A quarter of the S&P 500 companies report earnings next week, and that could buffet the market as investors await the July Fed meeting.Market Insiderread more
Iran's Revolutionary Guard claims a British tanker it still holds, Stena Impero, failed to follow international maritime rules.World Newsread more
Amazon hires Trump-allied lobbyist Jeff Miller as battle for Pentagon contract heats up.Politicsread more
In a series of tweets, the president addressed an unusual controversy stemming from a speech delivered Thursday by New York Fed President John Williams.Marketsread more
"You need to understand that we're about to embark on the busiest week of the year for industrial earnings," CNBC's Jim Cramer says.Mad Money with Jim Cramerread more
Boston Federal Reserve President Eric Rosengren is lining up against an apparent push to cut interest rates, telling CNBC in an interview Friday that the central bank can...The Fedread more
The MTA reported that the 1, 2, 3, 4, 5 and 6 trains are all facing delays due to a network communications issue impacting service in both directions, NBC New York reports.Transportationread more
Companies aren't waiting for the U.S.-China trade war to be resolved, says the head of the world's biggest money manager.Investingread more
US officials including Treasury Secretary Steven Mnuchin and White House economic adviser Larry Kudlow will host a meeting at the White House on Monday of semiconductor and...Technologyread more
Trump's constant berating of the Fed and its actions does not influence the central bank's decisions, Boston Fed's Eric Rosengren says.The Fedread more
The lawsuits allege J&J's talc-based baby powder contained asbestos and caused ovarian and other cancers.Health and Scienceread more
Freelance elite hackers can make more than $500,000 a year searching for security flaws and reporting those issues at big companies like Tesla and organizations like the Department of Defense, according to new data released by ethical hacking platform Bugcrowd.
The company, founded in 2012, is one of a handful of so-called "bug bounty" firms that provide a platform for hackers to safely chase security flaws at companies that want to be tested.
Hackers work on a clearly defined contract for a specific company and get paid a bounty when they are able to find a flaw in a company's infrastructure. How much they're paid depends on how serious the problem is.
Companies are increasingly looking for alternatives for cybersecurity testing as millions of jobs in the field go vacant, said Bugcrowd CTO Casey Ellis. By some estimates, as many as 3.5 million cyber jobs may be left open by 2021.
Last year, the company saw it's largest payout for a single exploit — $113,000 for a bug found at a large tech hardware company, Ellis said. Payouts rose 37 percent year over year in 2018, according to the data.
Half of the ethical hackers — or security experts hired to penetrate networks and computer systems on behalf of their owners — reported having full-time jobs, according to the survey. About 80 percent said the endeavor helped them land a job in cybersecurity. For the top 50 hackers, the average yearly payouts were around $145,000, Ellis said.
According to Ellis, the hackers making the most money have certain essential skills.
"They found a particular vulnerability class and they go after that over and over again at different companies. They will go all around cyberspace and try to find as many opportunities to exploit that vulnerability as they can," Ellis said.
"They also have good reconnaissance skills and are able to operate on an understanding of what might cause the most damage to an organization. A good sense of how businesses work, or how their infrastructure is built, is really helpful," he added.
And while 94 percent of Bugcrowd's hunters are ages 18 to 44, several are still in high school or middle school. The cost of entry is low and based on skills, Ellis said. About a quarter of the hackers on the platform do not have a college degree.
In order to protect against cyberattacks, companies have been using a range of methods to allow people with hacking skills to test their defenses. Some companies use in-house penetration testers, often putting them on so-called red teams to play the role of a malicious collective trying take down corporate servers or steal information.
Others use consulting firms that offer this service, or bug bounty companies like Bugcrowd, HackerOne, Synack and Cobalt. Or they simply make a reporting email available for anyone who finds issues to reach out to them.
The bug bounty programs offer a more formalized approach, with rules that the hackers must follow, such as not jumping from a server to be tested to other servers with more sensitive data, Ellis said.
IJet and Tesla pay hackers $1,000 to $15,000 for finding problems, depending on the severity of the issue. Mastercard pays up to $3,000. In October, the Department of Defense awarded "Hack the Pentagon" contracts to Bugcrowd, Synack and HackerOne for their crowd-sourced programs.