February 2020 Summaries
2 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Sebastian Neef, a prominent IT security freelancer, examines how WordPress plugins leak sensitive data, highlighting the security risks associated with relying on third-party plugins. The OWASP Top 10 identifies sensitive data exposure as a top web security issue, and Neef's research focuses on popular WordPress plugins with over 300,000 active installations that are vulnerable to remote exploitation. He categorizes leaked information into credentials, personal identifiable information (PII), and system information, emphasizing that such leaks often stem from WordPress's file permission settings and improper handling of log files by plugins. The analysis reveals that static file paths and directory listing vulnerabilities can expose sensitive log files, while randomizing file names and preventing directory listing can mitigate these risks. Neef advocates for enhanced security practices among both plugin developers and administrators, providing remediation tips and suggesting the use of Detectify's automated security monitoring to identify and address potential vulnerabilities.
Feb 26, 2020
2,573 words in the original blog post.
In anticipation of cybersecurity trends for 2020, experts Anne-Marie Eklund Löwinder and Tanya Janca highlight the increasing complexity of digitalization, which challenges both home and workplace environments with security vulnerabilities. Löwinder emphasizes the growing threat to critical infrastructures from IoT devices and cloud services, where misconfiguration and third-party vulnerabilities pose significant risks. She questions whether companies will allocate sufficient resources to address these threats and underscores the importance of ethical hacking for preemptive vulnerability identification. Janca predicts more breaches but also a shift towards DevOps cultures, emphasizing security automation and the integration of artificial intelligence and machine learning in security practices. She warns against the unethical use of technology that invades privacy and is enthusiastic about new tools emerging in the application security field. Both experts express their commitment to advancing their organizations' security practices and look forward to industry events such as Internetdagarna and various security conferences.
Feb 19, 2020
1,017 words in the original blog post.