March 2018 Summaries
6 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Risto Siilasmaa, a pioneer in IT security and early investor in Detectify, shares insights into the evolving landscape of cybersecurity, highlighting the shift from physical to digital security with the advent of PCs, smartphones, and cloud technology. Inspired by cyberpunk literature and early computer viruses, Siilasmaa emphasizes the importance of understanding potential threats and vulnerabilities within a company, advocating for proactive measures such as red team attacks to test security systems. He notes the increasing sophistication of attackers, including nation-states and organized crime, and the role of cryptocurrency in driving ransomware. Siilasmaa also stresses the significance of automation and machine learning in managing security tasks and highlights the importance of engaging white hat hackers for better detection and defense strategies. He underscores the CEO's responsibility in cybersecurity and the challenges posed by subcontractors and suppliers, particularly in large corporations like Nokia. Additionally, Siilasmaa discusses the potential impact of GDPR on European companies, mandating stronger protections against cyber threats, and advises building a security-savvy organizational culture over time to adapt to the ever-changing threat landscape.
Mar 28, 2018
1,361 words in the original blog post.
Malicious hackers are often stereotyped as solitary geniuses working in dark rooms, but in reality, they are diverse in methods and motives, often targeting vulnerabilities rather than specific organizations. Many attacks are automated and exploit widespread vulnerabilities, making no target too small. Contrary to popular belief, significant skill is not always required; even simple attacks can cause damage, especially when combined with automation. Hackers also frequently use social engineering techniques to bypass security, demonstrating the importance of comprehensive security measures across all systems. While some hackers are motivated by financial gain, others are driven by the challenge or thrill of exploiting security flaws. To mitigate these threats, adopting a proactive security approach, such as keeping systems updated and engaging with the ethical hacker community, is crucial. The growing community of white-hat hackers offers support in identifying and addressing vulnerabilities, emphasizing that awareness and vigilance are key in defending against cyber threats.
Mar 27, 2018
1,305 words in the original blog post.
Insecure Deserialization, featured in the OWASP Top 10 list of vulnerabilities, involves the unsafe handling of serialized objects, potentially allowing attackers to execute harmful payloads. Serialization converts objects into plaintext for transfer, while deserialization reverts them to their original form. This vulnerability arises when developers overlook security measures, treating serialized objects as trustworthy, which can lead to remote code execution if exploited. Although difficult to quantify its prevalence due to reliance on survey data, insecure deserialization is acknowledged as a significant risk, especially in widely-used applications. The impact varies based on object use, with critical outcomes like remote code execution possible. Detectify and similar tools primarily identify known vulnerabilities, but manual intervention is often required for exploitation, highlighting the need for regular security scans and stringent data validation. The infamous 2017 Equifax hack exploited such a vulnerability, underlining its potential severity.
Mar 21, 2018
1,047 words in the original blog post.
Detectify, a Swedish web security company, secured €5 million in funding led by Insight Venture Partners, with participation from existing investors Paua Ventures and Inventure, to boost international expansion and research and development. Founded in 2013 by top-ranked white-hat hackers, Detectify has grown to over 20 employees and serves clients across various industries, including Trello and Le Monde. The company automates web vulnerability scans using crowdsourced inputs from its network of ethical hackers, who are compensated when their findings identify vulnerabilities. Insight Venture Partners supports Detectify's innovative approach of combining automation with crowdsourced security to address the rapidly evolving threat landscape, viewing it as the future of web security. Insight Venture Partners is a major venture capital firm with a history of investing in high-growth software companies, aiming to drive transformative change and long-term success by offering hands-on growth expertise.
Mar 16, 2018
487 words in the original blog post.
As remote work becomes increasingly common, companies must establish robust cybersecurity policies to prevent hacker attacks and data breaches. Key strategies for enhancing security in remote work environments include using strong, unique passwords stored in a password manager, implementing two-factor authentication, and ensuring multiple layers of security, such as SSL combined with a VPN, especially on public Wi-Fi. Employees should be cautious of phishing attempts and verify the security of tools they use by checking for SSL/HTTPS and responsible disclosure policies. For developers, adhering to the OWASP Top 10 vulnerabilities, utilizing automated security scanners, and keeping CMS software updated with auto-updates are crucial practices. Proper management of access rights, particularly for departing employees, and hiring personnel with a strong interest in security are also recommended. Resources such as Detectify's team articles and Trello's e-book offer additional insights into establishing a successful remote work culture.
Mar 14, 2018
516 words in the original blog post.
Detectify, a Sweden-based IT security company, has achieved advanced technology partner status within the Amazon Web Services (AWS) Partner Network and has received pre-authorization for application vulnerability scanning on AWS. This recognition allows AWS customers to use Detectify’s automated web security scanner without prior approval, facilitating the easy and continuous testing of web applications for over 700 vulnerabilities. Founded in 2013 by a team of elite security experts known for identifying vulnerabilities in major companies like Google, PayPal, and Facebook, Detectify leverages the expertise of 100 ethical hackers to ensure its scanner remains updated against the latest security threats. The company's status with AWS aligns with the shared security model of AWS, where security responsibilities are divided between AWS and its customers, allowing for improved operational efficiency and security management.
Mar 06, 2018
364 words in the original blog post.