflare’s support forums.

The breakdown of bounty awards for targets based on the issues’ CVSS3 severity rating can be found in the table below.

SeverityCritical (9.0 – 10.0)High (7.0 – 8.9)Medium (4.0 – 6.9)Low (0.1 – 3.9)
Primary Targets$3,000$1,000$500$250
Secondary Targets$2,700$750$350$200
Other$2,100$500$200$100

Depending on a vulnerability’s mitigating factors and Cloudflare’s business risk assessment, the reported issues might receive a lower severity rating.

Also Read: The Competency Framework: A Guide for Managers and Staff

“Just as we grew our private program, we will continue to evolve our public bug bounty program to provide the best experience for researchers,” Shah added.

“We aim to add more documentation, testing platforms and a way to interact with our security teams so that researchers can be confident that their submissions represent valid security issues.”

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us