Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

1/30/2020
05:15 PM
50%
50%

Russian Cybercrime Forum Contests Bring Cash, Visibility to Winners

Competitions for users are a long-time tradition on underground cybercrime forums for members looking for money - and cred with major criminal syndicates.

Russian hackers looking to earn a bit of extra cash after the holidays can turn to the cash prizes of a contest on the cybercriminal forum XSS. 

The competition, which has been around in some form since the mid-2000s, nowadays asks contestants to prove their expertise and write an article on a technical solution, according to a new report from Digital Shadows. In addition to a share of $15,000 in prize money, participating hackers have a chance to get noticed by major Russian cybercriminal organizations.

Topics for articles in the current XSS competition include searching for zero-day vulnerabilities and developing exploits, APT attacks, and tricks for new forensics. This year's competition was sponsored and funded by the Sodinokibi (aka REvil) ransomware team.

XSS is not alone in running contests among its users. Russian forums including Verified, Korovka, and Omerta, among others, have sponsored competitions in the past.

For more, read here.

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "7 Steps to IoT Security in 2020."

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
gregwhite20134
50%
50%
gregwhite20134,
User Rank: Strategist
2/2/2020 | 3:19:59 AM
Re: Evil Bug Bounty
Many of them have the most brilliant minds in this field.  Indeed, they can make oney out of it.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15820
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
CVE-2020-15821
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
CVE-2020-15823
PUBLISHED: 2020-08-08
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15824
PUBLISHED: 2020-08-08
In JetBrains Kotlin before 1.4.0, there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
CVE-2020-15825
PUBLISHED: 2020-08-08
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.