logo
Bugcrowd names Umesh Shankar to board, bolstering AI security

Bugcrowd names Umesh Shankar to board, bolstering AI security

Techday NZ09-07-2025
Bugcrowd has appointed Umesh Shankar, Corporate Vice President of Data, Privacy & Security Engineering at Microsoft AI, to its Board of Advisors, marking a notable step in the company's focus on AI security expertise.
Shankar brings substantial industry experience to the advisory board. At Microsoft AI, he leads teams responsible for ensuring the privacy and security of AI products, with a particular emphasis on maintaining user trust through privacy-first engineering practices.
He previously held pivotal roles at Google for more than 18 years. During his tenure there, Shankar served as Distinguished Engineer and Chief Technologist for Google Cloud Security. In these roles, he led key initiatives related to data protection, key management, authentication, authorisation, and insider risk controls. Shankar was also instrumental in integrating generative AI functionalities into Google's security offerings, which improved automated security management capabilities. Beyond Google Cloud, Shankar contributed to the development of Google Assistant, focusing on developer tools, identity, monetisation, and discovery.
Shankar's academic credentials include a PhD and MS in Computer Science from the University of California, Berkeley, specialising in security and privacy. He also holds a BA in Computer Science from Harvard University.
With the increasing adoption of AI across sectors, Bugcrowd has underscored its commitment to providing robust crowdsourced security solutions, particularly for organisations integrating AI into their operations. The company emphasises that incorporating Shankar's expertise is aligned with its strategy to expand its platform capabilities, especially in AI-powered security. "I'm inspired by Bugcrowd's mission to help organizations proactively uncover and address vulnerabilities, strengthening cybersecurity through collaboration and innovation. I am excited to join Bugcrowd's Board of Advisors to help contribute to its efforts as it explores new ways to harness AI, foster trust, and support organizations in addressing emerging security challenges," said Umesh Shankar.
Dave Gerry, Chief Executive Officer of Bugcrowd, commented on Shankar's addition to the Board of Advisors, highlighting the growing importance of AI security frameworks for organisations. "AI is no longer just hype—it's now a core part of technology stacks across industries. However, many organizations are still early in building the security, policy, and governance frameworks needed to support it. At Bugcrowd, AI is embedded into the fabric of our platform, powering innovations like CrowdMatch and enabling secure, confident deployment of LLM-based applications. We're committed to helping organizations de-risk their AI initiatives with the insights and guidance they need. And we're honored to welcome Umesh to our Board of Advisors, his deep expertise will be an invaluable asset," said Dave Gerry, CEO of Bugcrowd.
Bugcrowd's approach to crowdsourced cybersecurity involves leveraging the skills of a broad community of security researchers, or ethical hackers, to identify potential system weaknesses. The company's platform uses AI-powered tools such as CrowdMatch, which aims to efficiently connect organisations with relevant cybersecurity expertise for tackling specific risks. According to the company, integrating AI into its processes supports scalable and adaptive security solutions that respond to evolving threats.
The addition of Shankar to the board is expected to bolster Bugcrowd's capacity to advance its AI-powered crowdsourced intelligence offerings. The company points to the growing need for sophisticated security, policy, and governance measures in the context of rising AI adoption worldwide.
Bugcrowd indicates that this latest appointment reflects its broader strategy to support organisations in navigating the complex digital risk environment created by modern AI applications. Under Shankar's guidance, Bugcrowd aims to further refine its product suite and reinforce its resources for clients seeking to secure AI-related systems and data.
The appointment comes at a time when industries are grappling with new challenges in maintaining digital trust and compliance as AI technologies become more integral to business operations. The company noted that Shankar's background in both technical development and strategic AI integration aligns with Bugcrowd's priorities in this evolving landscape.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

EY & ACCA urge trustworthy AI with robust assessment frameworks
EY & ACCA urge trustworthy AI with robust assessment frameworks

Techday NZ

time5 hours ago

  • Techday NZ

EY & ACCA urge trustworthy AI with robust assessment frameworks

EY and the Association of Chartered Certified Accountants (ACCA) have released a joint policy paper offering practical guidance aimed at strengthening confidence in artificial intelligence (AI) systems through effective assessments. The report, titled "AI Assessments: Enhancing Confidence in AI", examines the expanding field of AI assessments and their role in helping organisations ensure their AI technologies are well governed, compliant, and reliable. The paper is positioned as a resource for business leaders and policymakers amid rapid AI adoption across global industries. Boosting trust in AI According to the paper, comprehensive AI assessments address a pressing challenge for organisations: boosting trust in AI deployments. The report outlines how governance, conformity, and performance assessments can help businesses ensure their AI systems perform as intended, meet legal and ethical standards, and align with organisational objectives. The guidance comes as recent research highlights an ongoing trust gap in AI. The EY Response AI Pulse survey found that 58% of consumers are concerned that companies are not holding themselves accountable for potential negative uses of the technology. This concern has underscored the need for greater transparency and assurance around AI applications. "Rigourous assessments are an important tool to help build confidence in the technology, and confidence is the key to unlocking AI's full potential as a driver of growth and prosperity." Marie-Laure Delarue, EY's Global Vice-Chair, Assurance, expressed the significance of the current moment for AI: "AI has been advancing faster than many of us could have imagined, and it now faces an inflection point, presenting incredible opportunities as well as complexities and risks. It is hard to overstate the importance of ensuring safe and effective adoption of AI. Rigourous assessments are an important tool to help build confidence in the technology, and confidence is the key to unlocking AI's full potential as a driver of growth and prosperity." She continued, "As businesses navigate the complexities of AI deployment, they are asking fundamental questions about the meaning and impact of their AI initiatives. This reflects a growing demand for trust services that align with EY's existing capabilities in assessments, readiness evaluations, and compliance." Types of assessments The report categorises AI assessments into three main areas: governance assessments, which evaluate the internal governance structures around AI; conformity assessments, determining compliance with laws, regulations and standards; and performance assessments, which measure AI systems against specific quality and performance metrics. The paper provides recommendations for businesses and policymakers alike. It calls for business leaders to consider both mandatory and voluntary AI assessments as part of their corporate governance and risk management frameworks. For policymakers, it advocates for clear definitions of assessment purposes, methodologies, and criteria, as well as support for internationally compatible assessment standards and market capacity-building. Public interest and skills gap Helen Brand, Chief Executive of ACCA, commented on the wider societal significance of trustworthy AI systems. "As AI scales across the economy, the ability to trust the technology is vital for the public interest. This is an area where we need to bridge skills gaps and build trust in the AI ecosystem as part of driving sustainable business. We look forward to collaborating with policymakers and others in this fascinating and important area." The ACCA and EY guidance addresses several challenges related to the current robustness and reliability of AI assessments. It notes that well-specified objectives, clear assessment criteria, and professional, objective assessment providers are essential to meaningful scrutiny of AI systems. Policy landscape The publication coincides with ongoing changes in the policy environment on AI evaluation. The report references recent developments such as the AI Action Plan released by the Trump administration, which highlighted the importance of rigorous evaluations for defining and measuring AI reliability and performance, particularly in regulated sectors. As AI technologies continue to proliferate across industries, the report argues that meaningful and standardised assessments could support the broader goal of safe and responsible AI adoption both in the private and public sectors. In outlining a potential way forward, the authors suggest both businesses and governments have roles to play in developing robust assessment frameworks that secure public confidence and deliver on the promise of emerging technologies.

AI-driven DNS threats & malicious adtech surge worldwide
AI-driven DNS threats & malicious adtech surge worldwide

Techday NZ

time5 hours ago

  • Techday NZ

AI-driven DNS threats & malicious adtech surge worldwide

Infoblox has published its 2025 DNS Threat Landscape Report, revealing increases in artificial intelligence-driven threats and widespread malicious adtech activity impacting organisations worldwide. DNS exploits rising The report draws on real-time analysis of more than 70 billion daily DNS queries across thousands of customer environments, providing data on how adversaries exploit DNS infrastructure to deceive users, evade detection, and undermine brand trust. Infoblox Threat Intel has identified over 660 unique threat actors and more than 204,000 suspicious domain clusters to date, with 10 new actors highlighted in the past year alone. The findings detail how malicious actors are registering unprecedented numbers of domains, using automation to enable large-scale campaigns and circumvent traditional cyber defences. In the past 12 months, 100.8 million newly observed domains were identified, with 25.1% classed as malicious or suspicious by researchers. According to Infoblox, the vast majority of these threat-related domains (95%) were unique to a single customer environment, increasing difficulty for the wider industry to detect and stop these threats. Malicious adtech and evasive tactics The analysis highlights the growing influence of malicious adtech, with 82% of customer environments reportedly querying domains associated with blacklisted advertising services. Malicious adtech schemes frequently rely on traffic distribution systems (TDS) to serve harmful content and mask the true nature of destination sites. Nearly 500,000 TDS domains were recorded within Infoblox networks over the year. Attackers are also harnessing DNS misconfigurations and deploying advanced techniques such as AI-enabled deepfakes and high-speed domain rotation. These tactics allow adversaries to hijack existing domains or impersonate prominent brands for phishing, malware delivery, drive-by downloads, or scams such as fraudulent cryptocurrency investment schemes. TDS enables threats to be redirected or disguised rapidly, hindering detection and response efforts. "This year's findings highlight the many ways in which threat actors are taking advantage of DNS to operate their campaigns, both in terms of registering large volumes of domain names and also leveraging DNS misconfigurations to hijack existing domains and impersonate major brands. The report exposes the widespread use of traffic distribution systems (TDS) to help disguise these crimes, among other trends security teams must look out for to stay ahead of attackers," said Dr. Renée Burton, head of Infoblox Threat Intel. Infoblox notes that traditional forensic-based, post-incident detection - also termed a "patient zero" approach - has proven less effective as attackers increase their use of new infrastructures and frequently rotate domains. As threats emerge and evolve at pace, reactive techniques may leave organisations exposed before threats are fully understood or shared across the security industry. AI, tunnelling and the threat intelligence gap DNS is also being leveraged for tunnelling, data exfiltration, and command and control activities. The report documents daily detections of activity involving tools such as Cobalt Strike, Sliver, and custom-built malware, which typically require machine learning algorithms to identify due to their obfuscation methods. Infoblox Threat Intel's research suggests that domain clusters - groups of interrelated domains operated by the same actor - are a significant trend. During the past year, security teams uncovered new actors and observed the continued growth of domain sets used for malicious activities. Proactive security recommended The report advocates a shift towards preemptive protection and predictive threat intelligence, emphasising the limitations of relying solely on detection after the fact. The data indicates that using Infoblox's protective DNS solution, 82% of threat-related queries were blocked before they could have a harmful impact, suggesting that proactive monitoring and early intervention can help counter adversarial tactics. Infoblox researchers argue that combining protective solutions with continuous monitoring of emerging threats is essential to providing security teams the necessary resources and intelligence to disrupt malicious campaigns before significant damage occurs. The report brings together research insights from the past twelve months to map out attack patterns and equip organisations with up-to-date knowledge on DNS-based threats, with a particular focus on the evolving role of harmful adtech in the modern threat landscape.

Infoblox Supercharges Threat Defense To Deliver Enhanced Preemptive Protection Against Sophisticated, AI-Driven Attacks
Infoblox Supercharges Threat Defense To Deliver Enhanced Preemptive Protection Against Sophisticated, AI-Driven Attacks

Scoop

time7 hours ago

  • Scoop

Infoblox Supercharges Threat Defense To Deliver Enhanced Preemptive Protection Against Sophisticated, AI-Driven Attacks

Advancing preemptive security with powerful innovations designed to safeguard users, devices, IoT/OT, cloud workloads and shut down threats before they start Launching new and enhanced Protective DNS capabilities to help organisations predict threats, preempt AI-driven attacks and prevail over modern adversaries Introducing flexible token-based licensing to scale protection efficiently and align pricing with evolving security needs Strengthening leadership in Protective DNS and enabling alignment with forthcoming NIST guidelines to help organisations outpace evolving cyberattacks Powering Google Cloud's DNS Armor, providing native security for cloud workloads, with public preview later this year Infoblox, a leader in cloud networking and security services, today announced major enhancements to its Protective DNS solution, Infoblox Threat Defense™, empowering organisations to stay ahead of sophisticated, AI-driven cyberthreats with preemptive security. As global cybercrime costs surge toward US $23 trillion by 2027,1 traditional 'detect and respond' security tools are struggling to keep up. Modern attackers increasingly deploy AI to create unique, single-use malware and stealthy phishing campaigns that evade traditional defences—making it more likely than ever that any organisation can become 'patient zero.' Infoblox's Protective DNS solution, Infoblox Threat Defense, stops threats before they impact infrastructure by combining predictive threat intelligence with algorithmic and machine learning based detections—blocking high-risk and malicious domains an average of 68 days earlier than traditional tools, with an industry-leading 0.0002 per cent false positive rate. 'The difference between most DNS security tools and our approach is like the difference between law enforcement chasing street-level drug dealers versus taking down the cartel,' said Mukesh Gupta, chief product officer, Infoblox. 'We target the suppliers behind the cyberattackers—the cartel—so threats can be blocked before they ever reach the network. This preemptive strategy helps security teams reduce risk, eliminate noise and stop threats at the DNS layer before they ever reach the network.' To help customers get ahead of the new wave of AI-driven threats, Infoblox is continually delivering groundbreaking threat intelligence—solidifying the role of Threat Defense as a proactive, highspeed threat blocker. From better visibility and actionable insights to flexible licensing and clear metrics on preemptive protection, these new innovations are designed to help security teams close gaps before attackers can exploit them: Protection Before Impact: Provides security leaders with clear, quantifiable metrics on threats neutralised before they can cause damage, streamlining reporting and demonstrating security ROI. Security Workspace: An intuitive, centralised interface that gives security teams deep visibility into their environment with actionable insights to reduce risk and ultimately speed their mean time to respond (MTTR). Detection Mode: Provides organisations visibility into threats they're missing today— without changing existing DNS configuration, minimising operational risk. Asset Data Integration: Delivers deep context into what was protected as part of the preemptive strategy, enabling security teams to do further investigation and analysis. Token-Based Licensing: Flexible, token-based pricing aligned to protected assets simplifies procurement and drives clearer ROI. Powering Google Cloud's DNS Armor: Infoblox's Protective DNS capabilities also power Google Cloud's DNS Armor, providing native security for cloud workloads, with public preview later this year Infoblox Threat Defense gives security teams predictive insights to block attacks as threat actor infrastructure is being created—before malware is even deployed and long before a patient zero is hit. Unlike traditional security tools that must wait for the first victim to detect and respond, Infoblox's approach can preempt the attack entirely. By stopping attacks earlier, Infoblox reduces the load on detect-and-respond tools, such as XDR and SIEM—aligning with Gartner's view that preemptive cybersecurity will replace 40 per cent of traditional solutions by 2028. The latest NIST SP 800-81 guidelines reinforce this shift, noting that DNS can often prevent security incidents earlier than other systems. 'Traditional 'detect and respond' security simply can't keep pace with today's AI-driven attackers and malware. Cybercrime is evolving faster than ever, costing the world trillions and exploiting gaps in legacy defences,' said Scott Harrell, president and CEO, Infoblox. 'The legacy kill chain approach depends on someone else being 'patient zero' so those legacy systems can learn and react—but attackers today customise malware to target individual businesses or industries, rendering legacy, reactive approaches ineffective against modern AI-enabled attackers. When you're patient zero, the only thing being 'killed' is your business. The future of cybersecurity must be preemptive: stop threats before they ever reach your organisation.' 'Across APAC, cyberattacks are growing more aggressive and calculated. From exploiting third-party access points to targeting critical systems—attackers are finding the cracks in our digital foundations and are using AI to strike faster and smarter than ever,' said Paul Wilcox, VP of regional sales, APJ. 'For businesses in Singapore, where digital services are tightly woven into daily life, any downtime or confidentiality breach can be deeply disruptive. That's why organisations here need to invest in earlier threat detection that starts at the DNS layer. Stopping an attack before it begins is far less costly than dealing with the aftermath.' For deeper insights into our latest innovations and why preemptive DNS security matters more than ever, visit ou r Security Momentum launch blog. To see the latest research on evolving threats— including how DNS security blocks 82 percent of attacks before impact—read ou r 2025 DNS Threat Landscape Report. 1. 'Key Cyber Security Statistics for 2025,' SentinelOne, May 15, 2025. About Infoblox Infoblox unites networking, security and cloud to form a platform for operations that's as resilient as it is agile. Trusted by 13,000+ customers, including 92 of the Fortune 100, we seamlessly integrate, secure and automate critical network services so businesses can move fast without compromise. Visi t or follow us on LinkedIn.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store