Threat Intelligence

6/7/2017
06:20 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Centrify Fortifies Platform Security with Bugcrowd Bug Bounty Program

Centrify to award up to $3,000 per vulnerability to ensure the security of the Centrify Identity Services platform.

SAN FRANCISCO – Centrify, the leader in securing hybrid enterprises through the power of identity, today launched a public bug bounty program with Bugcrowd, the leader in crowdsourced security testing. Building on the success of its private, on-demand program, the public program will leverage more than 50,000 security researchers on the Bugcrowd platform to reinforce the security of the Centrify Identity Services platform. Centrify Identity Services secures each user’s access to apps, endpoints and infrastructure through single sign-on, multifactor authentication and privileged identity management.  

Centrify will reward security researchers between $100 - $3,000 USD per bug identified—depending on impact and severity of vulnerabilities identified in our Application Services, Infrastructure Services and corporate website.

"As a leader in identity services, it is incumbent upon us to fully vet the security on our platform to ensure that each user’s access to apps and infrastructure is secure and that we continue to deliver the best solutions," explains Raun Nohavitza, senior director of IT at Centrify. "Bugcrowd’s platform, organization, experience with triage and relationship with the security community make their bounty program very attractive. With Bugcrowd we’re not only doing the right thing for our security offerings in the best way possible, but we’re also getting consistent administration and management for our ongoing program."

At Bugcrowd security expertise is built into the design, support and management of every program. Bugcrowd’s easy-to-use platform connects organizations with a curated crowd of tens of thousands of researchers for quicker identification of vulnerabilities, while its experienced team manages programs every step of the way to ensure organizations see results.

"The explosion of online business has increased the opportunities for adversaries, which makes a strong security stance more important than ever," said Casey Ellis, CEO and founder of Bugcrowd. "Centrify is clearly demonstrating their commitment to keeping their customers secure by proactively engaging the help of the white-hat hacker community through the Bugcrowd platform. Bug bounty programs have emerged as the most effective and efficient way to secure the delivery of products and services, and we are proud to manage their bug bounty program."

To learn more about Centrify’s public bug bounty program or to participate, visit bugcrowd.com/centrify.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Why We Need a 'Cleaner Internet'
Darren Anstee, Chief Technology Officer at Arbor Networks,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11469
PUBLISHED: 2019-04-23
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
CVE-2013-7470
PUBLISHED: 2019-04-23
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
CVE-2019-11463
PUBLISHED: 2019-04-23
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive through 3.3.3 allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo.
CVE-2019-0218
PUBLISHED: 2019-04-22
A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.
CVE-2019-11383
PUBLISHED: 2019-04-22
An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid user via /data/data/com.medhaapps.wififtpserver/shared_prefs/com.medhaapps.wififtpserver_preferences.xml