Home / Companies / Detectify / Blog / June 2020

June 2020 Summaries

2 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify Crowdsource is an innovative bug bounty platform that leverages the power of a community of over 200 ethical hackers to enhance Internet security by automating the reporting of vulnerabilities. Unlike traditional bug bounty programs that focus on individual company needs, Detectify's approach seeks to address systemic vulnerabilities across a broad range of customers, making the process scalable. The platform simplifies the reporting process by utilizing in-house scanning engines to validate vulnerabilities and automatically communicate them to vendors. Detectify Crowdsource offers a unique compensation model where hackers earn continuous rewards for their discoveries, as long as the vulnerabilities they identify remain active in customer assets. This creates a form of passive income, encouraging a diverse group of participants, including pentesters, developers, and security enthusiasts, to contribute their expertise. The platform also facilitates collaboration and learning among hackers by sharing insights on prevalent technologies and guiding them to focus on impactful vulnerabilities.
Jun 30, 2020 875 words in the original blog post.
Detectify releases security updates every two weeks, integrating new findings and enhancements from their security researchers and the Crowdsource ethical hacker community into their scanner. Recent updates include tests for various vulnerabilities such as SQL injection in vBulletin, arbitrary file read in Zoho ManageEngine OpManger, sensitive data disclosure and image injection in Oracle iPlanet, and remote code execution (RCE) in Adobe AEM Fiddle and Groovy Console. Additionally, vulnerabilities like reflected XSS in the NGINX Virtual Host Traffic Status Module, insecure REST endpoints in Couchbase Server, and directory traversal in Spring Cloud Config have been addressed. These updates ensure that Detectify users have immediate access to the latest security measures to protect their systems.
Jun 17, 2020 562 words in the original blog post.