Description
Total length of the course: <1 hour
Vulnerabilities are the raw material of both cyber offence and defence, and understanding them is fundamental to understanding cybersecurity. In this conversation, we start from the ground up: what vulnerabilities and exploits actually are, how researchers find and prove them, and why some are worth far more than others. From there, explore how bug bounty programs work, what organizations get wrong when running them, and what decades of experience, including inside government, reveals about turning vulnerability disclosure into something that actually improves security.
Content details
What is a vulnerability, and how is it different from an exploit?
You don't currently have access to this content
How do you find a vulnerability?
You don't currently have access to this content
How do you prove a vulnerability exists?
You don't currently have access to this content
What is an exploit ‘primitive’?
You don't currently have access to this content
What are the main classes of vulnerability you see today?
You don't currently have access to this content
Why are some vulnerabilities more valuable than others?
You don't currently have access to this content
How do bug bounties fit into the broader vulnerability and exploit marketplace?
You don't currently have access to this content
What is a bug bounty program and how does it work?
You don't currently have access to this content
What kinds of organizations actually need a bug bounty program, and which do not?
You don't currently have access to this content
What are some of the most common mistakes companies make when setting up a bounty?
You don't currently have access to this content
When a vulnerability report comes in, how should organizations respond?
You don't currently have access to this content
How do organizations decide how much to pay for a bug?
You don't currently have access to this content
What did you learn from running a bug bounty inside government?
You don't currently have access to this content
Should every government have a bug bounty program?
You don't currently have access to this content
What is the role of vulnerability research in offensive capability pipelines?
You don't currently have access to this content