<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Secur0 - Bug Bounty con Ñ]]></title><description><![CDATA[Newsletter mensual sobre bug bounty en el mercado iberoamericano.]]></description><link>https://newsletter.secur0.com</link><image><url>https://substackcdn.com/image/fetch/$s_!YzZ3!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61a37d4a-5107-4239-aca1-bc8bc78c1df1_512x512.png</url><title>Secur0 - Bug Bounty con Ñ</title><link>https://newsletter.secur0.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 06 May 2026 11:52:27 GMT</lastBuildDate><atom:link href="https://newsletter.secur0.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Javier Juárez Zarruk]]></copyright><language><![CDATA[es]]></language><webMaster><![CDATA[javier@secur0.com]]></webMaster><itunes:owner><itunes:email><![CDATA[javier@secur0.com]]></itunes:email><itunes:name><![CDATA[Secur0]]></itunes:name></itunes:owner><itunes:author><![CDATA[Secur0]]></itunes:author><googleplay:owner><![CDATA[javier@secur0.com]]></googleplay:owner><googleplay:email><![CDATA[javier@secur0.com]]></googleplay:email><googleplay:author><![CDATA[Secur0]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Grayback: nueva plataforma de Bug Bounty en español]]></title><description><![CDATA[La realidad inc&#243;moda del mercado espa&#241;ol de bug bounty y por qu&#233; en Secur0 hemos decidido construir a largo plazo.]]></description><link>https://newsletter.secur0.com/p/grayback-nueva-plataforma-de-bug</link><guid isPermaLink="false">https://newsletter.secur0.com/p/grayback-nueva-plataforma-de-bug</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Sun, 01 Mar 2026 22:22:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!W3M-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Estos d&#237;as ha salido <a href="https://www.grayback.es/">Grayback</a>, una nueva plataforma de bug bounty en espa&#241;ol, y muchas personas nos han preguntado qu&#233; pensamos desde Secur0.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W3M-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W3M-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 424w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 848w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 1272w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W3M-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png" width="1153" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1153,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:388318,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/189585640?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W3M-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 424w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 848w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 1272w, https://substackcdn.com/image/fetch/$s_!W3M-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9a08a2e-3f56-4aa0-a882-cae3c3ab1178_1153x648.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><a href="https://www.grayback.es/">Grayback</a></figcaption></figure></div><p></p><p>La verdad es que nos parece l&#243;gico que aparezcan nuevas plataformas nacionales. De hecho, que nazcan proyectos como Grayback es se&#241;al de que el mercado empieza a moverse.</p><p>Y eso es positivo.</p><p>Pero tambi&#233;n creemos que es importante hablar de la pregunta inc&#243;moda:</p><p></p><h3>&#191;Puede una plataforma espa&#241;ola competir de verdad?</h3><p>Llevamos m&#225;s de un a&#241;o construyendo Secur0 y hubo una pregunta que durante mucho tiempo no supimos responder bien:<br>&#191;En qu&#233; se diferencia realmente Secur0 de gigantes como <a href="https://www.hackerone.com/">Hackerone</a>, <a href="https://www.bugcrowd.com/">Bugcrowd</a>, <a href="https://www.yeswehack.com/">YesWeHack</a>, <a href="https://www.intigriti.com/">Intigriti</a> &#8230;?</p><p>La verdad es que, m&#225;s all&#225; de su fuerza comercial, tampoco est&#225; claro qu&#233; los diferencia entre ellos.</p><p>La conclusi&#243;n inc&#243;moda a la que llegamos es que<strong> competir frontalmente contra ellos no tiene sentido estrat&#233;gico&#8230; al menos, no hoy.</strong></p><p>Intentar ser el &#8220;HackerOne espa&#241;ol&#8221; ser&#237;a ingenuo. En Secur0 no estamos aqu&#237; para autoenga&#241;arnos: preferimos construir paso a paso, con madurez y estrategia.</p><h3><br><br>El problema no es la competencia. Es la madurez del mercado.</h3><p>El bug bounty no es un servicio que se venda por precio.<br>Ni por ser &#8220;plataforma espa&#241;ola&#8221;.<br>Ni por cercan&#237;a cultural.</p><p>Es una decisi&#243;n que implica: <em>equipos legales, procesos internos complejos, gesti&#243;n de riesgo reputacional y capacidad de respuesta real ante vulnerabilidades. </em>Y, sobre todo, madurez en seguridad.</p><p>La realidad <strong>es que pocas empresas en Espa&#241;a est&#225;n preparadas para lanzar un programa p&#250;blico de bug bounty serio.</strong></p><p>Esa es la conversaci&#243;n real.</p><p></p><h3>Lo que aprendimos</h3><p>Al principio tambi&#233;n nos planteamos si deb&#237;amos ir directamente a vender BBP a grandes empresas. Despu&#233;s de hablar con fundadores de otras plataformas locales de bug bounty, como <a href="https://defenddenmark.dk/">Defend Denmark</a>, <a href="https://www.cyberdart.eu/">CyberDart</a>&#8230; y tambi&#233;n con iniciativas espa&#241;olas como <a href="https://www.epicbounties.com/es/">Epic Bounties</a> y CazHack, nos dimos cuenta de que no pod&#237;amos intentar vender solo bug bounty desde el primer d&#237;a o &#237;bamos a morir en el intento esperando un contrato con una gran empresa.</p><p>Decidimos <strong>empezar con 3.000&#8239;&#8364; y escalar desde ah&#237;</strong>, creciendo paso a paso hasta formar el equipo de 15 personas que somos hoy. Dani y yo no quer&#237;amos ir &#8220;a por todas&#8221; como el modelo tradicional de una startup sin antes tener una base s&#243;lida.</p><p>Por eso nuestra estrategia ha sido clara: <em>pentesting continuo, subir el nivel t&#233;cnico en cada ejercicio, acompa&#241;ar a los equipos internos y mejorar procesos de gesti&#243;n de vulnerabilidades</em>, en definitiva, construir madurez real.</p><p>Cuando el cliente est&#233; preparado, entonces s&#237; tendr&#225; sentido hablar de bug bounty. Esto es un proceso de a&#241;os, y estamos c&#243;modos con eso.</p><p></p><h3>&#191;Y qu&#233; implica esto para la comunidad hacker?</h3><p>No vamos a competir p&#250;blicamente con plataformas como HackerOne o Intigriti en volumen o recompensas millonarias. Nuestros programas visibles se centran en pentesters junior, estudiantes y quienes buscan su primera vulnerabilidad, con un enfoque en aprendizaje y mejora continua.</p><p>Al mismo tiempo, para<strong> los mejores hackers de nuestra comunidad habr&#225; oportunidades privadas, adaptadas a su nivel, con retos y recompensas competitivas.</strong> De esta manera, aseguramos que quienes demuestran talento puedan seguir creciendo y contribuir mientras ayudamos a formar a la pr&#243;xima generaci&#243;n de pentesters y bug hunters.</p><p>En Secur0 no buscamos retener talento: buscamos potenciarlo y darle las herramientas para llegar m&#225;s lejos.</p><p></p><h3>Entonces, &#191;qu&#233; significa la aparici&#243;n de Grayback?</h3><p>Que el mercado de bug bounty en espa&#241;ol se est&#225; moviendo.</p><p><strong>Si Grayback atrae empresas nuevas o ayuda a educar sobre bug bounty, es bueno para todos.</strong> Por eso desde Secur0 queremos felicitar a David Padilla y su equipo por lanzar Grayback y  les deseamos mucha suerte.</p><p>Nosotros seguimos con nuestro camino: construir madurez, formar talento y acompa&#241;ar a la comunidad. </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Community Fund en Bug Bounty]]></title><description><![CDATA[El innovador modelo de Defend Iceland]]></description><link>https://newsletter.secur0.com/p/community-fund-en-bug-bounty</link><guid isPermaLink="false">https://newsletter.secur0.com/p/community-fund-en-bug-bounty</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Tue, 03 Feb 2026 08:02:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CNtE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://defendiceland.is/">Defend Iceland</a> es una plataforma de bug bounty de Islandia con un modelo &#250;nico de <strong>community fund. </strong>El proyecto fue fundado por <a href="https://www.linkedin.com/in/theodor-ragnar-gislason-8753a92b/">The&#243;d&#243;r R. G&#237;slason</a> en 2023, gracias a un <a href="https://www.seren-project.eu/wp-content/uploads/2025/04/Project-Fact-Sheet_ECEDEF.pdf">grant de 2,6 millones del Digital Europe Programme.</a> Desde entonces, Defend Iceland no ha hecho m&#225;s que crecer: de 0 a 50.000&#8239;&#8364; de ingresos mensuales en tan solo un par de a&#241;os. Actualmente cuentan con un equipo de 8 personas, todos los bancos de Islandia est&#225;n en la plataforma y, adem&#225;s, mantienen una clara <strong>rama de impacto social.</strong></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8P1W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8P1W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 424w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 848w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 1272w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8P1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png" width="883" height="229" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:229,&quot;width&quot;:883,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/186651436?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8P1W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 424w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 848w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 1272w, https://substackcdn.com/image/fetch/$s_!8P1W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02ffcff8-007a-477b-9e12-3a8f8a48cbfc_883x229.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption"><a href="https://defendiceland.is/en/community-fund/">Community Fund</a></figcaption></figure></div><h3><br>El Community Fund</h3><p>El <a href="https://defendiceland.is/en/community-fund/">Community Fund</a> se financia de dos maneras: con las aportaciones de los clientes de Defend Iceland y con las de la comunidad de hackers &#233;ticos.</p><p>La contribuci&#243;n de los clientes se basa en la recompensa econ&#243;mica que se paga por las vulnerabilidades de seguridad. A esos pagos se les a&#241;ade<strong> una tarifa fija del 10&#8239;%</strong>, que constituye la aportaci&#243;n del cliente al fondo cada vez que paga por una vulnerabilidad.</p><p>Por su parte, los hackers &#233;ticos tambi&#233;n pueden realizar <strong>contribuciones voluntarias</strong> al fondo con parte de sus recompensas.</p><p>El fondo se destina a<strong> pagar por vulnerabilidades detectadas en entidades sin &#225;nimo de lucro,</strong> protegiendo datos confidenciales e infraestructuras cr&#237;ticas.<br></p><h3><br>Modelo abierto</h3><p>El Community Fund no es lo &#250;nico admirable de Defend Iceland. La plataforma tambi&#233;n destaca por su modelo de transparencia total, compartiendo a trav&#233;s de un dashboard p&#250;blico el estado de la plataforma:</p><ul><li><p>Recompensas pagadas</p></li><li><p>Estado del Community Fund</p></li><li><p>Tiempo medio para aceptar una vulnerabilidad</p></li><li><p>Desglose de las vulnerabilidades</p></li><li><p>Cantidad media pagada seg&#250;n criticidad</p></li></ul><p>Una<strong> transparencia admirable</strong> que permite a la comunidad y a los clientes seguir de cerca el impacto real de sus contribuciones.<br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CNtE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CNtE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 424w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 848w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 1272w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CNtE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png" width="1198" height="1177" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1177,&quot;width&quot;:1198,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:198671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/186651436?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CNtE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 424w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 848w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 1272w, https://substackcdn.com/image/fetch/$s_!CNtE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc656bac5-2289-4c4a-8884-044ce4adfd7a_1198x1177.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><a href="https://defendiceland.is/en/dashboard/">Defend Iceland Dashboard</a></figcaption></figure></div><p></p><h3>Defend Denmark</h3><p>Tras el &#233;xito de Defend Iceland, el modelo se est&#225; expandiendo a Dinamarca con <a href="https://defenddenmark.dk/">Defend Denmark</a>, liderado por <a href="https://www.linkedin.com/in/emil-h%C3%B8rning-8824641b4/">Emil H&#248;rning</a>. La plataforma lleva menos de un a&#241;o en funcionamiento, pero ya cuenta con una comunidad activa de hackers &#233;ticos.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!39wT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!39wT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 424w, https://substackcdn.com/image/fetch/$s_!39wT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 848w, https://substackcdn.com/image/fetch/$s_!39wT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!39wT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!39wT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png" width="1230" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1230,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Community Fund Flowchart showing the process from defenders reporting vulnerabilities to beneficiaries receiving payments&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Community Fund Flowchart showing the process from defenders reporting vulnerabilities to beneficiaries receiving payments" title="Community Fund Flowchart showing the process from defenders reporting vulnerabilities to beneficiaries receiving payments" srcset="https://substackcdn.com/image/fetch/$s_!39wT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 424w, https://substackcdn.com/image/fetch/$s_!39wT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 848w, https://substackcdn.com/image/fetch/$s_!39wT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!39wT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5f3680a-a1e2-46d4-af40-113af244f34e_1230x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><a href="https://defenddenmark.dk/community-fund">Defend Denmark</a></figcaption></figure></div><p>En definitiva, tanto Defend Iceland como Defend Denmark <strong>son ejemplos incre&#237;bles de c&#243;mo conectar a la comunidad de hackers y motivar a las empresas a contribuir a la seguridad digital de una naci&#243;n. </strong>Les deseamos el mejor de los &#233;xitos.<br><br><br>&#191;Crees que este modelo funcionar&#237;a con las empresas espa&#241;olas? &#191;Estar&#237;an dispuestas a <strong>contribuir un 10&#8239;% de los bounties al Community Fund</strong>?</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[¡Secur0 cumple su primer año como empresa!]]></title><description><![CDATA[Un a&#241;o de Hack 4 Bounty SL]]></description><link>https://newsletter.secur0.com/p/secur0-cumple-su-primer-ano-como</link><guid isPermaLink="false">https://newsletter.secur0.com/p/secur0-cumple-su-primer-ano-como</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Thu, 06 Nov 2025 08:28:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YzZ3!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61a37d4a-5107-4239-aca1-bc8bc78c1df1_512x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p></p><p>El 6 de noviembre de 2024, Secur0 se constituye bajo el nombre &#8220;HACK 4 BOUNTY, S.L&#8221; (despu&#233;s de que nos rechazar&#225;n 15 nombres desde el registro mercantil). Hace justo un a&#241;o empezamos esta locura con la idea de traer el bug bounty y crowdsourced pentesting a m&#225;s empresas espa&#241;olas y crear una comunidad de hackers &#233;ticos. </p><h3><br>Nuestro MVP</h3><p>No sab&#237;amos por d&#243;nde empezar, as&#237; que empezamos con una comunidad de Discord, 5 startups de impacto social, un formulario para reportar vulnerabilidades y 3 flippers zero para los estudiantes que m&#225;s vulnerabilidades reportar&#225;n. <br><br>Con esto, nos lanzamos el 29 de noviembre a dar una charla en el IES El Ca&#225;veral para los estudiantes del curso de especializaci&#243;n de ciberseguridad y fue todo un &#233;xito. Justo 2 meses despu&#233;s est&#225;bamos haciendo lo mismo en la Universidad de C&#225;diz, pero esta vez despu&#233;s de hacerlo en 26 centros antes, con 242 estudiantes en la comunidad y 80 vulnerabilidades reportadas en estas startups. Esta&nbsp;<a href="https://www.youtube.com/watch?v=s9gATBB0kog">charla</a>&nbsp;fue bastante especial porque la imparti&#243; Pedro Jos&#233; Navas, el estudiante que gan&#243; nuestra primera competici&#243;n con m&#225;s de 300 puntos en CVSS acumulado.</p><p></p><h3>Wayra, APTE, Madrid Emprende y la C&#225;mara de Comercio de Madrid</h3><p>Secur0 es nuestra primera empresa y hemos tenido que ir aprendiendo todo sobre la marcha. Pero sin Wayra, APTE y la C&#225;mara de Comercio de Madrid todo hubiera sido m&#225;s complicado, ya que durante diferentes programas o formaciones nos han apoyado y lo siguen haciendo donde m&#225;s lo necesitamos: legal y fiscal, ventas, marketing, operaciones&#8230;</p><p></p><h3>Formaci&#243;n junto de hacking y CTFs junto a INCIBE Emprende</h3><p>En marzo empezamos a dar formaci&#243;n de hacking &#233;tico y CTFs con IMMUNE Technology Institute y meses despu&#233;s har&#237;amos lo mismo con Wayra, El Club del Emprendimiento, Sherpa Tribe, Universidad de Salamanca... INCIBE Emprende</p><p>Ya llevamos m&#225;s de 200 talleres en 100 centros educativos distintos y es algo que nos hace mucha ilusi&#243;n, debido a que no solo estamos formando a los futuros hackers de nuestra red, sino que tambi&#233;n les estamos dando oportunidades con otras acciones como Hack Royale.</p><p></p><h3>Lanzamiento de la plataforma</h3><p>En agosto lanzamos la plataforma y desde entonces estamos creciendo un mont&#243;n:<br></p><ul><li><p>Hemos realizado alguna modalidad de hacking &#233;tico a 27 empresas</p></li><li><p>Encontrado 500+ vulnerabilidades</p></li><li><p>Tenemos 900+ hackers en la comunidad y 495 en la plataforma</p></li></ul><p></p><h3>Hack Royale</h3><p>Y septiembre m&#225;s de lo mismo:<br></p><ul><li><p>Hemos incorporado a 6 personas al equipo</p></li><li><p>Lanzado <a href="https://secur0.com/es/hack-royale">Hack Royale</a> nuestra competici&#243;n de hacking con 25.000&#8364; en premios</p></li><li><p>Cerrado un acuerdo con Chema Alonso para esta competici&#243;n</p></li></ul><h3><br>Futuro<br></h3><p>Tenemos 2 objetivos claros para lo que queda de a&#241;o y el 2026:</p><ul><li><p>Validar el modelo que ya tenemos validado en mediana empresa con grandes empresas espa&#241;olas</p></li><li><p>Y lo mismo con los partners, conseguir partners con grandes empresas que ya sabemos que nos ha funcionado con peque&#241;as consultoras</p></li></ul><p><br>Si crees que nos puedes ayudar con algo de esto o cualquier cosa, mi correo siempre est&#225; abierto</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:javier@secur0.com"><span>javier@secur0.com</span></a></p><p><br>Quer&#237;amos aprovechar para dar gracias a todas las personas y clientes que nos hab&#233;is ayudado en este a&#241;o y obviamente a los hackers por confiar en nosotros. </p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[¡Chema Alonso se une a Hack Royale!]]></title><description><![CDATA[Chema Alonso se une como padrino de la competici&#243;n]]></description><link>https://newsletter.secur0.com/p/chema-alonso-se-une-a-hack-royale</link><guid isPermaLink="false">https://newsletter.secur0.com/p/chema-alonso-se-une-a-hack-royale</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Wed, 01 Oct 2025 08:20:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JTFh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Hoy tenemos un notici&#243;n en Secur0, <strong>Chema Alonso se une como padrino de la competici&#243;n</strong> para potenciar e impulsar la visibilidad del trabajo de los hackers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JTFh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JTFh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 424w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 848w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 1272w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JTFh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png" width="728" height="419.6056338028169" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:532,&quot;width&quot;:923,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:373867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/174979536?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JTFh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 424w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 848w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 1272w, https://substackcdn.com/image/fetch/$s_!JTFh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81816448-7211-4d97-8b7a-8a7422b215f5_923x532.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><br>&#191;Qu&#233; significa esto para Hack Royale?</h3><p>Hack Royale es nuestra competici&#243;n en la que los futuros mejores hackers de Espa&#241;a se enfrentan por ganar 25.000&#8364;. Pero desde el inicio naci&#243; para ser mucho m&#225;s que una simple competici&#243;n. Nuestro objetivo es claro: potenciar el talento, ofrecer formaci&#243;n en entornos reales y generar un impacto social tangible. Con el apoyo de Chema vamos a darle todav&#237;a m&#225;s foco a estos pilares y crear m&#225;s oportunidades para nuestra comunidad hacker.<br></p><h3>La comunidad, en el centro</h3><p>Esto no va de Chema. No va de Secur0. Ni siquiera va solo de Hack Royale. Va de vosotros, nuestra comunidad de hackers.<br><br>Lo que buscamos con este movimiento es claro: daros m&#225;s oportunidades.</p><p>Con Chema Alonso como padrino, Hack Royale entra en una nueva fase. Esto es solo el principio.<br><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[El caso de Crowdfense]]></title><description><![CDATA[Reportar o vender, el dilema eterno de los investigadores]]></description><link>https://newsletter.secur0.com/p/el-caso-de-crowdfense</link><guid isPermaLink="false">https://newsletter.secur0.com/p/el-caso-de-crowdfense</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Tue, 02 Sep 2025 06:02:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!48fK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p><br>El reciente <a href="https://www.linkedin.com/posts/crowdfense_we-are-offering-350000-for-a-working-remote-activity-7366862199077761024-kRvt">anuncio</a> de Crowdfense sobre la recompensa de $350,000 por un RCE en la &#250;ltima versi&#243;n estable de NGINX ha vuelto a abrir el debate sobre el mercado de los Zero Days y los brokers. <br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!48fK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!48fK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 424w, https://substackcdn.com/image/fetch/$s_!48fK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 848w, https://substackcdn.com/image/fetch/$s_!48fK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 1272w, https://substackcdn.com/image/fetch/$s_!48fK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!48fK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png" width="591" height="599.3829787234042" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b713cec-5f61-485f-9227-065ef943691c_705x715.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:705,&quot;resizeWidth&quot;:591,&quot;bytes&quot;:73816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/172517479?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!48fK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 424w, https://substackcdn.com/image/fetch/$s_!48fK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 848w, https://substackcdn.com/image/fetch/$s_!48fK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 1272w, https://substackcdn.com/image/fetch/$s_!48fK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b713cec-5f61-485f-9227-065ef943691c_705x715.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><a href="https://www.vrh.crowdfense.com/bounties">Vulnerability Research Hub</a></figcaption></figure></div><p><br>Antes de ponernos al l&#237;o, hay que entender qu&#233; es un Zero Day y por qu&#233; vale tanto dinero.</p><h3><br><br>&#191;Qu&#233; es un Zero Day?</h3><p><a href="https://www.incibe.es/ciudadania/blog/que-es-una-vulnerabilidad-zero-day">Seg&#250;n INCIBE</a>, un Zero Day es un tipo de vulnerabilidad que acaba de ser descubierta y que a&#250;n no tiene un parche que la solucione. La principal amenaza reside en que, hasta que se lanza dicho parche correctivo y los usuarios lo instalan en sus equipos, los atacantes tienen v&#237;a libre para explotar la vulnerabilidad y sacar provecho del fallo de seguridad.</p><p></p><h3>&#191;Qu&#233; es Crowdfense y de d&#243;nde salen los $350,000?</h3><p>Crowdfense es la plataforma l&#237;der en la adquisici&#243;n de vulnerabilidades de d&#237;a cero. Ofrecen los pagos m&#225;s altos del sector, con recompensas que van desde 10.000 hasta 7 millones de d&#243;lares.</p><p>La respuesta de d&#243;nde sale este dinero es algo m&#225;s compleja, pero para resumir, los clientes de Crowdfense son principalmente clientes institucionales internacionales, incluidos <a href="http://Estas entidades utilizan los exploits adquiridos para recopilaci&#243;n de inteligencia, recopilaci&#243;n de informaci&#243;n e investigaciones, lo que justifica las elevadas recompensas ofrecidas por la plataforma.">gobiernos, agencias de inteligencia y fuerzas del orden, e integradores de sistemas</a>. Estas entidades utilizan los exploits adquiridos para&nbsp;<strong>la recopilaci&#243;n de inteligencia,&nbsp;la&nbsp;recopilaci&#243;n de informaci&#243;n e investigaciones</strong>.<br><br>Por esta raz&#243;n, las vulnerabilidades que m&#225;s se pagan son las de aplicaciones de mensajer&#237;a, debido a su enorme base de usuarios y el valor estrat&#233;gico de poder acceder a comunicaciones privadas:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.crowdfense.com/exploit-acquisition-program/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ocNV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 424w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 848w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 1272w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ocNV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png" width="662" height="198" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:198,&quot;width&quot;:662,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23657,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.crowdfense.com/exploit-acquisition-program/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/172517479?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ocNV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 424w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 848w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 1272w, https://substackcdn.com/image/fetch/$s_!ocNV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6c20682-f4e6-430c-867f-ab51d3beb838_662x198.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Exploit Acquisition Program</figcaption></figure></div><p></p><h3>Aqu&#237; llega el dilema, reportar al fabricante o vender al broker</h3><p>Siguiendo el caso de WhatsApp, el programa de Meta paga hasta $300,000 por las vulnerabilidades m&#225;s cr&#237;ticas. Sin embargo, esta cifra est&#225; muy por debajo de los 5 millones de d&#243;lares que ofrece Crowdfense por un exploit similar.<br><br>Este contraste refleja el dilema al que se enfrentan los investigadores: reportar la vulnerabilidad al fabricante y<strong> garantizar que se corrija</strong> <strong>para proteger a los usuarios</strong>, o venderla a un broker y <strong>obtener una recompensa mucho mayor</strong>, dejando la explotaci&#243;n en manos de clientes institucionales y gubernamentales. La decisi&#243;n implica no solo una cuesti&#243;n econ&#243;mica, sino tambi&#233;n consideraciones de &#233;tica, impacto en la seguridad y reputaci&#243;n profesional.</p><p><strong><br>&#191;Y t&#250; qu&#233; har&#237;as reportar al fabricante o vender al broker?<br></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Safe Harbor en Bug Bounty]]></title><description><![CDATA[Historia, est&#225;ndares y el compromiso de Secur0]]></description><link>https://newsletter.secur0.com/p/safe-harbor-en-bug-bounty</link><guid isPermaLink="false">https://newsletter.secur0.com/p/safe-harbor-en-bug-bounty</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Fri, 01 Aug 2025 21:49:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mzPB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Reportar una vulnerabilidad <strong>deber&#237;a</strong> ser algo sencillo. <br>Encuentras la vulnerabilidad, la documentas, la env&#237;as y la empresa te da las gracias.</p><p><br>Pero si llevas tiempo en esto, sabes que <strong>la mayor&#237;a de las veces ocurre justo lo contrario.</strong> Te ignoran, te cuestionan o incluso te amenazan con denunciarte, y una acci&#243;n de buena fe acaba convirti&#233;ndose en una situaci&#243;n hostil.  Aqu&#237; es donde entra en juego el Safe Harbor, o Puerto Seguro en espa&#241;ol. </p><p></p><h3>&#191;Qu&#233; es el Safe Harbor y por qu&#233; deber&#237;a importarte como hacker &#233;tico?</h3><p>En pocas palabras, Safe Harbor es un conjunto de <strong>compromisos y garant&#237;as que protegen a los investigadores</strong> que reportan vulnerabilidades de buena fe y siguiendo las pol&#237;ticas de la empresa en cuesti&#243;n.</p><p>No hay mejor forma de entender la importancia del Safe Harbor que viendo c&#243;mo la <strong>falta de protecci&#243;n puede acarrear problemas legales.</strong> En el <a href="https://github.com/disclose/research-threats">repositorio de amenazas legales a investigadores de seguridad</a> de disclose.io se documentan casos reales donde empresas han actuado de manera desproporcionada contra investigaciones realizadas de buena fe.<br><br>Estos son solo algunos ejemplos de las numerosas denuncias que sufren los investigadores de seguridad. No se trata de casos aislados, sino de una realidad que demuestra c&#243;mo la ausencia de un marco legal claro y protector <strong>pone en riesgo la seguridad jur&#237;dica de los investigadores</strong> y desincentiva la colaboraci&#243;n.</p><p></p><h3>Disclose.io</h3><p>Disclose.io nace como un proyecto independiente que busca estandarizar las buenas pr&#225;cticas de Safe Harbor para <strong>proteger la investigaci&#243;n en ciberseguridad</strong> realizada de buena fe.</p><p>Su objetivo es ofrecer recursos abiertos y gratuitos para ayudar a empresas y organizaciones a crear o mejorar sus programas de divulgaci&#243;n de vulnerabilidades. Tambi&#233;n promueve un sello reconocible que identifica a quienes participan en esta iniciativa global.<br><br>El proyecto es p&#250;blico y est&#225; en <a href="https://github.com/disclose">GitHub</a>, donde cualquiera puede consultarlo, adaptarlo o contribuir. Gracias a esta transparencia, disclose.io se ha convertido en un <strong>est&#225;ndar internacional en buenas pr&#225;cticas de divulgaci&#243;n responsable.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mzPB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mzPB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 424w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 848w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 1272w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mzPB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png" width="372" height="372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:372,&quot;bytes&quot;:18978,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/169878933?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mzPB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 424w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 848w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 1272w, https://substackcdn.com/image/fetch/$s_!mzPB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fead30824-95dd-449b-bf12-a1cbba760027_1667x1667.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>Nuestro compromiso con los hackers</h3><p>Desde Secur0 hemos adaptado el <a href="https://github.com/disclose/dioterms/blob/master/core-terms/bbp-core-terms-08-safe-harbor.md">est&#225;ndar</a> de disclose.io a la normativa espa&#241;ola y europea, reflejando as&#237; nuestro compromiso con ofrecer los <strong>est&#225;ndares m&#225;s altos de seguridad y protecci&#243;n a nuestra red de hackers &#233;ticos</strong>.</p><p>Nuestra versi&#243;n adaptada ha sido elaborada con el respaldo de asesor&#237;a legal especializada, garantizando su cumplimiento con la normativa espa&#241;ola y europea.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cy4h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cy4h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 424w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 848w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 1272w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cy4h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png" width="793" height="763" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:763,&quot;width&quot;:793,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171385,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/169878933?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cy4h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 424w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 848w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 1272w, https://substackcdn.com/image/fetch/$s_!Cy4h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33dfb8ea-4e7b-49c2-967f-1152a4051de2_793x763.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>M&#225;s all&#225; de disclose.io: ISO/IEC 29147 y 30111</h3><p>En Secur0 no solo nos basamos en disclose.io para proteger a nuestra comunidad de hackers &#233;ticos y clientes. Tambi&#233;n seguimos las normas ISO/IEC 29147 y 30111.</p><ul><li><p><a href="https://www.iso.org/standard/72311.html">ISO/IEC 29147</a>: Norma que establece requisitos y recomendaciones para los proveedores sobre la <strong>divulgaci&#243;n de vulnerabilidades</strong> en productos y servicios. </p></li><li><p><a href="https://www.iso.org/standard/69725.html">ISO/IEC 30111</a>: Norma que establece requisitos y recomendaciones sobre c&#243;mo <strong>procesar y remediar las vulnerabilidades</strong> potenciales notificadas en un producto o servicio.</p></li></ul><p></p><p>Si quieres estar al tanto del crecimiento de Secur0 y del bug bounty en Espa&#241;a, no olvides suscribirte a esta newsletter.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Una competición de hacking con propósito real]]></title><description><![CDATA[&#191;Por qu&#233; lanzamos Hack Royale I?]]></description><link>https://newsletter.secur0.com/p/una-competicion-de-hacking-con-proposito</link><guid isPermaLink="false">https://newsletter.secur0.com/p/una-competicion-de-hacking-con-proposito</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Wed, 02 Jul 2025 06:31:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Oa6t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>En Espa&#241;a hay cientos de personas con talento para la ciberseguridad, pero muy pocos espacios donde aprender practicando en condiciones reales, donde conectar con empresas que valoren ese talento o donde simplemente poder destacar sin tener que hacer CTFs o resolver retos dise&#241;ados m&#225;s para entretener que para formar.</p><p>Por eso nace <strong>Hack Royale I</strong>.<br>Una competici&#243;n diferente.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oa6t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oa6t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oa6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156551,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/167319677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oa6t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Oa6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10ab18d3-46b4-4b24-9fbb-b688ae79c27f_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hecha desde dentro del sector, con tres objetivos muy claros:</p><h3>Talento</h3><p>La competici&#243;n est&#225; totalmente enfocada en mejorar la empleabilidad de los participantes.</p><p>Conectando a los participantes con vacantes de empresas, otorgando un certificado por cada vulnerabilidad encontrada y finalizando en una feria de empleo presencial.</p><h3>Formaci&#243;n</h3><p>Aprende hackeando en entornos reales.</p><p>Nada de CTFs ni laboratorios vulnerables. Hackea a empresas reales, de forma legal.</p><h3>Impacto</h3><p>Hackea con prop&#243;sito social</p><p>No regales tu tiempo a gobiernos extranjeros o empresas multimillonarias que te pagan con camisetas o bebidas energ&#233;ticas.</p><p>En esta competici&#243;n estar&#225;s ayudando a mejorar la ciberseguridad de las startups, ONGs, fundaciones y proyectos open source espa&#241;oles que m&#225;s lo necesitan.</p><h3>&#191;C&#243;mo funciona?</h3><ul><li><p>Inicio: se abre la inscirpci&#243;n el 1 de septiembre de 2025.</p></li><li><p>Semifinales: los primeros 100 equipos pasan a la siguiente fase. Cada d&#237;a laboral se elimina un equipo.</p></li><li><p>Finalistas: los 15 mejores equipos llegan a la fase final en mayo.</p></li><li><p>Premios: 25.000 &#8364; a repartir entre los 5 primeros (10k, 6k, 4k, 3k, 2k).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D0uK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D0uK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D0uK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:218551,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/167319677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D0uK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D0uK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6945dd3a-48cf-455d-b1a5-ad9008a1b85f_1920x1080.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>&#191;Te interesa participar? &#161;&#218;nete a nuestra comunidad de Discord para no perderte nada!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://discord.com/invite/Tactyce2WA&quot;,&quot;text&quot;:&quot;Discord&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://discord.com/invite/Tactyce2WA"><span>Discord</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[¡España vuelve a ganar la Ambassador World Cup de Hackerone!]]></title><description><![CDATA[Por segundo a&#241;o consecutivo, el equipo espa&#241;ol gana la AWC.]]></description><link>https://newsletter.secur0.com/p/espana-vuelve-a-ganar-la-ambassador</link><guid isPermaLink="false">https://newsletter.secur0.com/p/espana-vuelve-a-ganar-la-ambassador</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Sun, 01 Jun 2025 21:52:32 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/32c4c773-6779-43b9-a034-6ac8405e693b_2000x1331.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Espa&#241;a lo ha vuelto a hacer. El equipo nacional se ha proclamado campe&#243;n por segundo a&#241;o consecutivo en la Ambassador World Cup organizada por HackerOne. </p><h3>&#191;Qu&#233; es la Ambassador World Cup?</h3><p>La Ambassador World Cup es una competici&#243;n por equipos, similar a la Copa Mundial de la FIFA, pero en el &#225;mbito de la ciberseguridad. En ella participan 42 equipos, cada uno representando a un pa&#237;s, que compiten para encontrar vulnerabilidades en los sistemas de las empresas participantes.<br><br>Este a&#241;o ha sido una edici&#243;n r&#233;cord:</p><ul><li><p>1 a&#241;o de preparaci&#243;n</p></li><li><p>42 equipos participantes</p></li><li><p>766 hackers involucrados</p></li><li><p>6 rondas intensas de competici&#243;n</p></li></ul><p>La competici&#243;n tuvo lugar del 6 al 9 de mayo en Dub&#225;i, uniendo a los mejores bug bounty hunters del mundo.  Durante esos d&#237;as, los hunters estuvieron reportando vulnerabilidades en entornos de empresas como Adobe, OKX, entre otras.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QpHd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QpHd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QpHd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:855061,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/164950594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QpHd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QpHd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28cd602b-f16a-4ed2-af3f-74f347ece27d_4096x4096.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Espa&#241;a obtuvo el primer puesto en la competici&#243;n, demostrando una vez m&#225;s el alto nivel y la calidad del talento en ciberseguridad que existe en el pa&#237;s. En el podio, Espa&#241;a fue seguida por Egipto, Grecia y Pa&#237;ses Bajos.<br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N0p4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N0p4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N0p4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg" width="1456" height="969" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:969,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1289349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/164950594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N0p4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N0p4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38827f0-1a43-4e7d-b7bf-376159f437ac_2000x1331.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><br>&#127466;&#127480; Talento nacional </h3><p>M&#225;s all&#225; del t&#237;tulo, esta victoria refleja el creciente ecosistema de hackers &#233;ticos que existe en nuestro pa&#237;s. Desde j&#243;venes talentos form&#225;ndose en plataformas de bug bounty, hasta profesionales que participan en sus ratos libres. </p><p>Lo que realmente destaca en Espa&#241;a no es solo el talento individual, sino la comunidad s&#243;lida y comprometida que han construido. Una comunidad que se mueve por el inter&#233;s de compartir conocimientos, colaborar y levantar el nivel de toda la industria. Ese esp&#237;ritu de colaboraci&#243;n es lo que impulsa sus &#233;xitos y asegura que el futuro de la ciberseguridad en Espa&#241;a sea cada vez m&#225;s prometedor.</p><div><hr></div><p>Si est&#225;s empezando en el mundo del bug bounty o ya llevas tiempo:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://discord.gg/Tactyce2WA&quot;,&quot;text&quot;:&quot;&#161;&#250;nete a nuestra comunidad en Discord!&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://discord.gg/Tactyce2WA"><span>&#161;&#250;nete a nuestra comunidad en Discord!</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[IA para el Bug Bounty]]></title><description><![CDATA[CAI la IA de Alias Robotics para Bug Bounty]]></description><link>https://newsletter.secur0.com/p/ia-para-el-bug-bounty</link><guid isPermaLink="false">https://newsletter.secur0.com/p/ia-para-el-bug-bounty</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Thu, 01 May 2025 21:58:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!afYG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Este mes no pod&#237;amos dedicar la newsletter de Secur0 a otro tema que no fuera la <strong>IA aplicada al bug bounty.</strong> Hace apenas tres semanas, Alias Robotics present&#243; <a href="https://github.com/aliasrobotics/cai">Cybersecurity AI (CAI)</a> una IA &#8220;lista&#8221; para el Bug Bounty. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!afYG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!afYG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 424w, https://substackcdn.com/image/fetch/$s_!afYG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 848w, https://substackcdn.com/image/fetch/$s_!afYG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 1272w, https://substackcdn.com/image/fetch/$s_!afYG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!afYG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png" width="1456" height="306" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:306,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:508471,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/162646034?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!afYG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 424w, https://substackcdn.com/image/fetch/$s_!afYG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 848w, https://substackcdn.com/image/fetch/$s_!afYG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 1272w, https://substackcdn.com/image/fetch/$s_!afYG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1a74cf2-b471-4026-86f1-57d88aae0d4c_1540x324.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p></p><h3><em>&#8220;En 2028, la mayor&#237;a de las acciones de ciberseguridad ser&#225;n aut&#243;nomas, con humanos teleoperando.&#8221;</em></h3><p>As&#237; empieza el <a href="https://arxiv.org/pdf/2504.06017">paper</a> de CAI, con una declaraci&#243;n ambiciosa&#8212;y para muchos, cuestionable&#8212; que ha provocado revuelo entre varios profesionales del bug bounty y pentesting con los que hemos hablado desde Secur0. Seg&#250;n <a href="https://www.linkedin.com/posts/endika-gil-uriarte_github-aliasroboticscai-cybersecurity-activity-7315727056334471169-8q2r?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAADbr2v4Bmcbk-k7nyHdnBj0gaZx5_Ls6GnM">esta</a> publicaci&#243;n en LinkedIn de Endika Gil Ugarte, CEO de Alias Robotics, esta predicci&#243;n se basa en estimaciones de Gartner. Sin embargo, el paper no proporciona datos concretos que respalden dicha afirmaci&#243;n.</p><p></p><h3>La importancia del Open Source</h3><p>CAI es la primera soluci&#243;n open source en un mercado marcado por el secretismo en torno a la eficacia real de estas IAs. A diferencia de soluciones closed source como <a href="https://xbow.com/">XBOW</a>, <a href="https://zeropath.com/">Zeropath</a>, <a href="https://copilot.bugbase.ai/">Pentest Copilot</a>, <a href="https://www.runsybil.com/">Runsybil</a>, <a href="https://www.zynap.com/">Zynap</a>, <a href="https://www.terra.security/">Terra</a> o <a href="https://staris.tech/">Staris</a>, que no permiten acceso al c&#243;digo y ofrecen poca transparencia sobre c&#243;mo funcionan, <strong>se agradece que desde Alias Robotics</strong> hayan decidido hacer a CAI de c&#243;digo abierto. Esto no solo hace que CAI siga mejorando por los cambios propuesto por la comunidad, sino que tambi&#233;n nos da la oportunidad de entender de verdad c&#243;mo funciona una IA dise&#241;ada para buscar vulnerabilidades.</p><p></p><h3>Principios &#233;ticos detr&#225;s de CAI</h3><p>Alias Robotics deja muy claro los dos principios &#233;ticos detr&#225;s de CAI, que son <strong>democratizar la IA de ciberseguridad y asegurar la transparencia en las capacidades de seguridad de la IA.</strong> Adem&#225;s, mencionan repetidamente en el paper que uno de sus objetivos es eliminar los &#8220;lock-in&#8220; impuestos por las plataformas de Bug Bounty m&#225;s dominantes como Hackerone o Bugcrowd, permitiendo que medianas y peque&#241;as empresas tengan acceso a una seguridad comparable a la que ofrecen estos programas.</p><p>Aunque actualmente est&#225;n muy lejos de conseguir este objetivo (y CAI chupe muchos tokens &#128521;), desde Secur0 compartimos esta misma visi&#243;n. Nos alegra ver que hay otras empresas trabajando en solucionar este problema desde otro enfoque completamente diferente.</p><h3><br>Europa vs Estados Unidos, 2,5M&#8364; vs 20M$</h3><p>El proyecto CAI ha recibido <a href="https://cordis.europa.eu/project/id/101161136/es">2,5 millones de euros del Consejo Europeo de Innovaci&#243;n</a> y el coste estimado del proyecto es de 3,5 millones, mientras que XBOW su competidor m&#225;s conocido ha levantado <a href="https://xbow.com/blog/xbow-seed-investment/">20 millones de d&#243;lares en una ronda liderada por Sequoia Capital.</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zJp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zJp7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 424w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 848w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 1272w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zJp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png" width="1456" height="949" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:949,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:319108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/162646034?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zJp7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 424w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 848w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 1272w, https://substackcdn.com/image/fetch/$s_!zJp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fd212f-3b9b-4dfd-bd54-e65cd8610de9_1693x1103.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>La diferencia actual entre ambas empresas es considerable, <strong>36 vulnerabilidades validadas en Hackerone por <a href="https://hackerone.com/xbow">XBOW</a> frente a 1 por <a href="https://hackerone.com/aliasroboticsbounties">CAI</a></strong>. Adem&#225;s, XBOW es totalmente privado, mientras que CAI es open-source.</p><h3><br>&#191;<strong>Interesados en la parte t&#233;cnica?</strong></h3><p>Desde Secur0 creemos que a&#250;n estamos lejos de ver una IA al nivel de un bug hunter. Dicho esto, estamos ilusionados de ver como mejora CAI, y ojal&#225; llegue a convertirse en una herramienta utilizada por miles de hunters y pentesters. Os animamos a probarla y formar vuestra propia opini&#243;n.</p><ul><li><p><a href="https://arxiv.org/pdf/2504.06017">Paper</a></p></li><li><p><a href="https://github.com/aliasrobotics/cai">Github</a></p></li><li><p><a href="https://discord.com/invite/fnUFcTaQAC">Discord de CAI</a> y ya que estamos <a href="https://discord.gg/Tactyce2WA">Discord de Secur0</a> &#128521;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hQ6_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hQ6_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 424w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 848w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 1272w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hQ6_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png" width="558" height="460" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:460,&quot;width&quot;:558,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30747,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.secur0.com/i/162646034?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hQ6_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 424w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 848w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 1272w, https://substackcdn.com/image/fetch/$s_!hQ6_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849c29f4-5e5f-491a-b43f-d5cde508433a_558x460.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>&#127466;&#127480; Innovaci&#243;n espa&#241;ola</h3><p>Si alguno no lo sabe, Alias Robotics es una empresa espa&#241;ola con sede en Vitoria,  y nos parece fundamental ense&#241;ar que <strong>en Espa&#241;a tambi&#233;n hay innovaci&#243;n en IA</strong>. Porque sino, luego nos pensamos que todo tiene que pasar en EE. UU. (adem&#225;s, as&#237; tienen algo que regular los 80 trabajadores de AESIA &#128521;). </p><p>Como comentamos antes, desde Secur0 nos alegra ver una empresa espa&#241;ola intentar solucionar los problemas actuales de las plataformas de Bug Bounty y apoyaremos en todo lo posible su desarrollo.</p><div><hr></div><p><strong>Me encantar&#237;a saber tu opini&#243;n sobre CAI y la IA aplicada al bug bounty en general. Te leo por correo.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:javier@secur0.com"><span>javier@secur0.com</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Bug Bounty en la Administración pública española]]></title><description><![CDATA[Programa de bug bounty de pago en la Agencia de Ciberseguridad de Catalunya]]></description><link>https://newsletter.secur0.com/p/bug-bounty-en-la-administracion-publica</link><guid isPermaLink="false">https://newsletter.secur0.com/p/bug-bounty-en-la-administracion-publica</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Tue, 01 Apr 2025 21:54:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YzZ3!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61a37d4a-5107-4239-aca1-bc8bc78c1df1_512x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Este art&#237;culo es un homenaje a la Agencia de Ciberseguridad de Catalunya (ACC) por todas sus iniciativas tan pioneras y sobre todo por impulsar el bug bounty en la administraci&#243;n p&#250;blica espa&#241;ola.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kRGN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kRGN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 424w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 848w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 1272w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kRGN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png" width="682" height="204.6" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:123,&quot;width&quot;:410,&quot;resizeWidth&quot;:682,&quot;bytes&quot;:6847,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://secur0.substack.com/i/160372861?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kRGN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 424w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 848w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 1272w, https://substackcdn.com/image/fetch/$s_!kRGN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262f3fed-2c27-4f0c-b857-707c2ff17226_410x123.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p></p><p>Si bien los programas de bug bounty son habituales en las empresas privadas, a&#250;n no son una pr&#225;ctica com&#250;n en el sector p&#250;blico. En 2016 tuvo lugar el primer programa de bug bounty del gobierno de EE.UU., <a href="https://hackthepentagon.mil/">"Hack the Pentagon"</a>, una iniciativa que result&#243; exitosa y que sigue activa hasta el d&#237;a de hoy. En la UE, los <strong>Pa&#237;ses Bajos han sido pioneros</strong> desde 2013, pero no fue hasta 2019, con el bug bounty <a href="https://commission.europa.eu/about/departments-and-executive-agencies/digital-services/eu-fossa-2-free-and-open-source-software-auditing_en">EU-FOSSA 2</a>, cuando la UE lanz&#243; un programa destinado a detectar errores en el software de c&#243;digo abierto utilizado por las instituciones europeas.</p><p>En Espa&#241;a, en diciembre de 2020, la ACC, junto con la Direcci&#243;n General de Atenci&#243;n Ciudadana, fueron pioneras en la puesta en marcha de una <strong>prueba piloto</strong> de bug bounty sobre un conjunto de activos de la Generalitat de Catalu&#241;a. Durante dos semanas, un n&#250;mero reducido de reconocidos profesionales de la ciberseguridad participaron de manera altruista mediante una invitaci&#243;n personal y exclusiva. </p><p>A partir de esta experiencia positiva, la Agencia ha incorporado el Bug Bounty como una herramienta para mejorar la seguridad de los sistemas de informaci&#243;n del sector p&#250;blico de Catalu&#241;a.</p><p></p><h3><strong>Licitaci&#243;n 2025 sobre Bug Bounty</strong></h3><p>El pasado 17 de marzo la ACC public&#243; el <a href="https://contractaciopublica.cat/ca/detall-publicacio/300400784">anuncio</a> en la &#8220;Plataforma de serveis de contractaci&#243; p&#250;blica (PSCP)&#8221;. <strong>Con un valor estimado del contrato de 140.000&#8364; +IVA</strong>, que se repartir&#225; de la siguiente manera:</p><p>50.000&#8364; para la <strong>plataforma</strong> adjudicataria del contrato</p><p>90.000&#8364; a repartir entre los <strong>hackers</strong> que encuentren las vulnerabilidades.<br></p><p>Os invito a leer el pliego de cl&#225;usulas administrativas (58 p&#225;ginas) y el pliego de prescripciones t&#233;cnicas (28 p&#225;ginas) porque tiene mucha chicha y tenemos la suerte de poder leerlo <a href="https://contractaciopublica.cat/ca/detall-publicacio/300400784">aqu&#237;</a>.</p><div><hr></div><p><strong>&#191;C&#243;mo ves t&#250; el futuro del bug bounty en la administraci&#243;n p&#250;blica espa&#241;ola?, me encantar&#237;a saber tu opini&#243;n, te leo por correo</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:javier@secur0.com"><span>javier@secur0.com</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[¿Deben existir los programas de divulgación de vulnerabilidades (VDP)?]]></title><description><![CDATA[S&#237; y no ...]]></description><link>https://newsletter.secur0.com/p/deben-existir-los-programas-de-divulgacion</link><guid isPermaLink="false">https://newsletter.secur0.com/p/deben-existir-los-programas-de-divulgacion</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Sat, 01 Mar 2025 21:48:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3x7L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>Antes de responder esta pregunta, es importante entender qu&#233; son los programas de divulgaci&#243;n de vulnerabilidades.</p><h3><strong>Nacen de la idea &#8220;see something, say something&#8221;.</strong></h3><p>Los VDPs, por sus siglas en ingl&#233;s &#8220;Vulnerability Disclosure Policies&#8221;, son programas establecidos por organizaciones para que investigadores, hackers &#233;ticos o cualquier persona interesada pueda reportar vulnerabilidades de seguridad de manera responsable, <strong>sin percibir compensaci&#243;n econ&#243;mica</strong>.<br><br>Pero&#8230; tienen muchos problemas, como cuando tienen el mismo alcance en programas de pago y VPDs, el ranking, tiempos de respuesta, pero, sin duda, el principal problema es el siguiente:</p><h3>Trabajo gratis para empresas que facturan millones.</h3><p>El principal problema de los programas de divulgaci&#243;n de vulnerabilidades es que empresas que facturan millonadas, se aprovechan del trabajo gratuito de expertos. Sin ir m&#225;s lejos a d&#237;a de hoy en Hackerone hay 209 VDPs y en Bugcrowd 187, donde los &#250;nicos que ganan dinero son las plataformas y las empresas por recibir bugs de manera gratuita.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3x7L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3x7L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 424w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 848w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 1272w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3x7L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png" width="600" height="363.6" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:303,&quot;width&quot;:500,&quot;resizeWidth&quot;:600,&quot;bytes&quot;:287326,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://secur0.substack.com/i/154079314?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3x7L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 424w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 848w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 1272w, https://substackcdn.com/image/fetch/$s_!3x7L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf74c908-c8ae-4e53-990a-cf9f65572b7f_500x303.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"> Alex Sotirov y Dino Dai Zovi </figcaption></figure></div><p><br>Un claro ejemplo de este problema es Red Bull, una empresa que en <a href="https://www.redbull.com/es-es/energydrink/empresa">2024 factur&#243; 11 227 mil millones de euros</a> y ha recibido un total de 8981 reportes. De ellos, ha <a href="https://app.intigriti.com/programs/redbull/redbull/detail">aceptado 2191</a>, es decir, han encontrado m&#225;s de 2.000 vulnerabilidades pagando solo con unas cuantas latas. Como Red Bull, hay un mont&#243;n de empresas que facturan millones y te pagan con merchandising (SWAG).<br></p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adb66d96-88e6-4141-baf5-22c950ad093b_373x394.png&quot;},{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e12310a-365d-4b9a-a891-f2e9f77a1d32_712x949.jpeg&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e39f9a0-7717-4eef-a28f-2f447511b5a2_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p><br></p><h3>Dicho esto, Secur0 tiene y tendr&#225; VDPs.</h3><p>Debido a que estamos centrados en la formaci&#243;n, creemos firmemente que los VDPs cumplen una funci&#243;n muy valiosa. Por ejemplo, permiten que un profesor de formaci&#243;n profesional o universitario ense&#241;e hacking en empresas reales y no solo en entornos simulados.</p><p><strong>Actualmente tenemos cinco programas de VDP con startups de impacto social</strong> que no pueden permitirse invertir en ciberseguridad. En estos programas, hay 300 hackers de 36 centros educativos buscando vulnerabilidades en estas startups.<br><br>A partir del 15 de mayo, vamos a mejorar nuestros VDPs y <strong>solo aceptaremos ONGs y proyectos 100% open source con </strong><em><strong>full disclosure</strong></em><strong>. </strong>Nuestro objetivo es que no deis vuestro tiempo gratis a empresas con &#225;nimo de lucro y que pod&#225;is divulgar sin restricciones una vez se haya solucionado la vulnerabilidad.<strong><br><br></strong>Desde el punto de la plataforma, no incentivaremos los VDPs con puntos y nunca haremos VDPs privados.</p><div><hr></div><p><strong>Tenemos claro que queremos mejorar los VDP actuales. &#191;Echas en falta algo en nuestra propuesta? Te leo por correo.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:javier@secur0.com"><span>javier@secur0.com</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[El boom del bug bounty]]></title><description><![CDATA[&#191;Cu&#225;l es el futuro del bug bounty?]]></description><link>https://newsletter.secur0.com/p/el-boom-del-bug-bounty</link><guid isPermaLink="false">https://newsletter.secur0.com/p/el-boom-del-bug-bounty</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Sat, 01 Feb 2025 22:40:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aJm5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>&#8220;El tama&#241;o del mercado mundial de plataformas Bug Bounty es de 1 520 millones de USD en 2024 y se espera que alcance los <strong>4 950 millones de USD en 2032</strong>, creciendo a una tasa de crecimiento anual compuesta (CAGR) de alrededor del 15,94%&#8221; (<a href="https://www.businessresearchinsights.com/market-reports/bug-bounty-platforms-market-102501">Business Research Insights, 2024</a>). <br><br>Business Research Insights atribuye su predicci&#243;n a que las organizaciones necesitan &#8220;probar regularmente su infraestructura inform&#225;tica&#8221;, dada la &#8220;constante evoluci&#243;n de su infrastructura&#8221; y el hecho de que &#8220;un hacker podr&#237;a destruir la reputaci&#243;n de una empresa en minutos&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aJm5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aJm5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 424w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 848w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 1272w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aJm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png" width="697" height="556" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:556,&quot;width&quot;:697,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58422,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aJm5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 424w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 848w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 1272w, https://substackcdn.com/image/fetch/$s_!aJm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51cbbae-1b0b-4af1-8411-7fe994d13d29_697x556.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Business Research Insights, 2024</figcaption></figure></div><p><br>Nosotros desde Secur0, pensamos que el mercado crecer&#225; por las siguientes tres razones:</p><h3>1. Aumento del n&#250;mero de ciberataques</h3><p>Como todos sabemos, los ciberataques no paran de crecer desde hace a&#241;os y 2024 no nos ha dejado indiferentes. <br><br>Se prev&#233; que el <strong>coste mundial de la ciberdelincuencia</strong> alcance los <a href="https://www.statista.com/chart/28878/expected-cost-of-cybercrime-until-2027/">10,29 billones de d&#243;lares anuales en 2025</a>. Si se midiera como un pa&#237;s, la ciberdelincuencia ser&#237;a la tercera mayor econom&#237;a del mundo despu&#233;s de Estados Unidos y China. </p><p>El <strong>coste medio mundial de una filtraci&#243;n de datos</strong> en 2024 fue de <a href="https://www.ibm.com/reports/data-breach">4,88 millones de d&#243;lares</a>, un 10 % m&#225;s que el a&#241;o pasado y el total m&#225;s alto de la historia.<br><br>El <strong>pago medio por un ransomware</strong> en 2024 es de <a href="https://www.sophos.com/en-us/press/press-releases/2024/04/ransomware-payments-increase-500-last-year-finds-sophos-state">2,73 millones de d&#243;lares</a>, casi un aumento de un mill&#243;n de d&#243;lares con respecto a 2023.</p><p><em>Podr&#237;a seguir llenando este art&#237;culo con cifras alarmantes, pero creo que todos entendemos la magnitud del problema.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iraF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iraF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iraF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iraF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iraF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iraF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:350782,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iraF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iraF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iraF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iraF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770c8fd1-b2ae-4604-95e3-a8e05f807912_1200x1200.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Statista, 202</figcaption></figure></div><h3><em><br>2. </em>Aumento de las superficies de ataque</h3><p>Es una realidad que las empresas cada vez tienen m&#225;s superficie de ataque y las dos principales razones son las siguientes:</p><ul><li><p>La <strong>transformaci&#243;n digital de las empresas</strong> avanza r&#225;pidamente, como lo demuestra el <a href="https://digital-strategy.ec.europa.eu/en/activities/funding-digital">Plan Financiero Multianual de la Uni&#243;n Europea 2021-2027</a>, que destina 7 600 millones de euros para impulsar la transformaci&#243;n digital de la sociedad, la econom&#237;a y las administraciones p&#250;blicas de sus Estados miembros.</p></li><li><p>El <strong>trabajo remoto no deja de crecer</strong>, seg&#250;n un <a href="https://www.statista.com/statistics/1450450/employees-remote-work-share/">estudio de Statista</a> el 28% de los empleados trabaja de manera remota o h&#237;brida, alcanzando el 67% en las empresas tecnol&#243;gicas. </p></li></ul><p> </p><h3>3. Aumento de las obligaciones de cumplimiento</h3><p>Los organismos reguladores, como NIST, ENISA y CISA, abogan por una pol&#237;tica de divulgaci&#243;n de vulnerabilidades obligatoria y recomiendan programas de bug bounty, conforme a las normas ISO 29147 e ISO 30111. Algunos ejemplos son:</p><ul><li><p>La <a href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act">CRA</a> exige que se apliquen pol&#237;ticas coordinadas de divulgaci&#243;n de vulnerabilidades (pol&#237;ticas CVD o VDP) para facilitar la notificaci&#243;n externa de vulnerabilidades.</p></li><li><p>La norma<a href="https://listings.pcisecuritystandards.org/documents/PCI-DSS-v4_0-LA.pdf"> PCI-DSS 4.0 / 6.3.1</a> recomienda los programas de bug bounty como una posible soluci&#243;n para evaluar las vulnerabilidades del software desarrollado internamente.</p></li></ul><p></p><h3>Tendencias del bug bounty</h3><ul><li><p>La querid&#237;sima <strong>inteligencia artifical </strong>sigue ganando terreno, no solo en el proceso de b&#250;squeda de vulnerabilidades, sino tambi&#233;n en la creaci&#243;n de programas de bug bounty. <a href="https://huntr.com/bounties">Huntr</a>, es la primera plataforma de bug bounty 100% enfocada en AI/ML, actualmente cuenta con m&#225;s de 240 programas de pago.</p></li><li><p>Por otro lado, el <strong>Hardware Hacking</strong> ha mostrado un crecimiento notable. Seg&#250;n el <a href="https://www.bugcrowd.com/blog/inside-the-mind-of-a-hacker-2024-edition/">informe de 2024 de BugCrowd</a>, el 81% de los hackers de hardware se encontraron con una nueva vulnerabilidad que nunca antes hab&#237;an visto en los &#250;ltimos 12 meses. Adem&#225;s, el 64% de ellos considera que actualmente existen m&#225;s vulnerabilidades en hardware que hace un a&#241;o.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4y8f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4y8f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4y8f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22910,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4y8f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!4y8f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc001be74-587b-415d-bf8d-4ab6b3bd9ee3_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Huntr</figcaption></figure></div><div><hr></div></li></ul><p><strong>Y t&#250;, &#191;c&#243;mo ves el futuro del bug bounty? Te leo por correo</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:javier@secur0.com"><span>javier@secur0.com</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscribirse&quot;,&quot;language&quot;:&quot;es&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Escribe tu correo electr&#243;nico..." tabindex="-1"><input type="submit" class="button primary" value="Suscribirse"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[El origen del bug bounty]]></title><description><![CDATA[&#8220;Get a bug if you find a bug&#8221;]]></description><link>https://newsletter.secur0.com/p/el-origen-del-bug-bounty</link><guid isPermaLink="false">https://newsletter.secur0.com/p/el-origen-del-bug-bounty</guid><dc:creator><![CDATA[Secur0]]></dc:creator><pubDate>Wed, 01 Jan 2025 21:35:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!b2FR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Suscr&#237;bete ahora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.secur0.com/subscribe?"><span>Suscr&#237;bete ahora</span></a></p><p>La newsletter &#8220;Secur0 - Bug Bounty con &#209;&#8221; surge como un homenaje a &#8220;Infosec - Ciberseguridad con &#209;&#8221;, creada por el gran Nacho Garc&#237;a Egea. <br><br>Esta newsletter mensual nace con un objetivo claro, <strong>mantenerte informado sobre todo lo relacionado con el bug bounty</strong>. Y qu&#233; mejor manera de arrancar que conociendo sus ra&#237;ces, explorando c&#243;mo naci&#243; el concepto de recompensar a los hackers &#233;ticos por encontrar vulnerabilidades.  </p><h3>1983, Get a bug if you find a bug</h3><p>El origen de los programas de bug bounty se remonta a 1983 , cuando una startup de Silicon Valley llamada Hunter &amp; Ready <strong>ofrec&#237;a un Volkswagen Beetle como recompensa</strong> a los investigadores que encontraran vulnerabilidades en su sistema operativo Versatile Real-Time Executive (VRTX).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b2FR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b2FR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b2FR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg" width="871" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:871,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:193355,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b2FR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b2FR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd02d196b-5441-46a4-b2c0-05f82618ae40_871x1200.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Anuncio de Hunter &amp; Ready</figcaption></figure></div><h3>1995, Netscape lanza el primer programa de bug bounty</h3><p>No obstante, el <a href="https://web.archive.org/web/19970501041756/www101.netscape.com/newsref/pr/newsrelease48.html">primer programa de Bug Bounty</a> moderno, tal y como lo conocemos hoy en d&#237;a,<strong> no surgi&#243; hasta 1995</strong>, cuando la compa&#241;ia Netscape decidi&#243; recompensar a cualquier investigador que reportara fallos sobre su navegador Netscape Navigator 2.0.</p><p>Matt Horner, Vicepresidente de marketing de Netscape, destac&#243; en su momento: "Al recompensar a los usuarios por identificar e informarnos r&#225;pidamente de los errores, este programa fomentar&#225; una revisi&#243;n amplia y abierta de Netscape Navigator 2.0 y nos ayudar&#225; a seguir creando productos de la m&#225;xima calidad."</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TmV7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TmV7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 424w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 848w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 1272w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TmV7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png" width="676" height="427.34269005847955" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1081,&quot;width&quot;:1710,&quot;resizeWidth&quot;:676,&quot;bytes&quot;:502453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TmV7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 424w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 848w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 1272w, https://substackcdn.com/image/fetch/$s_!TmV7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd375d71-9674-4211-9686-e67f0cd1bb9e_1710x1081.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Programa de bug bounty de Netscape</figcaption></figure></div><h3>2002, IDefense se convierte en intermediario de bug bounties</h3><p>Como el modelo de bug bounty de Netscape no consigui&#243; atraer a otros proveedores, la empresa de seguridad IDefense se convirti&#243; en el <a href="https://web.archive.org/web/20020812035333/www.idefense.com/contributor.html">primer intermediario de bug bounties</a>. Su programa &#8220;vulnerability contributor program&#8221; ofrec&#237;a a los investigadores hasta 400 d&#243;lares por informarles de vulnerabilidades en <strong>software de otras empresas</strong>. IDefense actuaba entonces como intermediario entre el investigador y los vendedores de software.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kf-B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kf-B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 424w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 848w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 1272w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kf-B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png" width="561" height="141" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:141,&quot;width&quot;:561,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20035,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Kf-B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 424w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 848w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 1272w, https://substackcdn.com/image/fetch/$s_!Kf-B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd38e086c-f28f-40d0-80f2-8ea388941bdc_561x141.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Tabla de pagos de IDefense</figcaption></figure></div><h3>2004, Mozilla Firefox bug bounty program</h3><p>En 2004, Mozilla Fundation implement&#243; su propio <a href="https://www.mozilla.org/en-US/security/bug-bounty/">programa de bug bounty</a> para su navegador Firefox, pagaban 500 d&#243;lares por vulnerabilidad tanto en la versi&#243;n estable como en las versiones beta. Incentivando a los investigadores a reportar fallos antes de que afectaran a un mayor n&#250;mero de usuarios. <strong>Este programa fue todo un &#233;xito debido a la gran comunidad de contribuidores open source con los que contaban. </strong><a href="https://blog.mozilla.org/press/2004/08/mozilla-foundation-announces-security-bug-bounty-program/">Aqu&#237;</a> puedes encontrar el anuncio oficial de este programa.</p><h3>2005 &#8212; Zero Day Initiative</h3><p>La Zero Day Initiative (ZDI) se cre&#243; para <strong>fomentar el reporte de vulnerabilidades de d&#237;a cero de forma privada a los proveedores afectados</strong>, recompensando econ&#243;micamente a los investigadores. En la actualidad, el ZDI es el <strong>programa de bug bounty independiente de proveedores m&#225;s grande del mundo.</strong> No revenden ni redistribuyen las vulnerabilidades adquiridas a trav&#233;s de ZDI. </p><h3>2010, Google bug hunters</h3><p>El bug bounty empieza a despegar con el lanzamiento del <a href="https://bughunters.google.com/">programa de bug bounty del gigante t&#233;cnol&#243;gico.</a> A principios del mismo a&#241;o, Google hab&#237;a lanzado un programa similar para el proyecto de c&#243;digo abierto Chromium. Debido a que fue todo un &#233;xito, este nuevo progrma inclu&#237;a toda las aplicaciones web de Google. Este programa sigue en marcha y <strong>han pagado un total de <a href="https://bughunters.google.com/about/key-stats">58.760.845 d&#243;lares</a> </strong>a 3672 hackers desde entonces, siendo el pago m&#225;s grande de <a href="https://security.googleblog.com/2023/02/vulnerability-reward-program-2022-year.html">605.000 d&#243;lares</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!awRN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!awRN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 424w, https://substackcdn.com/image/fetch/$s_!awRN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 848w, https://substackcdn.com/image/fetch/$s_!awRN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 1272w, https://substackcdn.com/image/fetch/$s_!awRN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!awRN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png" width="1456" height="764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:764,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55463,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!awRN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 424w, https://substackcdn.com/image/fetch/$s_!awRN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 848w, https://substackcdn.com/image/fetch/$s_!awRN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 1272w, https://substackcdn.com/image/fetch/$s_!awRN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd300e3be-d84f-49e4-bef5-c5139722f238_2400x1260.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>2011, Facebook whitehat program </h3><p>Facebook sigui&#243; los pasos de Google y lanz&#243; su propio <a href="https://bugbounty.meta.com/">programa whitehat</a>, con la particularidad de que no hab&#237;a limite en la cantidad m&#225;xima pagada por una vulnerabilidad. A d&#237;a de hoy el l&#237;mite es de 300.000 d&#243;lares para algunas ejecuciones remotas de c&#243;digo (RCE). Facebook se caracteriza por <strong>organizar eventos de hacking en vivo anualmente</strong> con los mejores hackers del programa.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0bdk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0bdk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 424w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 848w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 1272w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0bdk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png" width="680" height="221" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16583064-b3bc-4524-86c4-eb65ad862790_680x221.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:221,&quot;width&quot;:680,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47697,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0bdk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 424w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 848w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 1272w, https://substackcdn.com/image/fetch/$s_!0bdk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16583064-b3bc-4524-86c4-eb65ad862790_680x221.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>2012, Nace Hackerone</h3><p>Hackerone fue fundada en 2012 por los expertos en seguridad <a href="https://www.linkedin.com/in/jobertabma/">Jobert Abma</a>, <a href="https://www.linkedin.com/in/michiel3/">Michiel Prins</a>, <a href="https://www.linkedin.com/in/alexrice/">Alex Rice</a> y <a href="https://www.linkedin.com/in/merijnterheggen/">Merijn Terheggen</a>. <strong>Revolucionando la manera en la que se gestionan los programas de bug bounty</strong>, facilitando a las empresas a llegar a m&#225;s hackers y reduciendo la complejidad de gesti&#243;n, haciendo el triaje de las vulnerabilidades y gestionando los pagos, entre otras muchas cosas. </p><p>A partir de este momento, plataformas como Bugcrowd, Intigriti, YesWeHack y <strong>Secur0</strong> &#128521; surgieron, convirti&#233;ndose en la opci&#243;n m&#225;s com&#250;n para las empresas que tienen programas de bug bounty. Hoy en d&#237;a, <strong>son pocas las compa&#241;&#237;as que optan por gestionar sus programas de bug bounty de manera independiente</strong>, ya que estas plataformas ofrecen soluciones m&#225;s completas y especializadas.</p><h3>Futuro del bug bounty</h3><p>El futuro del bug bounty est&#225; lleno de posibilidades, con cada vez m&#225;s empresas adoptando este modelo. En la edici&#243;n de la newsletter del mes que viene indagaremos en como vemos el futuro del bug bounty desde Secur0. <strong>Pero antes, quiero saber como te gustar&#237;a que fuera el futuro de bug bounty.</strong><br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:javier@secur0.com&quot;,&quot;text&quot;:&quot;M&#225;ndame un mail a javier@secur0.com&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="mailto:javier@secur0.com"><span>M&#225;ndame un mail a javier@secur0.com</span></a></p><p><br><strong>&#191;Qu&#233; crees que debe mejorar en la industria del bug bounty? &#191;C&#243;mo imaginas el futuro de los programas y plataformas? Escr&#237;beme, contestar&#233; a todos los correos.</strong></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.secur0.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Gracias por leer Secur0 - Bug Bounty con &#209;. Suscr&#237;bete gratis para estar al tanto de la actualidad del bug bounty.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>