Home / Companies / Detectify / Blog / April 2022

April 2022 Summaries

3 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Users of the platform now have enhanced capabilities to understand and manage their online attack surfaces, with new insights such as the visibility of assets over time and their extent of exposure online. The platform allows users to toggle views between active and inactive assets, helping them determine which assets have been recently active. Users can now monitor the state of their attack surface, identifying whether domains have open ports, reachable IPs, or simply a resolving DNS record. A new feature enables manual triggering of autodiscovery on root assets, ensuring comprehensive visibility by identifying all publicly available subdomains, including legacy systems or forgotten pages. Additionally, users can manually add subdomains to root assets, improving coverage of their attack surface. Performance enhancements in port discovery and scanning have been implemented by integrating Masscan and nMap, reducing false positives and providing accurate information about open ports, which can now be filtered by specific ports. The platform emphasizes continuous coverage to address evolving security challenges, inviting users to review their assets and consider joining the team for further development opportunities.
Apr 29, 2022 583 words in the original blog post.
In a reflection on current cybersecurity challenges, David Jacoby, a seasoned white-hat hacker and co-founder of Sprinkler Security, highlights the evolving landscape of IT security, emphasizing the importance of integrating knowledge across various specialized interest groups like network segmentation and vulnerability management. With over 25 years in the field, Jacoby illustrates the persistent vulnerabilities in systems, including weak password practices and poor network segmentation, through real-life penetration tests. Despite advancements and increased collaboration between security researchers and companies, such as the expansion of the bug bounty community, Jacoby points out that organizations often overlook basic security measures, which can lead to significant breaches even without exploiting zero-day vulnerabilities. He underscores that protecting both external and internal networks is crucial, advocating for comprehensive strategies including system hardening and security awareness to mitigate risks posed by compromised devices and password reuse.
Apr 14, 2022 1,894 words in the original blog post.
Numerous vulnerabilities have recently been discovered in Spring, a widely-used Java Web app development framework from VMware, with notable ones being CVE-2022-22965 (Spring4Shell RCE) and CVE-2022-22963 (Spring Cloud Function RCE). Detectify has promptly responded by providing scanning modules for these vulnerabilities, initially for Surface Monitoring customers and later for Application Scanning users. The Spring Cloud Function vulnerability was patched shortly after disclosure, while Spring4Shell remains a critical 0-day issue, with its potential impact compared to the notorious Log4Shell vulnerability. Detectify employs various methods, such as payload-based scanning and fuzzing, to detect these vulnerabilities, emphasizing the importance of both source code assessment and black box analysis for comprehensive coverage. As these threats are reportedly being exploited, Detectify is actively developing and releasing new modules, advising customers to scan critical assets promptly, and offering a free trial for non-customers to start scanning immediately.
Apr 01, 2022 557 words in the original blog post.