Ferdi F. Zebua ๐ŸŒ · @FerdiZ
367 followers · 8010 posts · Server mastodon.cloud

Protect your business and build trust with customers and stakeholders by creating a comprehensive vulnerability disclosure policy! Our ultimate guide shows you how to do it right. cyber-consult.org/secure-your-

#vulnerabilitydisclosure #cybersecurity #ethicalhacking

Last updated 1 year ago

CryptoNewsBot · @cryptonewsbot
443 followers · 21045 posts · Server schleuss.online
Guido Schulte · @GuidoSchulte
27 followers · 58 posts · Server social.tchncs.de

Hall of Fame fรผr Scherheitsforschende

"Vorbilder
Danksagungen an diejenigen, die Sicherheitslรผcken melden, sind insbesondere in groรŸen US-amerikanischen Konzernen wie Google und Microsoft lรคngst gang und gรคbe. Aber auch das BSI und die Bundeswehr haben bereits eigene Webseiten mit Danksagungen; im Bereich der Medien ist das allerdings bislang eher unรผblich."

heise.de/news/In-eigener-Sache

#Schwachstellenmanagement #VDPBw #VDP #vulnerabilitydisclosure

Last updated 1 year ago

Allen Householder · @adh
76 followers · 25 posts · Server infosec.exchange
John Opdenakker · @j_opdenakker
1907 followers · 731 posts · Server infosec.exchange

This is awesome. The Centre for Cyber Security Belgium (CCB) has adopted a framework that protects individuals or organizations from prosecution (if they play by the rules) when they report security vulnerabilities affecting any systems, networks, or applications located in Belgium.

ccb.belgium.be/en/news/new-leg

#infosec #vulnerabilitydisclosure

Last updated 1 year ago

100th post, as fine a time as any to do the traditional before nobody on does them anymore.
Iโ€™m a , a parent, a founder & CEO, government advisory board member, cat food servant, defender and participant in democracy, & an arm wrestling and karaoke enthusiast โ€” not necessarily at the same time, but not opposed to trying it all at once either.
Carpe brachium karaoke as they say. ๐Ÿ’ช๐Ÿผ๐ŸŽค
Here we go. Get a snack & some water, this is long. ๐Ÿช ๐Ÿฅ›
My professional passions include & with my on helping organizations & governments develop healthy sustainable programs that may end up growing into a program, or helping existing programs mature & evolve.
๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ
๐ŸŒบI founded & run Lutasecurity.com & we employ dozens of people, mostly in the US, to help some of our customers manage their and as internally-placed personnel.
๐Ÿ“œServices: lutasecurity.com/services
๐Ÿ’ปHiring: lutasecurity.com/careers
๐Ÿ’ตReferral bounties: lutasecurity.com/referralbount
๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ ๐ŸŒบ๐Ÿ๏ธ
๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ ๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ ๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ
I helped launch in 2016, which was the first bug bounty of the US government & the first time it was legal to hack the USG.
๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ ๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ ๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป๐Ÿ’ฐ๐Ÿ›ก๏ธ
This was after I created Microsoftโ€™s first bug bounty programs in 2013, paying out the most at the time for brand new exploitation techniques, which would later lead to me directly helping the US renegotiate the Arrangement to clarify โ€œintrusion softwareโ€ and โ€œintrusion software technologyโ€ export control exemptions to more easily allow for hassle-free exchange of 0day & malware samples across borders for vulnerability disclosure & incident response.
๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป
I also started two vulnerability research programs, Symantec Vulnerability Research & Microsoft Vulnerability Research. The latter was also the first formal major vendor multiparty vulnerability coordination & disclosure program.
๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป ๐Ÿ› ๏ธ๐Ÿ’ป
I now serve on 3 Federal advisory boards in cyber.
โš–๏ธNIST ISPAB: csrc.nist.gov/Projects/ispab/m
๐Ÿ’ฑCommerce ISTAC: tac.bis.doc.gov/index.php/docu
๐ŸšจDHS CSRB: dhs.gov/news/2022/02/03/dhs-la
๐ŸŽ™๏ธFun fact: Despite mainstream media lip service about getting diverse voices on TV, and my extensive direct experience in US domestic & foreign cyber policy & norm-setting, I have *never* been invited to be on broadcast news to talk about it. Not one time. But there are the same dudes with none of my experience showing up on TV all the time.
๐Ÿ“บ Email Press@Lutasecurity.com if you can change that.
๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ๐Ÿ“บ
โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ
๐Ÿ‘ฉ๐Ÿปโ€โš–๏ธ Speaking of gender equity, I was the lead plaintiff in the attempted class action gender pay and promotion discrimination lawsuit against Microsoft.
๐Ÿ’ต๐Ÿ’ช๐Ÿผ theverge.com/22331972/pay-equi
When it failed to get class certified due to some legal gotchas, NOT because of lack of data and evidence, I decided to drop my case and founded payequitynowfoundation.org/blo & created
manglonalab.org/ to fight for in our lifetime.
โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ โš–๏ธ๐Ÿ’ธ
๐ŸŒธAnother fun fact: Iโ€™m asked about the gender stuff way more often than any of my professional work or national security work. I view this as The Lady Tax & Iโ€™m all paid up thanks.
๐Ÿ™…๐Ÿปโ€โ™€๏ธDonโ€™t ask me about how to attract more diverse candidates, donโ€™t ask me to mentor your mentee, and donโ€™t ask me for any more free labor. Donโ€™t ask any historically marginalized people to do free labor, especially to solve your diversity puzzle.
๐Ÿ‘๐ŸผI highly recommend blacktechpipeline.com/ if you are serious about not just hiring but welcoming more black workers into your company. There are specialty recruiters out there for you to pay, so donโ€™t ask every woman or person of color you know to help you with that unless they are being paid to do it.
๐Ÿ‘๐Ÿผ๐Ÿ’ฐ๐Ÿ‘๐Ÿผ๐Ÿ’ฐ๐Ÿ‘๐Ÿผ๐Ÿ’ฐ๐Ÿ‘๐Ÿผ๐Ÿ’ฐ
๐Ÿงฉ Miscellaneous bits if youโ€™ve made it this far is that I studied molecular biology, biochemistry & mathematics but dropped out to become a systems administrator, a professional Linux developer, then a hacker for hire.
๐Ÿ” I still hack by accident (because hacksidents happen), and nobody should have to be the coauthor/coeditor of the International Standards on how to do Vulnerability Disclosure to get an organizationโ€™s attention.
๐Ÿ‘ฉ๐Ÿปโ€๐Ÿซ ISO standards overview: m.youtube.com/watch?v=-L3DNZtK

๐Ÿ“ฒ Clubhouse hack: wired.com/story/clubhouse-bug-
๐Ÿ”๐Ÿ”๐Ÿ”๐Ÿ”๐Ÿ”๐Ÿ”๐Ÿ”
๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ
๐Ÿ™„ Despite my entire career being technical, when my company tried for venture capital funding to build something cool, we were met with sexism & lack of imagination & I was hilariously asked more than once if I had a technical cofounder.
Itโ€™s cool, jokeโ€™s on them. Weโ€™re and growing.
๐Ÿคจvice.com/en/article/xgyvza/thi
๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ๐Ÿ’ธ
๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ
I participate in Democracy with more than voting. Anyone with the bandwidth should look into doing it too.
1. Google โ€œfind my Legislative districtโ€
2. Go to your State website & search by your address
3. Look up your Legislative Districtโ€™s (LD) website to find out how to join
4. Attend monthly LD meetings
5. Run for Delegate per LD or be appointed like me when not enough people do 1-4
๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ๐Ÿ›๏ธ
๐Ÿ‘‹๐ŸผโœŒ๐Ÿผ๐Ÿ‘‹๐ŸผโœŒ๐Ÿผ๐Ÿ‘‹๐ŸผโœŒ๐Ÿผ๐Ÿ‘‹๐ŸผโœŒ๐Ÿผ
๐Ÿ›‘Ending abruptly is on brand for me as a neuroatypical person, so Iโ€™ll leave you with this thought:
๐Ÿˆ I named my 17 year old cat Scapy (rhymes with happy) after the Python tool of the same name. Because he is dumb & fuzzy.
๐Ÿ˜ธIf you get that joke, you pretty much get me.
๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ๐Ÿค™๐Ÿฝ
โœŒ๐ŸผBe kind, drink water, touch grass, save the planet, save Democracy, pet cute animals. โœŒ๐Ÿผ

#introduction #mastodon #hacker #SystemDynamics #security #focus #vulnerabilitydisclosure #bugbounty #vdps #bugbounties #hackthepentagon #wassenaar #supplychain #payequity #profitable

Last updated 2 years ago

Thorkson Ericsson :donor: · @thorkson
173 followers · 30 posts · Server infosec.exchange

@hdm I guess you know this already but for some of your followers:

If you ever need help in the future with vulnerability disclosure and need 3th party to coordinate:

I have very good experience with CERT(s), as long as you don't want any bounty, other forms of "payment" or want your name on each newspaper frontpage for fame those organizations can coordinate the disclosure.

Which is very nice!

I can only speak for @certbund and the Polish CERT but i guess all those kind of organizations will support you.

#vulnerabilitydisclosure

Last updated 2 years ago

ITSEC News · @itsecbot
738 followers · 32490 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
The Hacker News · @thehackernews
402 followers · 2779 posts · Server social.tchncs.de
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy - Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes availab... more: threatpost.com/google-ditches-

#google #90days #bugbounty #projectzero #policychanges #vulnerabilities #coordinateddisclosure #vulnerabilitydisclosure

Last updated 5 years ago

The Hacker News · @thehackernews
402 followers · 2779 posts · Server social.tchncs.de