Business Daily Media

Men's Weekly

.

Lazada and YesWeHack Strengthen Long-term Partnership by jointly hosting a live Bug Bounty event at HITBSecCONF2022 Singapore

Since launching their first private bug bounty program in 2020, the initiative has expanded into a two-day live hacking event focused on protecting Lazada’s consumer data

SINGAPORE - Media OutReach - 8 September 2022 - Southeast Asia's leading eCommerce platform Lazada has concluded its latest live bug bounty with YesWeHack, a leading global Bug Bounty and Vulnerability Disclosure Policy (VDP) Platform.

The two-day live bug bounty program, which was held at the Hack In The Box Security Conference (HITBSecCONF 2022), resulted in 115 vulnerability reports being submitted by the several dozen researchers present at the event, including some of the best security researchers in the world.

After running a successful two-year Bug Bounty program with YesWeHack, Lazada scaled the program to the next level this year during the HITBSecCONF 2022. The event allowed Lazada to test their applications over the given period of time, while being able to meet with researchers to exchange on the discoveries—thus giving Lazada deep and exclusive insights to the vulnerabilities found.

Lazada wanted to use this live event as an opportunity to achieve in-depth security. To enable this, the company voluntarily disabled a number of security mechanisms for participating researchers and only for the period of the event, allowing them to extensively test the systems and applications. For instance, researchers were able to bypass Web Application Firewalls (WAF) throughout the length of the event—allowing them to hack into the eCommerce platform's sites and services directly. Lazada had chosen to disable WAFs for the hunters, due to the fact that while they are able to block most of the attack, they are not infallible. In addition to WAFs, Lazada also disabled other security solutions that are typically used as a first line of defense, so as to offer hackers the chance to test their application in greater depth.

"Accomplishing a live program on this scale demonstrates Lazada's commitment to security and progressive stance towards bug bounties. By engaging with the broader community, the eCommerce giant is placing an unprecedented level of trust in ethical hackers to better strengthen their security, transparency, as well as data privacy and protection. We are delighted to be able to contribute to yet another successful collaboration with Lazada," said Kevin Gallerin, CEO APAC, YesWeHack.

"Securing customer's data and protecting it from any future incidences is of highest importance at Lazada. Having some of the best security researchers in the world in the same room as us is an exceptional opportunity to learn and exchange—especially for our red team, who mounts deliberate attacks on our systems daily to identify and fix vulnerabilities," said Bruno Demarche, who leads the Red Team & Security Testing Team at Lazada Group.

"The live bug bounty program was a rewarding experience for Lazada and YesWeHack alike. The teams have been able to uncover quality results, which has already given us ideas on how we can improve our internal testing processes for our application and services to ultimately better safeguard Lazada's customers and partners," said Yuezhong Bao, Head of Cybersecurity, Lazada Group.

Lazada's partnership with YesWeHack began in January 2020 with a successful 18-month private bug bounty program. The partners then continued to expand the scopes of their collaboration, and Lazada opened its program to the public in 2021, with rewards of up to US$10,000 per bounty. Since then, the company has been working with over 45,000 ethical hackers to detect flaws within their application and systems to achieve maximum security and protection over their platforms.

The collaboration with Lazada has also allowed YesWeHack to further advance its community of cybersecurity experts and position the company as the leading player of bug bounties in Asia Pacific. Since 2019, YesWeHack has served more than 60 clients from its Asia Pacific headquarters in Singapore, including large BFSIs, tech unicorns and government bodies. With a growing market demand being seen for the crowdsourced security model, 40 percent of YesWeHack's security researchers are based out of Asia, with 30 percent of its clientele coming from Australia, China, Indonesia, Malaysia, and Singapore.


Hashtag: #YesWeHack

About Lazada

Lazada Group is Southeast Asia's pioneer eCommerce platform. For the last 10 years, Lazada has been accelerating progress in Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam through commerce and technology. Today, a thriving local ecosystem links about 160 million active users to more than one million actively-selling sellers every month, who are transacting safely and securely via trusted payments channels and Lazada Wallet, receiving parcels through a homegrown logistics network that has become the largest in the region.

With a vision to achieve USD100 billion annual GMV, Lazada aims to serve 300 million shoppers by 2030, and be the best at enabling brands and sellers in digitalizing their businesses.

In 2022, the Lazada Foundation was set up to empower youths and women for the digital future, close the gender digital divide and uplifting communities by creating positive impact. More information can be found here .

About YesWeHack

Founded in 2015, YesWeHack is a global Bug Bounty and VDP Platform. YesWeHack offers companies an innovative approach to cybersecurity with Bug Bounty (pay-per-vulnerability discovered), connecting more than 40,000 cybersecurity experts (ethical hackers) across 170 countries with organisations to secure their exposed scopes and reporting vulnerabilities in their websites, mobile apps, infrastructure and connected devices.

YesWeHack runs private (invitation based only) programs and public programs for hundreds of organisations worldwide in compliance with the strictest European regulations.

In addition to the Bug Bounty platform, YesWeHack also offers: a creation and management solution for Vulnerability Disclosure Policy (VDP), a Pentest Management Platform, a learning platform for ethical hackers called Dojo and a training platform for educational institutions, YesWeHackEDU.


News from Asia

FGA Trust Showcases Hong Kong’s Institutional Strength at 2025 Inclusion Conference on the Bund

HONG KONG SAR - Media OutReach Newswire - 12 September 2025 - FGA Trust, a licensed trustee in Hong Kong, participated in the 2025 Inclusion Conference on the Bund by the invitation of InvestHK, a...

Appier Drives GenAI-Powered Creatives Transformation with AdCreative.ai, Empowering Hong Kong Brands to Accelerate into the Agentic AI Marketing Era

HONG KONG SAR - Media OutReach Newswire - 12 September 2025 - Appier (TSE: 4180), an AI-native SaaS company specializing in AdTech and MarTech solutions, today hosted the GenAI for Marketing Asia ...

Uni-Bio Science Group and Kexing Biopharm Forge Strategic Partnership to Accelerate Global Expansion of Osteoporosis Treatment Bogutai®

Zhangqiu District, Jinan City, Shandong Province – September 2025HONG KONG SAR - EQS Newswire – 12 September 2025 - Uni-Bio Science Group ("the Group") is pleased to announce the signing of a strat...

10th Belt & Road Summit celebrates decade of business, investment and co-operation achievements

HONG KONG SAR - Media OutReach Newswire - 12 September 2025 - The 10th edition of the Belt and Road Summit in Hong Kong (September 10-11) gathered about 6 200 high-profile participants from govern...

Digital Entertainment Leadership Forum 2025 Kicks Off Today

AI-Driven Innovation Unlocks the Missing Piece in Digital EntertainmentHONG KONG SAR - Media OutReach Newswire - 12 September 2025 - The Digital Entertainment Leadership Forum 2025 (DELF 2025), Cy...

COOFANDY, EKOUAER, and Zeagoo Announce Participation in Oktoberfest 2025 with Joint Pop-Up Event at Substanz Club

MUNICH, GERMANY - Media OutReach Newswire - 13 September 2025 - COOFANDY, EKOUAER, and Zeagoo are excited to announce their participation in the 2025 Munich Oktoberfest, alongside a special off...

Coastline Wealth Management’s Garrett Taylor Named a Top New York Best-in-State Wealth Advisor

LONG ISLAND, US - Media OutReach Newswire - 13 September 2025 - Garrett Taylor, CRPC®, Founder and Managing Partner of Coastline Wealth Management, has earned a place on Forbes' 2025 Best-in-State...

China Telecom Global Showcases at the 10th Belt and Road Summit, Paving the Way for a Smarter Silk Road Future

HONG KONG SAR - Media OutReach Newswire - 13 September 2025 - The 10th Belt and Road Summit was successfully held at the Hong Kong Convention and Exhibition Centre from September 10 to 11, 2025...

IVD Medical Holding Limited and ETHK Group Establish Joint Venture, On-Chain Financial Strategy Upgraded On September 14

NEW YORK, US - Media OutReach Newswire - 14 September 2025 - IVD Medical Holding Limited (01931.HK) released an announcement stating its collaboration with ETHK Group, a global on-chain financial ...

IVD Medical Holding Limited Releases "ETHK" Ecosystem Vision: Technology for the Public, Chain for the Way On September 14

NEW YORK, US - Media OutReach Newswire - 14 September 2025 - IVD Medical Holding Limited (01931.HK) officially announced its name change. Its English name was changed to "ETHK Labs Inc...

Manny Shah: Is your business disappearing from Google? You’re not alone

Small business owners across Australia are panicking as their websites vanish from Google’s front pages overnight. According to Manny Shah, cofounde...

MR Roads named Queensland Finalist in the 2025 Telstra Best of Business Awards

MR Roads, co-founded by Daniel Mikus and James Rolph, has been announced as a Queensland finalist in the prestigious 2025 Telstra Best of Business...

AWS research shows strong AI adoption momentum in Australia, with startups outpacing large enterprises in innovation

Amazon Web Services (AWS), an Amazon.com company, released new research revealing that while artificial intelligence (AI) adoption continues to acce...

Changing the World One Bite At a Time: IKU Turns 40

One of Australia’s first plant-based, chef-led eateries and now ready meal provider IKU is celebrating its 40 year anniversary with the business e...

Three generations marking 45 years in hot-air balloons

Australia’s leading hot-air balloon company is celebrating 45 years in the sky and its 700,000th passenger, driven by the passion of father-son du...

Workplace DMs, Reinvented: Deputy Messaging, Purpose-Built For Shift-Based Teams

Deputy, the global people platform for shift-based businesses, has launched Deputy Messaging, a fully integrated, real-time communication tool designe...

Sell by LayBy