{"id":8542,"date":"2024-01-19T11:58:52","date_gmt":"2024-01-19T11:58:52","guid":{"rendered":"https:\/\/www.satup.xyz\/index.php\/2024\/01\/19\/adobe-recap-2023-ambassador-world-cup-final-four-by-chris-parkerson-dec-2023\/"},"modified":"2024-01-19T11:58:52","modified_gmt":"2024-01-19T11:58:52","slug":"adobe-recap-2023-ambassador-world-cup-final-four-by-chris-parkerson-dec-2023","status":"publish","type":"post","link":"https:\/\/www.satup.xyz\/index.php\/2024\/01\/19\/adobe-recap-2023-ambassador-world-cup-final-four-by-chris-parkerson-dec-2023\/","title":{"rendered":"Adobe Recap: 2023 Ambassador World Cup Final Four | by Chris Parkerson | Dec, 2023"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div>\n<h2 id=\"15be\" class=\"pw-subtitle-paragraph ho gq gr be b hp hq hr hs ht hu hv hw hx hy hz ia ib ic id cp dt\">Author: <a class=\"af ie\" href=\"https:\/\/www.linkedin.com\/in\/venturadaniel42\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Daniel Ventura<\/a>, Manager, Product Security Incident Response Team (PSIRT) and Bug Bounty Program<\/h2>\n<div class=\"if ig ih ii ij\">\n<div class=\"speechify-ignore ab co\">\n<div class=\"speechify-ignore bg l\">\n<div class=\"ik il im in io ab\">\n<div>\n<div class=\"ab ip\"><a href=\"https:\/\/medium.com\/@cparkers?source=post_page-----df701e1a1b12--------------------------------\" rel=\"noopener follow\"><\/p>\n<div>\n<div class=\"bl\" aria-hidden=\"false\">\n<div class=\"l iq ir bx is it\">\n<div class=\"l fg\"><img loading=\"lazy\" decoding=\"async\" alt=\"Chris Parkerson\" class=\"l fa bx dc dd cw\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:88:88\/1*_lCXy09QTCyvOoXLCN75DA.jpeg\" width=\"44\" height=\"44\" loading=\"lazy\" data-testid=\"authorPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><a href=\"https:\/\/blog.developer.adobe.com\/?source=post_page-----df701e1a1b12--------------------------------\" rel=\"noopener  ugc nofollow\"><\/p>\n<div class=\"iw ab fg\">\n<div>\n<div class=\"bl\" aria-hidden=\"false\">\n<div class=\"l ix iy bx is iz\">\n<div class=\"l fg\"><img loading=\"lazy\" decoding=\"async\" alt=\"Adobe Tech Blog\" class=\"l fa bx bq ja cw\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:48:48\/1*riyFijvwTfGcWNf1guRNtg.png\" width=\"24\" height=\"24\" loading=\"lazy\" data-testid=\"publicationPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure class=\"nq nr ns nt nu nv nn no paragraph-image\">\n<div role=\"button\" tabindex=\"0\" class=\"nw nx fg ny bg nz\">\n<div class=\"nn no np\"><picture><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/format:webp\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\" type=\"image\/webp\"\/><source data-testid=\"og\" srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/1*jf3X3SeEbNeM3tsfr4zsUA.jpeg 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\"\/><img fetchpriority=\"high\" alt=\"\" class=\"bg mv oa c\" width=\"700\" height=\"379\" loading=\"eager\" role=\"presentation\"\/><\/picture><\/div>\n<\/div>\n<\/figure>\n<p id=\"e0a5\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">Adobe has long focused on establishing a strong foundation of cybersecurity, built on a culture of collaboration, enabled by talented professionals, strong partnerships, leading edge capabilities,<strong class=\"od gs\"><em class=\"ox\"> <\/em><\/strong>and deep engineering prowess. We have been an active participant in the security community for many years, engaging with partners, standards organizations, and security researchers to collectively enhance the security of our products.<\/p>\n<p id=\"537f\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">We recognize the security community as a force multiplier in our quest to provide a safe and secure experience for Adobe\u2019s customers. Adobe\u2019s Vulnerability Disclosure Program (VDP) and Bug Bounty Program leverage the large community of hackers to collaborate and strengthen protections for Adobe products. Additionally, we work with external security researchers through our private Bug Bounty Program, <a class=\"af ie\" rel=\"noopener ugc nofollow\" target=\"_blank\" href=\"https:\/\/blog.developer.adobe.com\/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b\">Adobe-VIP<\/a>, to responsibly disclose vulnerabilities found in our products.<\/p>\n<p id=\"30fa\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">Last month, Adobe participated in the <a class=\"af ie\" href=\"https:\/\/www.hackerone.com\/lhe\/awc-final-round-2023\" rel=\"noopener ugc nofollow\" target=\"_blank\">Final Round<\/a> of the 2023 Ambassador World Cup (AWC). This live hacking event, hosted by HackerOne, consists of an eight-month-long, competition-driven way to build community engagement, collaboration, and ambassador brand awareness throughout the hacker community. The AWC, led by <a class=\"af ie\" href=\"https:\/\/www.hackerone.com\/hackers\/brand-ambassador-program\" rel=\"noopener ugc nofollow\" target=\"_blank\">HackerOne Brand Ambassadors<\/a>, allows teams of hackers worldwide to identify impactful vulnerabilities in participating customer programs, including this year\u2019s participants Adobe, A.S. Watson, Epic Games, Mercado Libre, MetaMask, OpenSea, Shopify, Stripe, TikTok, Tinder, and Yahoo.<\/p>\n<p id=\"ce73\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">In each round, participating customer programs receive an increase in new, fresh hacker engagement to drive high-signal traffic to the program\u2019s approved scope. The benefits include dedicated focus on programs from the best hackers in the world, designed to extend attack resistance measures. This event also provided an opportunity to become more ingrained with the global community, create essential partnerships, and build new connections that continue beyond the competition.<\/p>\n<p id=\"106d\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">The AWC started out with 29 teams and 677 hackers from 22 different countries. Entering the Final Round, 580 hackers across 25 teams were eliminated. The Final Four consisted of 97 remaining masterful hackers,<strong class=\"od gs\"> <\/strong>representing the countries of France, Israel, Nepal, and Spain.<\/p>\n<p id=\"c6a0\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">The following Adobe products participated in the competition:<\/p>\n<ul class=\"\">\n<li id=\"f261\" class=\"ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow oy oz pa bj\">Adobe Commerce<\/li>\n<li id=\"0fa1\" class=\"ob oc gr od b hp pb of og hs pc oi oj ok pd om on oo pe oq or os pf ou ov ow oy oz pa bj\">Photoshop Web<\/li>\n<li id=\"00d0\" class=\"ob oc gr od b hp pb of og hs pc oi oj ok pd om on oo pe oq or os pf ou ov ow oy oz pa bj\">Lightroom Web<\/li>\n<li id=\"9d01\" class=\"ob oc gr od b hp pb of og hs pc oi oj ok pd om on oo pe oq or os pf ou ov ow oy oz pa bj\">Identity Management System (IMS)<\/li>\n<li id=\"32c3\" class=\"ob oc gr od b hp pb of og hs pc oi oj ok pd om on oo pe oq or os pf ou ov ow oy oz pa bj\">Adobe Firefly<\/li>\n<li id=\"f2b2\" class=\"ob oc gr od b hp pb of og hs pc oi oj ok pd om on oo pe oq or os pf ou ov ow oy oz pa bj\">Acrobat Sign<\/li>\n<\/ul>\n<p id=\"8ffd\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">The event was a great success with Adobe receiving over 200 vulnerabilities from over 80 world-class hackers helping us to proactively harden our products. The feedback we received from the community was overwhelmingly positive, due to our programs\u2019 broad scope, transparency, and inclusive engagement with hackers. We received invaluable input from our interactions with the hackers. Not only with the typical interactions, but also their feedback on what makes a bug bounty program great. For example, what incentivizes them to work in a particular company\u2019s program, do they prefer to work alone or in groups, any pet peeves when bug hunting\u2026 etc. We\u2019re looking forward to continuing our collaboration next year.<\/p>\n<p id=\"a94f\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\"><strong class=\"od gs\">Hear from our Top Hackers<\/strong><\/p>\n<p id=\"fc95\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">We had the opportunity to collaborate with some of the brightest from the hacker community. Here\u2019s a snapshot of some of the highlights:<\/p>\n<blockquote class=\"pg ph pi\">\n<p id=\"12ff\" class=\"ob oc ox od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">The France team decided to work on Adobe\u2019s program as we felt this was where the most interesting targets would be. Communication was smooth and response times were fast. Great experience! It was cool having privileged access to Adobe products for the testing. I hope Adobe had as much fun as we had, and that all our work will bring them good value \u2014 after all, that\u2019s the sense of the collaboration that bug bounty programs should bring.<\/p>\n<\/blockquote>\n<p id=\"b1a4\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">\u2013 <a class=\"af ie\" href=\"https:\/\/www.hackerone.com\/hackerone-community-blog\/ambassador-spotlight-awc-edition-blaklis\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"od gs\">Blaklis, Team France<\/strong><\/a><strong class=\"od gs\">, #49 bounty hunter on HackerOne\u2019s Platform<\/strong><\/p>\n<blockquote class=\"pg ph pi\">\n<p id=\"5d10\" class=\"ob oc ox od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">By far, it has been the most professional team we have had in this edition of the Ambassadors World Cup 2023. Adobe\u2019s team was super responsive during the event making sure to answer questions and provide documentation and feedback to all the researchers. We would also like to highlight their transparency during the resolution of the reports, quickly making triages and paying all while clearly communicating their goals and what they expected from us. This has helped us improve our overall performance by boosting our motivation. We look forward to working with Adobe\u2019s bug bounty team in future events and will certainly be happy to continue participating in their program.<\/p>\n<\/blockquote>\n<p id=\"a5cb\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\"><strong class=\"od gs\">\u2013 <\/strong><a class=\"af ie\" href=\"https:\/\/hackerone.com\/djurado?type=user\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"od gs\">Djurado, Team Spain<\/strong><\/a><strong class=\"od gs\">, #45 bounty hunter on HackerOne\u2019s platform<\/strong><\/p>\n<blockquote class=\"pg ph pi\">\n<p id=\"db1d\" class=\"ob oc ox od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">It\u2019s rare to see mature Bug Bounty programs able to offer above market standards bounty, acknowledge submissions very quickly, and paying bounties right within validation. Combining these factors with the fact that we also received positive feedback and appreciation for what we\u2019ve found really pushed us forward to go deeper and find more impactful bugs within the program. We look forward to continuing work on Adobe\u2019s program, even after the AWC event.<\/p>\n<\/blockquote>\n<p id=\"5a68\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\"><strong class=\"od gs\">\u2013 <\/strong><a class=\"af ie\" href=\"https:\/\/hackerone.com\/nagli?type=user\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"od gs\">Nagli, Team Israel<\/strong><\/a><strong class=\"od gs\">, #6 bounty hunter on HackerOne\u2019s platform<\/strong><\/p>\n<blockquote class=\"pg ph pi\">\n<p id=\"56fd\" class=\"ob oc ox od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">Team Nepal had one of the best experiences working with Adobe Bug Bounty in the AWC-2023. With a complex scope that included custom configurations, different setups, and various credentials, Adobe managed to fulfill all the hackers\u2019 requests and queries surrounding it. The best thing about the Adobe Bug Bounty Program was the fast triage and rewards. It worked as a motivating factor for the team to hack even more on Adobe resulting in more and cooler bugs. Looking forward to seeing Adobe on the upcoming AWC-2024 as well.<\/p>\n<\/blockquote>\n<p id=\"0def\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\"><strong class=\"od gs\">\u2013 <\/strong><a class=\"af ie\" href=\"https:\/\/hackerone.com\/dhakal_ananda\/?type=user\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"od gs\">dhakal_ananda, Team Nepal<\/strong><\/a><strong class=\"od gs\">, #62 bounty hunter on HackerOne\u2019s platform<\/strong><\/p>\n<p id=\"8688\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">We\u2019d like to thank HackerOne for organizing such an incredible event for companies to engage with the global hacker community. As we move into the new year, our team eagerly looks forward to creating deeper connections within the community by continuing to invest in hacker-driven events and providing more opportunities to help us protect Adobe and our products.<\/p>\n<p id=\"bad7\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\"><strong class=\"od gs\">Join Adobe-VIP<\/strong><\/p>\n<p id=\"4d5c\" class=\"pw-post-body-paragraph ob oc gr od b hp oe of og hs oh oi oj ok ol om on oo op oq or os ot ou ov ow gk bj\">If you are ready to join the Hall of Fame initiative and level-up your skills in security research, we invite you to <a class=\"af ie\" href=\"https:\/\/survey.adobe.com\/jfe\/form\/SV_etgMr1R0BUZg86y\" rel=\"noopener ugc nofollow\" target=\"_blank\">apply for the Adobe-VIP program<\/a>. As a member of Adobe-VIP, you\u2019ll have the opportunity to work closely with our world-class team of security experts to help safeguard the digital experiences of millions of people around the globe, and on a much wider set of products than in our public program.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/blog.developer.adobe.com\/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12?source=rss----9342990108af---4\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Author: Daniel Ventura, Manager, Product Security Incident Response Team (PSIRT) and Bug Bounty Program Adobe has long focused on establishing a strong foundation of cybersecurity, built on a culture of collaboration, enabled by talented professionals, strong partnerships, leading edge capabilities, and deep engineering prowess. We have been an active participant in the security community for [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8543,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19],"tags":[],"class_list":["post-8542","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-graphics-design"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=8542"}],"version-history":[{"count":0,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8542\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media\/8543"}],"wp:attachment":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=8542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=8542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=8542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}