Trisha Shetty (Editor)

Vupen

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit
Type
  
Société anonyme

Headquarters
  
Montpellier, France

Founder
  
Chaouki Bekrar

Website
  
www.vupen.com

Founded
  
2004

Vupen wwwtheblackvaultcomdocumentarchivewpcontentu

Area served
  
Information security, Espionage

Vupen pwned google chrome aka sandbox aslr dep bypass


Vupen Security was a French information security company founded in 2004 and based in Montpellier with a U.S. branch based in Annapolis, Maryland. Its specialty was in discovering zero-day vulnerabilities in software from major vendors in order to sell them to law enforcement and intelligence agencies which use them to achieve both defensive and offensive cyber-operations. Vupen ceased trading in 2015, and the founders created a new company Zerodium.

Contents

Work

In 2011, 2012, 2013 and 2014 Vupen won first prize in the hacking contest Pwn2Own, most notably in 2012 by exploiting a bug in Google Chrome. Their decision not to reveal the details of the vulnerability to Google, but rather to sell them, was controversial. Unlike 2012, during Pwn2Own 2014, Vupen decided to reveal to the affected vendors, including Google, all its exploits and technical details regarding the discovered vulnerabilities, which led to the release of various security updates from Adobe, Microsoft, Apple, Mozilla, and Google to address the reported flaws.

According to the French registrar of companies, Vupen earned a net profit of €1,283,000 in 2014. Some years ago Vupen was still providing information about vulnerabilities in software for free, but then decided to earn money with its services. "The software companies had their chance", said Vupen-founder Chaouki Bekrar according to the article, "now it's too late". On 15 September 2013, it was revealed that the NSA was a client of Vupen and had a subscription to its exploit service. On 9 November 2014, the German magazine Der Spiegel reported that the German intelligence agency BND was also a client of Vupen. On 22 July 2015, it was revealed that Vupen provided exploits to Hacking Team between 2010 and 2011.

On 5 May 2015, Vupen headquarters filed documents ceasing its operations.

Zerodium

On 23 July 2015, Vupen's founders launched a new US cybersecurity company named Zerodium and having a different business model as it acquires exclusive zero-day discoveries from independent researchers and reports them, along with protective measures and security recommendations, to its corporate and government clients.

References

Vupen Wikipedia