Bug Bounty

Platform

  • BugCrowd
  • HackerOne - platform that connects you to ethical hackers who work for you continuously protect your attack surface and find critical risks.
  • HackenProof - Expert web3 bug bounty and crowdsourced audit platform.
  • Intigriti - platform where you can lunch, hunt, and manage bug bounty programs with the help of ethical hackers and researchers.
  • 0din.ai - Mozilla’s 0Day Investigative Network (0Din) is a GenAI bug bounty program that incentivizes the discovery and reporting of security vulnerabilities in large language models, attention-based systems and other generative models to enhance Internet and personal safety.
  • OpenBugBounty - Free bug bounty program.
  • Huntr - huntr provides a single place for security researchers to submit vulnerabilities, to ensure the security and stability of AI/ML open-source apps and libraries and ML model file formats.
  • YesWeHack - YesWeHack is a leading Bug Bounty and Vulnerability Management Platform that was founded in 2015.
  • Zerodium - bug bounty program founded by cyber security expert that offers zero-day research.

Company Program

  • Google - Google Bug Hunters is aimed at external security researchers who want to contribute to keeping Google products safe and secure.
  • Github - Github bug bounty program.
  • LeetCode - LeetCode Bug Bounty Program.
  • Meta - Meta bug bounty.
  • Proton - Proton bug bounty program.

Conferences

  • Blackhat - Founded in 1997, Black Hat is an internationally recognized cybersecurity event series providing the most technical and relevant information security research.
  • Defcon - is a hacker convention held annually in Las Vegas, Nevada.
  • KiwiCon [New Zealand] - New Zealand’s Hacker Con
  • Microsoft - Bluehat
  • Nullcon - Nullcon came into existence in the year 2010 and is managed and marketed by Payatu Technologies Pvt Ltd.
  • Offensivecon [Berlin, Germany] - Offensive security conferences

Foundation

  • OpenSSF - The Open Source Security Foundation (OpenSSF) seeks to make it easier to sustainably secure the development, maintenance, and consumption of the open source software (OSS) we all depend on.
  • OWASP - The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.

Training and Certification 🏕️

  • Academy TCM - training and certification from tcm-sec.
  • HackTheBox - Hack The Box gives individuals, businesses and universities the tools they need to continuously improve their cybersecurity capabilities — all in one place.
  • PortSwigger - web security academy - Free, online web security training from the creators of Burp Suite.
  • Root-Me - The fast, easy, and affordable way to train your hacking skills.
  • TryHackMe - We’re a gamified, hands-on cyber security training platform that you can access through your browser, with blue, red and purple team content for all skill levels.
  • ZerodayEngineering - Zero Day vulnerability research and training.

Reading, Listening and Watching

Book / Guide

News

Podcast

  • DarknetDiaries - This is a podcast about hackers, breaches, shadow government activity, hacktivism, cybercrime, and all the things that dwell on the hidden parts of the network. New episodes every first Tuesday of the month.

Youtube

  • @jstrosch - videos about malware analysis, reverse engineering and other cyber security topics.
  • @ippsec - mostly HTB related topics.
  • @0xdf
  • @MalwareTechBlog - Tech insights from a software engineer and cybersecurity professional.
  • @RanaKhalil101 - Channel that discusses security related topics.
  • @lauriewired - Reverse engineer (malware, mobile analysis, etc).