Home / Companies / Detectify / Blog / May 2022

May 2022 Summaries

5 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Attackers employ various creative methods to steal information, exploiting an organization's digital attack surface, which has expanded beyond traditional firewalls and networks due to the increasing reliance on SaaS services. The attack surface comprises all publicly accessible web applications, including known and unknown assets, with external cloud assets being more frequently compromised than on-premises ones. The cost of data breaches has risen, particularly affecting organizations with less mature security postures, as attacks on web applications and phishing remain significant threats. To mitigate risks, organizations are encouraged to adopt external attack surface management (EASM) tools, monitor subdomains, and adhere to best practices for managing vulnerabilities. The integration of third-party services further complicates the attack surface, necessitating vigilant risk monitoring and management. Despite improvements in security practices, challenges persist, as evidenced by regulatory fines under the EU's GDPR and ongoing legislative efforts like the United States' "Better Cybercrime Metrics Act" to enhance cybercrime data collection. Automated tools are essential for maintaining a robust security posture and compliance in today's complex IT environments.
May 31, 2022 1,599 words in the original blog post.
Detectify has recently focused on enhancing its Vulnerabilities page by introducing new features and improvements. Users can now filter vulnerabilities based on criteria such as severity, domain, or specific vulnerability titles, allowing for prioritized remediation efforts. Bulk actions enable the management of up to 500 vulnerabilities simultaneously, streamlining status updates like marking them as "fixed" or "accepted risk." The REST API provides easy access to vulnerability information, facilitating integration with other tools. The platform now directs users to the Vulnerabilities page upon login, retiring the previous Dashboard for a more centralized view of findings from Surface Monitoring and Application Scanning. Surface Monitoring settings have been consolidated to the Root Assets page, and performance improvements have been made for customers with numerous open ports. Additionally, new vulnerabilities sourced from the ethical hacking community have been added, enhancing the platform's ability to identify and manage risks. Detectify is also expanding its team, seeking engineers, product managers, and sales professionals.
May 24, 2022 432 words in the original blog post.
Detectify's Hack Yourself event in Stockholm serves as a platform to explore the evolving field of External Attack Surface Management (EASM), a cybersecurity trend emphasized by Gartner in 2021. EASM focuses on identifying risks from internet-facing assets, highlighting a growing need for organizations to understand and manage these threats. The event revisits discussions from a previous gathering in 2021, featuring insights from IT Security Specialist Jesper Larsson, Sprinkler Security co-founder David Jacoby, and Detectify CEO Rickard Carlsson, who address current security practices and their shortcomings, such as the over-reliance on templates and lack of technical depth. They emphasize that security is not just a tooling issue but involves education, visibility, and cultural integration within organizations. Penetration testing remains a critical method for vulnerability detection, but it often lacks in scenario-specific assessments aligned with modern-risk frameworks. The event offers speaker sessions and panel discussions on EASM challenges, encouraging a security culture integrated with continuous development to combat the ever-expanding attack surface.
May 18, 2022 739 words in the original blog post.
Recent updates have introduced new filtering capabilities and expanded SSL assessments to enhance vulnerability management and attack surface monitoring. Users can now filter vulnerabilities by type, title, or CVE name, allowing for more efficient prioritization and remediation efforts. The ability to perform bulk actions on up to 500 vulnerabilities streamlines the management process, and filtering the attack surface view by open ports simplifies identifying security concerns. Additionally, SSL assessments have been integrated into Surface Monitoring, providing tests for vulnerabilities like CRIME, POODLE, BEAST, and FREAK. New medium, high, and critical severity modules from the ethical hacking community have been added to Surface Monitoring and Application Scanning, as detailed in the "What's New?" section. To meet evolving security challenges, continuous coverage is emphasized, and the company is currently hiring for various roles, including engineers and product managers.
May 10, 2022 456 words in the original blog post.
Hack Yourself London brought together ethical hackers, industry leaders, and IT security experts to discuss the expansion of attack surfaces and Gartner's top security trends for 2022. A key focus was on External Attack Surface Management (EASM), which involves continuous and automated oversight of external-facing enterprise assets to identify vulnerabilities, although it is not a replacement for traditional security methods like pen-testing. The event highlighted the importance of integrating security throughout the development lifecycle, as emphasized by Detectify's CEO Rickard Carlsson, who advocated for a 'shift right' approach to security within the DevSecOps framework. Phishing threats were also discussed, with evolving techniques like Browser in the Browser (BitB) attacks posing new challenges. Additionally, the event examined the OWASP Top 10's role in software security and the significant security risks associated with WordPress plugins due to poor update practices. The discussions underscored the need for comprehensive security strategies that incorporate advanced monitoring tools and community-driven projects to protect against an ever-changing threat landscape.
May 04, 2022 1,713 words in the original blog post.