TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

Bug Bounties for the 99%

2022-09-27 · Read original ↗

ATT&CK techniques detected

4 predictions
T1195Supply Chain Compromise
75%
"bug bounties for the 99 % intro by andrew morgan, founder of right of boom cyber summit. march 26, 2020, and july 2, 2021, are two dates that will be seen as turning points for the way managed service providers ( msps ) run their businesses. the solarwinds sunburst ( 2020 ) and t…"
T1588.002Tool
73%
"as “ bug bounty programs " and, as expected, the most active bug bounty programs are run by the most successful tech businesses. they get the lion ’ s share of the attention from the research community. unfortunately, that leaves a large swath of the tech landscape ( small to med…"
T1190Exploit Public-Facing Application
66%
"via tools like metasploit, cobalt strike, etc. ), so due to the lack of technical skills required to operate these tools and launch such attacks, the incoming wave of activity can be overwhelming to even those with a substantial security presence. the cleanup of one such exploit,…"
T1588.006Vulnerabilities
51%
". capitalizing on the fervor associated with these recent security events, google aims to further incentivize security researchers in spending time investigating design issues that may lead to exploitable vulnerabilities. bug bounties are becoming more prevalent these days, and t…"

Summary

Bug bounty programs are everywhere for enterprise organizations. But where does that leave the 99%—those under-resourced small to mid-sized businesses?