March 2022 Summaries
6 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Detectify has enhanced its platform with new features aimed at improving external attack surface monitoring, which is crucial as vulnerabilities continue to evolve. The platform now offers an at-a-glance mode for critical insights, making it easier for development teams to manage their use of Detectify. The Enterprise Attack Surface Monitoring product provides continuous monitoring of domain and subdomain configurations, helping companies secure their expanding attack surfaces. Notable features include the ability to view newly discovered assets easily, a port scanner that goes beyond the standard ports 80 and 443, and improved team member management through simplified invitation processes. Detectify's tools scan web applications for known vulnerabilities using techniques like fuzzing and crawling, offering continuous security integrated with development workflows. The platform's advancements aim to provide users with more comprehensive insights into their attack surfaces and facilitate efficient vulnerability management.
Mar 29, 2022
578 words in the original blog post.
Research from Detectify, a SaaS security company, reveals a significant rise in subdomain takeovers, which have become more challenging to monitor due to increased vulnerabilities in domains. The study highlights a 25% increase in vulnerabilities detected in 2021 compared to 2020, with the median number of vulnerabilities per domain doubling. This surge underscores the importance of External Attack Surface Monitoring (EASM) tools in enhancing organizational security, as modern infrastructure's dependence on DNS for internal and third-party services expands attack surfaces and potential cyber threats. Subdomain takeovers occur when attackers exploit DNS misconfigurations to gain control over subdomains, posing risks such as data theft and phishing. Despite being pioneered by ethical hackers and highlighted by Detectify in 2014, this vulnerability remains prevalent, exacerbated by the rise of cloud solutions. Detectify's Surface Monitoring tool leverages a network of ethical hackers to monitor subdomains, detect vulnerabilities, and alert organizations to potential takeovers, emphasizing the necessity of maintaining a comprehensive subdomain inventory and deploying EASM tools to mitigate risks.
Mar 22, 2022
771 words in the original blog post.
Companies face challenges in securing their increasingly complex and expanding attack surfaces due to the rapid proliferation of data, the rise of third-party software, and the growing volume of domains. Attackers and security professionals view these surfaces from different perspectives, creating vulnerabilities where their views do not align. To manage this, organizations are encouraged to adopt External Attack Surface Management (EASM), which involves using attacker-like reconnaissance methods to identify and secure potential vulnerabilities. Detectify, a platform powered by a community of ethical hackers, aids companies in managing their web security by automating testing for vulnerabilities, identifying unknown assets, and integrating the latest attack vectors into development processes. This approach allows organizations to make informed security decisions and efficiently allocate their security resources, ultimately enhancing their digital resilience.
Mar 15, 2022
774 words in the original blog post.
Gender inequality remains a significant issue in the tech industry, particularly within cybersecurity, where women comprise only 24% of the workforce. Despite longstanding debates, active measures are needed to empower women in this field. In honor of International Women's Day, several women at Detectify shared their experiences and motivations for joining the security industry, emphasizing the importance of diversity, inclusion, and the meaningful impact of their work in making the internet safer. They highlighted the industry's dynamic nature, the need for proactive security measures, and the political aspects of cybersecurity. The women also shared advice for others entering the field, encouraging hands-on learning, networking, and understanding the broader implications of cybersecurity. Detectify exemplifies progress in gender equality, with a significant increase in female representation within its teams and management, demonstrating that strides towards inclusivity are achievable with commitment and action.
Mar 08, 2022
2,118 words in the original blog post.
Goonjeta Malhotra, inspired by her brother, entered the hacking field and found success in bug bounties, emphasizing a methodical approach to identifying vulnerabilities. Her journey began with reporting simple bugs, but after refining her strategies, she achieved a significant $2,000 bounty for an Access Control issue. Malhotra appreciates the role of platforms like Detectify Crowdsource, which reward researchers for discovering unique vulnerabilities, benefiting companies by uncovering otherwise undetected issues. She advocates for more women in cybersecurity, highlighting organizations like the Women’s Society of Cyberjutsu for their supportive initiatives, and aspires to become a role model by achieving $1 million in bounties. Malhotra encourages a focus on learning and collaboration in the community, urging companies to support security researchers to create mutually beneficial relationships.
Mar 07, 2022
1,464 words in the original blog post.
Proactive External Attack Surface Management (EASM) is vital for organizations facing a growing threat landscape, as described by hacker Luke "hakluke" Stephens, who elucidates its implementation and potential pitfalls. EASM, a concept gaining traction, focuses on managing risks associated with digital assets rather than merely discovering them. The approach integrates with existing security processes, enhancing efficiency through automation and prioritization. Common mistakes include confusing EASM with asset discovery and viewing it as separate from other security tasks. Stephens emphasizes the importance of a comprehensive EASM program that encompasses discovery, assessment, prioritization, and remediation of risks. He warns against improper implementations that can lead to misinformation and highlights the need for continuous improvement in EASM programs. A well-executed EASM strategy can significantly enhance a security team's workflow, reduce their burden, and improve an organization's overall safety by proactively identifying and addressing vulnerabilities.
Mar 01, 2022
975 words in the original blog post.