• HackerOne employee stole bug reports and collected the bounties

    From TechnologyDaily@1337:1/100 to All on Mon Jul 4 10:45:04 2022
    HackerOne employee stole bug reports and collected the bounties

    Date:
    Mon, 04 Jul 2022 09:24:51 +0000

    Description:
    An insider was scooping up vulnerability reports and disclosing the findings to the vendors in exchange for a reward.

    FULL STORY ======================================================================

    An employee of bug bounty platform HackerOne has been stealing user-submitted reports and disclosing the information to the affected vendors, sometimes in exchange for financial reward.

    In a blog post , the company revealed the details of the incident, which took place over the course of roughly three months, and confirmed that the
    employee has since been fired.

    HackerOne is still considering whether or not to pursue a criminal lawsuit, BleepingComputer reported. Identical reports raising eyebrows

    In early April, HackerOne brought in a new employee who, due to his position, had access to bug reports. These reports highlight vulnerabilities in various software and services that could be exploited by cybercriminals to steal passwords and other sensitive information, distribute malware and more.

    From early on, the individual began gathering reports, and under a fake name reaching out to the affected businesses, often in a threatening and intimidating tone, HackerOne said.

    The employee would then demand payment in exchange for the vulnerability disclosure, and in some instances even got his way.

    HackerOne was alerted to the potential fraud when one of its affected clients reached out to say that another person discovered an identical flaw. While duplicate discoveries in bug hunting aren't uncommon, this particular
    instance was identical to such an extent that it arose suspicion, the company said. Read more

    Google is upping its Linux bug bounty prize


    1Password ups maximum bug bounty


    Best patch management tools of 2022

    Together with payment providers, HackerOne was able to follow the money, and soon discovered one of its own employees was behind the scheme.

    Soon after, it banned the employee from accessing the system, and remotely locked his laptop, pending investigation. The investigation showed all of the bug reports the person had accessed, prompting the company to reach out to both the hackers discovering the bugs and the companies affected.

    The company also said that not all of the bug reports that the person
    accessed were abused. In some cases, the access was for legitimate purposes. Protect your devices from bad actors with the best malware removal services right now

    Via: BleepingComputer



    ======================================================================
    Link to news story: https://www.techradar.com/news/hackerone-employee-stole-bug-reports-and-collec ted-the-bounties/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)