fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

DOD Expands Bug Disclosure Program To All Publicly Accessible Systems

DOD Expands Bug Disclosure Program To All Publicly Accessible Systems

US Department of Defense (DOD) officials today announced that the department’s Vulnerability Disclosure Program (VDP) has been expanded to include all publicly accessible DOD websites and applications.

DOD’s VDP is led by the Department of Defense Cyber Crime Center (DC3), and it allows security researchers to search for and report any vulnerabilities affecting public-facing DOD information systems.

Number of reports expected to increase drastically

With today’s expansion, researchers can look for security issues impacting all publicly accessible “DOD networks, frequency-based communication, Internet of Things, industrial control systems, and more.”

Before the VDP was launched, ethical hackers had no way to interact with the DOD even when they discovered valid vulnerabilities.

“Because of this, many vulnerabilities went unreported,” Brett Goldstein, the director of the Defense Digital Service, said

“The DOD Vulnerability Policy launched in 2016 because we demonstrated the efficacy of working with the hacker community and even hiring hackers to find and fix vulnerabilities in systems.”

With the VDP’s scope expanding, DOD Cyber Crime Center director Kristopher Johnson expects the numbers of reports to increase dramatically due to security researchers discovering and reporting vulnerabilities previously unreportable.

“The department has always maintained the perspective that DOD websites were only the beginning as they account for a fraction of our overall attack surface,” Johnson added.

Also Read: How To Comply With PDPA: A Checklist For Businesses

More than 30,000 reports submitted via DOD’s VDP

Since it was officially established in 2016, over 30,000 vulnerability reports have already been submitted through this program, with more than 70% of them containing a valid bug impacting DOD systems.

The DOD used information collected through the bug bounty program to strengthen the security of the US DoD Information Network (DoDIN).

In collaboration with the Defense Counterintelligence Security Agency, the DoD Cyber Crime Center launched a 12-month Defense Industrial Base Vulnerability Disclosure Program (DIB-VDP) pilot in April for defense industrial base (DIB) companies.

The DIB-VDP allows ethical hackers to report vulnerabilities in DoD contractor partner’s information systems, web properties, and other in-scope assets.

Also Read: 4 Considerations In The PDPA Singapore Checklist: The Specifics

“The expansion of vulnerability research to participating DoD contractor networks replicates the DoD’s’ success by making participating DoD contractor networks available for vulnerability research,” DoD’s Cyber Crime Center explains.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us