April 2020 Summaries
3 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Detectify releases major security updates every two weeks to ensure their tool remains current with the latest discoveries and enhancements from their security researchers and the Crowdsource ethical hacker community. While not all updates can be publicly detailed due to confidentiality agreements, they are promptly integrated into the scanner available to all users. Recent updates include the addition of tests for vulnerabilities like CVE-2020-7961, which involves a JSON deserialization issue in Liferay Portal allowing remote code execution, a Denial of Service vulnerability in Adobe Experience Manager due to unregulated cached page flushing, and CVE-2020-8509, which affects Zoho ManageEngine Desktop Central by allowing unauthenticated access to a servlet that could lead to sensitive information exposure. Users are encouraged to begin scans for these vulnerabilities and can start a free trial or log in to check their assets with Detectify.
Apr 16, 2020
290 words in the original blog post.
Tom Hudson, known by his hacker handle TomNomNom, is a UK-native who transitioned from software engineering to ethical hacking and is now the Tech Lead for Security Research & Module Development at Detectify. Passionate about learning and sharing knowledge, Tom believes in the importance of collaboration and diversity in the cybersecurity field, highlighting that diverse teams can better address complex challenges. His journey began as a Network Engineer with interests in cybersecurity, which evolved through experiences with bug bounties and collaborations within the ethical hacking community, leading to significant achievements like being named Most Valuable Hacker at a HackerOne event. Tom advocates for changing the narrative around cybersecurity to reduce fear and misunderstanding, emphasizing the need for open corporate responsibility disclosure programs. At Detectify, he values the company's commitment to diversity, knowledge sharing, and maintaining a work-life balance, viewing it as an environment where he continues to learn and contribute to the field. Tom envisions a future where collaboration and community spirit are central to advancing cybersecurity, encouraging partnerships even among competitors to tackle the complexities of the internet.
Apr 15, 2020
1,286 words in the original blog post.
In a light-hearted April Fool's Day twist, the text humorously merges the concept of pen-testing with actual pens, offering tongue-in-cheek advice from the Detectify Crowdsource community, a group known for their bug bounty work and security testing expertise. The piece playfully suggests tips for pen-testing success, including finding a niche, staying creative, and documenting findings, while cleverly using pen-related puns and metaphors to entertain and engage readers. This whimsical narrative reflects the growing acknowledgment of pen-testing as a critical component for maintaining the integrity of communication systems and data storage, as companies are encouraged to proactively manage risks through skilled testing. The article ultimately celebrates the community's achievements while enjoying a playful take on the world of cybersecurity.
Apr 01, 2020
591 words in the original blog post.