Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
Show notes
Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software. We discuss how orgs can be more effective at securing their environment and what role LLMs might have in evaluating controls. Plus, we look to the future of bug bounty programs and how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-402