Home / Companies / Detectify / Blog / February 2021

February 2021 Summaries

5 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify's Crowdsource ethical hacking community has been actively contributing security updates, including zero-day research, to enhance asset monitoring by delivering tests at unprecedented speeds, within 25 minutes from detection to scanner deployment. While confidentiality agreements limit the public disclosure of all security updates, these are promptly added to the Detectify scanner for user access. Recent reported vulnerabilities include Apache Cocoon XXE, which risks data disclosure; Magento XSS, allowing credential theft via JavaScript execution; Node-RED Dashboard path traversal, which permits arbitrary file downloads; and several remote code execution (RCE) vulnerabilities in Unraid, Zoho ManageEngine, Cockpit CMS, Yaws, and ThinkPHP, potentially granting attackers full server control. Additionally, a directory traversal vulnerability in Cisco ASA/FTD could enable unauthorized file deletion, highlighting the diverse range of security threats addressed by Detectify's ethical hackers.
Feb 22, 2021 445 words in the original blog post.
Detectify has prioritized building a diverse team by attracting talent from various backgrounds, nationalities, and life experiences, as demonstrated by their first Diversity & Belonging Survey. This initiative reflects the company's belief that cybersecurity should be inclusive and accessible to all, challenging the perception that it is only for a select few. Detectify's workforce includes 45% women globally and 72% in executive leadership, although women make up only 35% of technical roles, highlighting an area for improvement. The company embraces over 30 nationalities and values personal milestones, with 20% of employees being parents or caretakers. Detectify remains committed to improving gender parity and inclusivity through community events and equitable hiring practices. The positive response from 90% of survey participants further motivates the company to enhance diversity and inclusion efforts, with a future report planned to share progress and inspire other organizations.
Feb 19, 2021 651 words in the original blog post.
Detectify Crowdsource, a community of ethical hackers, contributes new vulnerabilities that are integrated into automated security tests for users, and the Vuln of the Month series highlights notable vulnerabilities like CVE-2020-10148, the SolarWinds Orion Authentication Bypass. This critical zero-day vulnerability allowed attackers to bypass authentication, enabling them to execute unauthorized API commands and deliver the Supernova malware, as seen in a major attack on SolarWinds, a system used by 33,000 customers, including US government agencies and large corporations. The vulnerability can be exploited by manipulating the Request.PathInfo portion of a URI request to include specific parameters, which may cause SolarWinds to process the request without authentication. Detectify assists by scanning for this vulnerability in SolarWinds Orion users' applications and providing alerts if detected, urging users to start a free trial or check existing accounts to secure their assets.
Feb 16, 2021 300 words in the original blog post.
In the wake of the shift to remote work catalyzed by the COVID-19 pandemic, small to mid-sized tech organizations have faced increased challenges in maintaining security visibility, prompting a focus on enhanced authentication, automation, and collaboration with ethical hackers. Multi-Factor Authentication (MFA) emerged as a critical defense, while tools like Detectify have been utilized to automate vulnerability detection and prioritize security efforts through integration with CI/CD pipelines and communication platforms like Slack. Organizations have reinforced security awareness through training and by involving developers in security remediation, aiming to address vulnerabilities and configure secure infrastructures amid the expanded attack surface of remote work environments. Additionally, some companies have transitioned from VPNs to identity-aware proxies to improve security by linking access to Single Sign-On (SSO) systems, reducing unauthorized access risks. The collaboration with ethical hackers has also increased, with responsible disclosure programs and manual pen testing enhancing security posture. As remote work continues, maintaining security visibility remains crucial, and tools like Detectify play a significant role in identifying and remediating vulnerabilities by providing verified and prioritized findings to security defenders.
Feb 10, 2021 890 words in the original blog post.
Detectify's Crowdsource ethical hacker community has been actively identifying and reporting various security vulnerabilities, which are promptly added to their scanner for user access. Recent updates between January 25 and February 5 include several critical vulnerabilities such as remote code execution (RCE), cross-site scripting (XSS), information exposure, authentication bypass, and SQL injection across multiple platforms like Zend Framework, Fortigate FortiWeb, PrestaShop, UCMS, SolarWinds Orion, Apache Tomcat, Silver Peak Unity Orchestrator, SonicWall SSLVPN, WebLogic Server, SonarQube, and ECShop. These vulnerabilities, identified by specific CVE numbers, highlight potential risks such as unauthorized command execution, credential theft, or unauthorized file deletion, emphasizing the importance of timely updates and patches to protect against possible exploits.
Feb 08, 2021 663 words in the original blog post.