August 2017 Summaries
7 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
On August 24th, Detectify celebrated its move to a new office in Stockholm with a housewarming party attended by customers, investors, business partners, and friends. The event, originally postponed from April due to unsuitable weather, took advantage of a sunny evening for a barbecue and included office tours led by CMO Carl Svantesson, which highlighted various company anecdotes. CEO Rickard Carlsson spoke on the company's impact on cybersecurity, while Timo Tirkkonen from Inventure reflected on Detectify's journey. The party featured references to hacking culture, refreshments from local distillers, and branded accessories to enhance the guest experience. The event underscored Detectify's growth and commitment to improving internet security.
Aug 29, 2017
247 words in the original blog post.
Detectify, a security testing tool, regularly updates its security tests to help users stay informed about the latest vulnerabilities. The most recent updates include tests for a variety of vulnerabilities, such as an unauthenticated SQL injection in vBulletin (CVE-2016-6195), PHP symfony debug toolbar disclosure, a DOM XSS in a WordPress bridge-theme, and updates for Web Cache Deception. For those interested in deepening their understanding of DOM XSS vulnerabilities, Detectify offers additional resources, including a detailed write-up on their creation of the Tesla DOM DOOM XSS.
Aug 28, 2017
100 words in the original blog post.
Historically driven by annual compliance audits, the rapidly evolving landscape of web security demands a more dynamic approach, combining manual penetration testing with automated security testing. While manual pentests, conducted by skilled experts, uncover vulnerabilities and complex attack vectors, they struggle to keep pace with the continuous deployment of new code. Automated security testing addresses this challenge by frequently updating tests to spot vulnerabilities before they reach production. The integration of these methods enhances test frequency and coverage, facilitates knowledge sharing across development teams, and allows pentesters to focus on sophisticated threats. Tools like Detectify, designed for tech teams by ethical hackers, streamline this process with user-friendly interfaces, integrations with popular developer tools, and a robust knowledge base, all while leveraging crowdsourced expertise to stay current with emerging threats.
Aug 16, 2017
506 words in the original blog post.
Sonokinetic BV, a Netherlands-based manufacturer of virtual instruments for media industry composers, faced challenges in keeping up with rapidly changing technology and evolving security threats. To address this, they sought a solution compatible with their AWS infrastructure that could effectively manage security vulnerabilities. Detectify offered a solution by recommending continuous scans of Sonokinetic's application, leveraging the expertise of over 100 ethical hackers to identify and address security issues, including AWS-specific vulnerabilities. This approach provided Sonokinetic with a robust knowledge base to fix vulnerabilities, ensuring they could maintain a secure operating environment while focusing on their creative processes.
Aug 15, 2017
232 words in the original blog post.
KRY is transforming the healthcare sector by offering video consultations with licensed doctors through their app, focusing on making quality healthcare accessible and secure. To meet stringent security requirements, KRY has engaged in extensive discussions with county councils and chosen tools carefully to protect sensitive patient data. Running on AWS, KRY sought a security company familiar with AWS infrastructure and found Detectify to be an ideal partner due to its expertise in AWS services and serverless architecture. Detectify consulted with KRY, advising them to test the security of their entire environment, including production, to identify vulnerabilities. As a result, KRY continuously uses Detectify's services, which have enabled them to achieve high security standards and foster greater security awareness within their organization.
Aug 15, 2017
225 words in the original blog post.
Detectify is a leading platform in External Attack Surface Management (EASM), renowned for its high accuracy in vulnerability assessments, achieving a 99.7% success rate. It is trusted by Product Security (ProdSec) and Application Security (AppSec) teams to reveal potential exploitation methods for Internet-facing applications. The platform automates ongoing, real-world attack simulations using payloads contributed by a global network of elite ethical hackers, identifying critical vulnerabilities before they can be exploited by malicious actors. Detectify offers a two-week free trial for new users to explore its capabilities.
Aug 10, 2017
62 words in the original blog post.
Detectify Crowdsource is a security initiative that integrates the expertise of white hat hackers into its services, allowing collaboration with top security researchers worldwide. In July, the platform received diverse vulnerability submissions, including critical issues like Remote Code Execution and SQL injection, affecting a wide array of technologies from enterprise systems to WordPress plugins. These submissions are incorporated into Detectify's scanning service, which can automatically check numerous websites for vulnerabilities, resulting in over 800 hits in July alone. Since its inception, the platform has identified 5,940 vulnerabilities, showcasing the effectiveness of combining white hat knowledge with automation. To enhance the user experience for hackers, Detectify has introduced improvements like anonymous leaderboard participation and faster payouts through BugCrowd. As part of its growth strategy, security researcher Linus Särud has joined the team to further develop the platform and increase access to valuable security insights.
Aug 03, 2017
357 words in the original blog post.