December 2016 Summaries
3 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
As 2016 concluded, several significant security events marked the year, including large-scale hacker attacks, ransomware, and privacy policy controversies. Notable incidents included the Dropbox hack, which compromised millions of user accounts and highlighted the need for strong passwords, and the Dyn DNS DDoS attack, which exploited vulnerable IoT devices to disrupt major websites. In the UK, the passing of the Investigatory Powers Act raised concerns over increased state surveillance, while in the US, debates ensued over privacy following Cisco's revelations about the NSA and Apple's refusal to create an iPhone backdoor for the FBI. The Bitfinex hack exposed the risks of cryptocurrency exchanges, and the Dirty COW exploit underscored the importance of addressing long-standing vulnerabilities in software. Ransomware attacks surged, affecting diverse institutions and emphasizing the need for heightened security awareness. DARPA's Cyber Grand Challenge introduced automation into vulnerability hacking and patching, showcasing the potential of autonomous systems in cybersecurity. Looking forward to 2017, there is anticipation of continued focus on IoT security, advanced attacks on Tor networks, and increased security awareness efforts.
Dec 15, 2016
766 words in the original blog post.
In 2016, Detectify experienced significant growth and achievements, marked by active participation in over 30 international security conferences, the release of a new, more efficient crawler, and the expansion of their team with diverse new hires. They introduced a new OWASP Top 10 view for improved vulnerability assessment, gained prominent clients like Trello and Pipedrive, and received widespread media coverage for their security research. The company also launched several new integrations, including JIRA, and expanded their security expertise through the Detectify Crowdsource platform. Recognized as one of Europe's hottest startups by Wired UK, Detectify focused on e-commerce security in anticipation of the holiday season and hosted a memorable hippie festival with co-workers. They also established partnerships with Office IT Partner and Basefarm to enhance security testing services, shared insights through guest blogging, and maintained engagement with their audience through newsletters and interactive content.
Dec 14, 2016
1,210 words in the original blog post.
Pipedrive, a sales pipeline management tool founded in 2010, is utilized by over 30,000 customers worldwide to enhance productivity and elevate sales processes. Jesse Wojtkowiak, the Information Security Manager at Pipedrive, emphasizes the growing workload in security management, highlighting the importance of efficient solutions like Detectify. After a career in the navy and further studies in cyber security, Wojtkowiak notes that security concerns often arise in customer interactions, particularly around privacy and regulations like GDPR. Detectify, discovered through research and an investment group, is used by Pipedrive to scan applications and blogs, integrating with JIRA for seamless risk assessment and resolution tracking. The tool significantly enhances security efficiency, allowing Pipedrive to address vulnerabilities promptly with responsive support from Detectify, contrasting with larger, less agile enterprise-focused solutions. Wojtkowiak stresses that while security challenges persist, leveraging modern tools like Detectify, alongside bug bounty programs and manual pentesting, is crucial for maintaining continuous and automated security testing.
Dec 12, 2016
586 words in the original blog post.