Home / Companies / Detectify / Blog / June 2021

June 2021 Summaries

2 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
The paradigm shift towards continuous security in application security (AppSec) is essential to maintain the speed and innovation of modern tech organizations, as highlighted by Detectify's CEO, Richard Carlsson. Traditional security practices like annual penetration testing are insufficient in the current landscape where vulnerabilities can be exploited within hours of discovery. Continuous security involves frequent, automated security checks integrated into the development process, allowing for immediate feedback and rapid iteration, which is crucial as applications move quickly from staging to production. Detectify aids this process by leveraging a network of ethical hackers to integrate the latest security research into their tools, enabling organizations to stay ahead of potential threats. This approach ensures security is an enabler for business innovation rather than a hindrance, emphasizing the importance of collaboration between security teams and developers.
Jun 10, 2021 1,205 words in the original blog post.
Detectify's Crowdsource ethical hacker community has been actively contributing to security updates, delivering rapid asset monitoring tests within 25 minutes from discovery to implementation. While confidentiality agreements prevent the public disclosure of all updates, these are promptly integrated into Detectify's scanner for user access. Recent security vulnerabilities reported include a Ghost CMS Install Exposure RCE, which exploits an exposed admin configuration endpoint, and CVE-2021-28073, an Ntopng Authentication Bypass allowing attackers to read specific files. Other vulnerabilities involve the unauthorized disclosure of source code in Nexus Repository, directory listing in SAP Netweaver, argument injection in Ruby Dragonfly, and open redirect attacks in Prometheus. Additionally, Redhat Ceph versions are susceptible to an XSS vulnerability, and AWS CodeBuild build spec files may expose sensitive project information if not securely managed.
Jun 01, 2021 348 words in the original blog post.