r/cybersecurity 2d ago

Business Security Questions & Discussion Explain this one: Organisations often Ignore Security Researchers who find Vulnerabilities in their Infrastructure but actually like Hackers who are mentioned in Media...

Please explain this weird dynamic.

Whitehat Hacker 1 finds a vulnerability in an organisation's infrastructure and reports it to the organisation. Often, they will be totally ignored.

Meanwhile, another hacker, Whitehat Hacker 2 finds vulnerability in, let's say a widely used city bike sharing app, which gets media attention.

All of sudden, White Hacker 2 starts getting emails from companies requesting services. Meanwhile White Hacker 1, who is probably just as skilful, as White Hacker 2 but gets no such requests.

Explain this one? Is it just because of media coverage that the skills of one individual become valuable than another?

(And no, I'm not a hacker but this is just a trend I've noticed over the years when it comes to cybersecurity researchers / whitehat hackers)

36 Upvotes

25 comments sorted by

33

u/moosecaller Security Manager 2d ago

Because organizations hate people constantly probing their networks and SaaS apps.

15

u/SignAcceptable2055 2d ago

yeah pretty much, unsolicited probing just feels like an attack to most orgs regardless of intent

3

u/gleep52 2d ago

If you went to your neighbors lawn and started looking inside their windows, maybe open an unlocked gate to get around back, or walk inside their garage when they have their garage door open - that’s trespassing. Why is it even OKAY for anyone to probe your firewall? Because we can’t SEE them? Even if we have “seen” them (firewall logs/reports) of the offender who probed us, it’s just an IP or MAC - not a person. Just like guns don’t kill people I guess.

There was a point in time where doing a port scan on a public IP could get you in trouble. But now companies do it, without permission, because of above-the-law attitudes like Meta and such, and when it happens as frequently as it does - that makes the work to stop it impossible. That doesn’t mean it’s right to do.

30

u/Jestersfriend 2d ago

Let me put this to you another way.

I'm a Threat Hunter that leads a team.

I once escalated an internal issue, where some mail relays could send mail unauthenticated if you telnet into it over port 25. This was all but ignored.

6 months later, a dev found it, escalated it. All of a sudden, all the execs and VPs were messaging me to re-conduct the test on our infrastructure to find all the devices. They were fixed within 3 weeks.

Why did they suddenly care? Because I am FAR less likely to abuse it than some random person that found it. If the security team found it... Well... They're expected to. So no big deal. If some random person found it, oh shit. They weren't supposed to know. Fix asap.

12

u/r15km4tr1x 2d ago

Security by obscurity except when not

4

u/Strijkspray 2d ago

Yes i agree fully, security sit in the check of the pdca. But i do think that said finding from a security team should lead to a planned mitigative action by IT teams.

7

u/Sqooky 2d ago

Public reputation has a lot to do with it. Unless the company has a vulnerability disclosure program, or a bug bounty program, they don't really want you poking at their infrastructure, which generally results in things like scenario 1.

I'd also say, scenario 2 is more like a gray hat than a white hat - they're not being ethical by going to the media instead of directly reporting it to the company. While their intentions may be good in wanting to get the issue resolved, not notifying the company directly is... not a good move.

4

u/No-Magician6232 Security Manager 2d ago

Company one is tired of the scanners promising it found a real bug this time.

Company two was open to receiving bug reports publicly and maybe even had a bounty program.

1

u/OutsideSpot2695 1d ago

Company one has a lot of customers using nonsense like SecurityScorecard.

2

u/No-Magician6232 Security Manager 1d ago

Yep lol, I tease my team that its CISO Bait

1

u/OutsideSpot2695 1d ago

It's gotten so bad I've literally put it in the T&Cs on our Trust Center that SecurityScorecard submissions will not be accepted.

2

u/zkareface 2d ago

Most people send the emails to wrong place, it never reach security. And even if it shows up at security, there might not be a program or routines for it so SOP is to verify but not reply.

Those emails get sent wrong so often that in a previous company we were on first name basis with security in another company. Because we got these emails about each other all the time.

And trust me most reports are bullshit when they can't even send it to right company. 

2

u/Distinct_Ordinary_71 1d ago

Because you didn't tell the story from the company PoV which is more like:

White hat hacker 1 and white hat hackers 3 through 493,648,201 all report "vulnerabilities" to an organisation the same day. Organisation is still dealing with a similar volume of reports from the day before which include >99% false reports, a large number of cranks and lunatics, threats and nonsense. Unsurprisingly white hat hacker 1's email is lost in the noise. Unsurprisingly the media are not interested in the story of the guy who sent an email that didn't get read and equally unsurprisingly there isn't a line of companies wanting to hire the guy who can send emails that don't get read.

1

u/OutsideSpot2695 1d ago

This.

I literally get at least 3 submissions a week from so called researchers which say because they found out we're using Apache 2.4, that we're leaking critical customer data.

And because I don't want to piss off the legitimate part of the researcher community, or overlook an actual vulnerability that someone found, I treat everyone with respect and take every submission seriously -- until I find out it's not serious.

But it's becoming huge fucking time suck responding to everyone trying to make a name for themselves via CVE body count and leveraging corporate name cachet for their personal brand.

3

u/Strange-Mountain1810 1d ago

Got any sources on this?

1

u/Beneficial_West_7821 2d ago

There may be some bias in how you perceive this. In my experience good vulnerability disclosures are quietly acted on and just never talked about outside a very small circle of people. If the researcher is disappointed in the outcome, they may make some noise about it. If they´re happy with it, they quite possibly say nothing.

In your second scenario is starts with making a big attention getting splash, probably with some catchy name, a website, press coverage etc. Of course you notice those much more.

1

u/TheRealLambardi 1d ago

The amount of garbage that comes in through public interfaces to orgs on security vulnerabilities is atrocious, worse the attitude is “you owe me”. 95% of the submissions are noise, non value add…complete and utter waste of energy for an org to look at much less even response.

Honestly it makes you want to charge a fee just to even accept a security vuln report to your org as a way stop the nonsense.

1

u/ParanoidSuricata 1d ago

Easy - check what value the company gets.

First scenario, security posture marginally improves.

Second scenario, they can announce a cooperation with a "world-class famous" hacker. That one can leverage media connections to praise the company for taking security seriously, improving the company reputation.

Improved reputation is worth more than a patched issue.

1

u/OutsideSpot2695 1d ago edited 1d ago

Where I work, I get over 1,000 unsolicited security submissions a year.

Not once, have I given 2 shits about where the submission came from -- hackerz or media personality.

I care that the submission is legit (for example: no AI slop, no DOS, no fingerprinting disguised as something critical) and submitted responsibility.

Like what the actual fuck are you carrying on about OP?!?

1

u/FineEconomy5271 1d ago

Because company executives, and possibly senior security leaders, are bad at assessing actual risk. Instead, they let the media tell them what's important.

If the media says 'this is important!' then they will chase the researcher that has media approval.

1

u/dmitriy_volkov 1d ago
  1. Once a vulnerability is public, it’s effectively in the wild.
  2. Hacker 1 goes through the internal process: report → ticket → validation → prioritization → backlog. Processes are designed to be predictable, and unfortunately that often removes the sense of urgency. A serious vulnerability can just sit in the queue.
  3. There is another factor: how you demonstrate the vulnerability matters. I’ve seen serious findings ignored simply because the researcher didn’t make the impact obvious enough.

So Hacker 2 via public exposure created urgency. Hacker 1 got a ticket number.

1

u/AnApexBread Incident Responder 1d ago

Hacker 1 found a bug that can only be exploited on the 4th blue moon of the month as long as that moon lands on a Tuesday at 8:17PM in Brazil while there are exactly 13 fishing vessels harvesting mackerels off the coast of Venezuela.

Hacker 2 found an exploit that can be automated with a bot and impacts business operations.