Google AI
The Times Australia

Times Media Advertising

Lazada and YesWeHack Strengthen Long-term Partnership by jointly hosting a live Bug Bounty event at HITBSecCONF2022 Singapore

Since launching their first private bug bounty program in 2020, the initiative has expanded into a two-day live hacking event focused on protecting Lazada’s consumer data

SINGAPORE - Media OutReach - 8 September 2022 - Southeast Asia's leading eCommerce platform Lazada has concluded its latest live bug bounty with YesWeHack, a leading global Bug Bounty and Vulnerability Disclosure Policy (VDP) Platform.

The two-day live bug bounty program, which was held at the Hack In The Box Security Conference (HITBSecCONF 2022), resulted in 115 vulnerability reports being submitted by the several dozen researchers present at the event, including some of the best security researchers in the world.

After running a successful two-year Bug Bounty program with YesWeHack, Lazada scaled the program to the next level this year during the HITBSecCONF 2022. The event allowed Lazada to test their applications over the given period of time, while being able to meet with researchers to exchange on the discoveries—thus giving Lazada deep and exclusive insights to the vulnerabilities found.

Lazada wanted to use this live event as an opportunity to achieve in-depth security. To enable this, the company voluntarily disabled a number of security mechanisms for participating researchers and only for the period of the event, allowing them to extensively test the systems and applications. For instance, researchers were able to bypass Web Application Firewalls (WAF) throughout the length of the event—allowing them to hack into the eCommerce platform's sites and services directly. Lazada had chosen to disable WAFs for the hunters, due to the fact that while they are able to block most of the attack, they are not infallible. In addition to WAFs, Lazada also disabled other security solutions that are typically used as a first line of defense, so as to offer hackers the chance to test their application in greater depth.

"Accomplishing a live program on this scale demonstrates Lazada's commitment to security and progressive stance towards bug bounties. By engaging with the broader community, the eCommerce giant is placing an unprecedented level of trust in ethical hackers to better strengthen their security, transparency, as well as data privacy and protection. We are delighted to be able to contribute to yet another successful collaboration with Lazada," said Kevin Gallerin, CEO APAC, YesWeHack.

"Securing customer's data and protecting it from any future incidences is of highest importance at Lazada. Having some of the best security researchers in the world in the same room as us is an exceptional opportunity to learn and exchange—especially for our red team, who mounts deliberate attacks on our systems daily to identify and fix vulnerabilities," said Bruno Demarche, who leads the Red Team & Security Testing Team at Lazada Group.

"The live bug bounty program was a rewarding experience for Lazada and YesWeHack alike. The teams have been able to uncover quality results, which has already given us ideas on how we can improve our internal testing processes for our application and services to ultimately better safeguard Lazada's customers and partners," said Yuezhong Bao, Head of Cybersecurity, Lazada Group.

Lazada's partnership with YesWeHack began in January 2020 with a successful 18-month private bug bounty program. The partners then continued to expand the scopes of their collaboration, and Lazada opened its program to the public in 2021, with rewards of up to US$10,000 per bounty. Since then, the company has been working with over 45,000 ethical hackers to detect flaws within their application and systems to achieve maximum security and protection over their platforms.

The collaboration with Lazada has also allowed YesWeHack to further advance its community of cybersecurity experts and position the company as the leading player of bug bounties in Asia Pacific. Since 2019, YesWeHack has served more than 60 clients from its Asia Pacific headquarters in Singapore, including large BFSIs, tech unicorns and government bodies. With a growing market demand being seen for the crowdsourced security model, 40 percent of YesWeHack's security researchers are based out of Asia, with 30 percent of its clientele coming from Australia, China, Indonesia, Malaysia, and Singapore.


Hashtag: #YesWeHack

About Lazada

Lazada Group is Southeast Asia's pioneer eCommerce platform. For the last 10 years, Lazada has been accelerating progress in Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam through commerce and technology. Today, a thriving local ecosystem links about 160 million active users to more than one million actively-selling sellers every month, who are transacting safely and securely via trusted payments channels and Lazada Wallet, receiving parcels through a homegrown logistics network that has become the largest in the region.

With a vision to achieve USD100 billion annual GMV, Lazada aims to serve 300 million shoppers by 2030, and be the best at enabling brands and sellers in digitalizing their businesses.

In 2022, the Lazada Foundation was set up to empower youths and women for the digital future, close the gender digital divide and uplifting communities by creating positive impact. More information can be found here .

About YesWeHack

Founded in 2015, YesWeHack is a global Bug Bounty and VDP Platform. YesWeHack offers companies an innovative approach to cybersecurity with Bug Bounty (pay-per-vulnerability discovered), connecting more than 40,000 cybersecurity experts (ethical hackers) across 170 countries with organisations to secure their exposed scopes and reporting vulnerabilities in their websites, mobile apps, infrastructure and connected devices.

YesWeHack runs private (invitation based only) programs and public programs for hundreds of organisations worldwide in compliance with the strictest European regulations.

In addition to the Bug Bounty platform, YesWeHack also offers: a creation and management solution for Vulnerability Disclosure Policy (VDP), a Pentest Management Platform, a learning platform for ethical hackers called Dojo and a training platform for educational institutions, YesWeHackEDU.


Read more: Lazada and YesWeHack Strengthen Long-term Partnership by jointly hosting a live Bug Bounty event at...

More Articles …

  1. The first AXA Medical Centre officially unveils
  2. OPPO Collaborates with Artist Julian Stanczak to Provide Aquamorphic Wallpaper in ColorOS 13
  3. PetaRush Demo Version Gameplay Announced. Reveal the Blind Box for Free and Run in the Game as NFT Animal Characters
  4. Redress Design Award 2022 winner of Timberland prize announced amid mounting urgency faced by global sustainable fashion practices
  5. Avone Beauty Secrets’s First-Ever Non-Invasive Henna Brows Artistry Received 3 Awards By Daily Vanity
  6. NannyStreet Launches New Mobile App To Simplify The Confinement Nanny Hiring Process For Parents
  7. FastLane Group Launched Partnership Program to Connect Different Cloud Solution and Services Providers
  8. Cellini Ranked No. 1 for Customer Service in the Premium Furniture Retail Sector in Singapore
  9. Resorts World Sentosa to recognise the world’s greatest wines at the second edition of Wine Pinnacle Awards with a specially curated programme and new awards categories
  10. Hong Kong James Dyson Award winning design offers personalized vision care and easy eye physiotherapy at home
  11. Over Half of Global Firms’ Supply Chains Compromised by Ransomware
  12. First Anniversary of the Qianhai Plan, Shenzhen-Hong Kong Collaboration Has Much Deepened
  13. Prudential launches mobile app to provide SME employees with easy access to medical and company benefits
  14. Chinachem Group Confirms with Helical The Purchase of a London Office Building at £158.5 million
  15. Hong Kong Life’s Family Care Dread Disease Protection Plan safeguards your family by extending Cancer Benefit to your loved ones
  16. Local Start-Up Wada Bento Achieved a Fresh Round of Funding Accumulated More Than HK$22 Million
  17. KOL LIVE Announced HK$500,000 Base Salary Scheme
  18. CP Foods Thailand’s CP, MEAT ZERO and Benja Chicken Products Win at Superior Taste Award 2022, Which Is Hosted by the Prestigious International Institute of Taste
  19. OKAY.com celebrates 10 years of Transforming Hong Kong’s Luxury Real Estate Sector
  20. InnoBlock Technology Builds Hong Kong’s First ESG Data Platform on AWS
  21. Opening doors to a sustainable future with Microsoft’s Circular Center in Singapore
  22. Trading Forex safely: the ultimate checklist for choosing a Forex broker in Malaysia
  23. Udokan Copper and RusHydro sign cooperation agreement on sustainable development
  24. Positive Cambodia Retail Outlook: Prince Real Estate Group’s Proactive Moves to Stimulate the Retail Market
  25. Chuo Spring Leverages Infor ERP to Drive Further Business Efficiencies and Standardization in Overseas Operations
  26. Bybit Next Level 2022 — Becoming the ‘Crypto Ark’ of the World
  27. Citi Appoints Vicky Kong as Consumer Business Manager for Hong Kong
  28. Give your child a safe break from school this September holidays with Arlo
  29. 2023 MDRT Executive Committee Delivers Expanded Member Resources for a Post-Pandemic World
  30. Nestlé showcases Harvest Gourmet, a versatile range of plant-based tasty goodness specially curated to suit the Asian palate at FHA 2022 with the focus on expanding its local and export markets
  31. Singapore hits three-year-high for H1 fintech funding at US$2.14 billion but scores smaller total deal value compared to H2’21: KPMG Pulse of Fintech report
  32. KPMG to launch Singapore’s first Embedded Finance Hub
  33. TRON GameFi WIN NFT HERO Mystery Box will be officially launched at Binance NFT Marketplace on September 8
  34. Guaranteeing long-term smoothness with the tech-innovative Dynamic Computing Engine in OPPO ColorOS 13
  35. Bybit Partners With SignalPlus in an Industry-First Partnership
  36. Bybit Launchpad 2.0 to Diamond Launch Coin (DLC) IEO
  37. Sunlight Real Estate Investment Trust ("Sunlight REIT") Final Results for the Year Ended 30 June 2022
  38. Less than 50% of asthma patients feel their condition is well managed, Economist Impact study finds
  39. Sapphire Technologies to Generate Electricity Using Waste Energy at Liquefied Natural Gas Terminal in Japan
  40. RockFlow Launching "Baby Bull & Baby Bear", Making Options Trading Simpler
  41. More SHIOK With a New Twist! 7-Eleven Refines Recipes of 9 Fan-Favourite 7-SELECT Ready to Eat Meals
  42. Hang Lung Debuts "Hang Lung Future Women Leaders Program" in Hong Kong and Shanghai to Empower Young Female Talent in Collaboration with the HKFYG Leadership Institute and Women's Federation
  43. An Ultraman figure event presented by TAMASHII NATIONS Starting from Bangkok, Thailand to multiple cities in South East Asia! 『ULTRA HEROES TOUR SOUTH EAST ASIA』
  44. "Colorectal Medical Education Encyclopedia" publishes article to explain how sphincter saving surgery make preservation of the anus in rectal cancer patients possible
  45. Aftermeats Launches One of the Most Nutritional and Convenient Vegan Meat Alternative
  46. NEFIN Group Partners With E-Mobility Start-Up Oyika To Accelerate EV Adoption In South-East Asian Markets
  47. Alnnovation was Included in list of Eligible Stocks for Stock Connect by SZSE Enable to Diversify Investor Base
  48. Prudential plc included in the Shenzhen-Hong Kong Stock Connect Programme
  49. Spackman Media Group Artist Wi Ha-jun’s Drama, LITTLE WOMEN, Premieres #1 In Viewership Ratings
  50. Bybit Launches First-in-Market USDC Options for ETH and SOL

Times Magazine

Offshore vs Inshore Centre Console Boats: Which One Should You Buy?

Centre console boats have become one of the most popular choices among modern anglers. Their open ...

Why Australian Enterprises Are Rethinking Their Core Communication Technologies

The corporate landscape in Australia has undergone a permanent structural shift over the past few ...

Road safety risk: New data reveals almost 2 in 3 Australian drivers are letting car maintenance slide as cost of living pressures bite

Australians are putting off vehicle maintenance and new research released on the eve of National R...

Technology

Why Australian Enterprises Are Reth…

The corporate landscape in Australia has undergone a permanent structural shift over the past few ...

Local News

QLD Day

On Saturday 6 June, parkrun events across the state will be a sea of maroon, with communities  str...

Culture

Sugar: The Sweet Habit Costing Australians Th…

Walk through the doors of any Australian supermarket and you will find aisle after aisle devoted t...

Travel

Sri Lanka: An Island Adventure That Delivers …

For Australian travellers looking for a destination that combines tropical beaches, ancient histor...

The Times Features

Community Politics: Could Australia Return Candidate Se…

Australia's system of government was founded on a simple democratic principle. Communities elected...

Building Better Communities

Australia has spent years debating how many homes we need. Perhaps it is time to ask another ques...

Sugar: The Sweet Habit Costing Australians Their Health

Walk through the doors of any Australian supermarket and you will find aisle after aisle devoted t...