Home / Companies / Detectify / Blog / January 2023

January 2023 Summaries

4 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Security teams are tasked with monitoring vast numbers of both known and unknown assets for vulnerabilities, making the management of asset characteristics challenging. To address this, enhancements have been made to the All Asset view, allowing users to pin, adjust, hide columns, and modify row density and pagination for a more tailored experience. Additionally, the Detectify web application scanner has been improved for faster vulnerability detection through enhanced crawling and fuzzing. New features include the ability to identify non-monitored assets, expanded search parameters for technologies, and the retention of recent filter settings. Furthermore, a list of new vulnerabilities sourced from ethical hackers has been added to the tool, enhancing the breadth of security coverage.
Jan 30, 2023 446 words in the original blog post.
External Attack Surface Management (EASM) is an emerging concept crucial for medium to large organizations to manage their internet-facing assets and potential vulnerabilities effectively. Many organizations may be unaware of some of their digital assets due to transitions to cloud services and the lack of subsequent asset management. EASM programs, like Detectify, automate asset discovery and vulnerability scanning, providing organizations with detailed insights into their digital landscape. They prioritize vulnerabilities by criticality, assisting security teams in focusing their efforts on the most pressing issues. Additionally, EASM solutions offer practical guidance for vulnerability remediation, bridging the gap between security teams and developers who might lack specific security expertise. Detectify exemplifies these capabilities by offering actionable intelligence that speaks both technical and security languages, underscoring the importance of EASM in safeguarding against malicious attacks. Organizations can explore these benefits through trials or demos of such solutions.
Jan 20, 2023 909 words in the original blog post.
The text critically examines the limitations of current vulnerability management systems, particularly focusing on the use of Common Vulnerabilities and Exposures (CVEs) and the Common Vulnerability Scoring System (CVSS). It argues that while CVEs provide a standardized way to identify and communicate about cybersecurity vulnerabilities, they do not account for specific business conditions or effectively prioritize risks, leading to incomplete security solutions. The CVSS scoring system is critiqued for its mathematical flaws, which result in misleading scores that may not accurately reflect the risk to an organization. Additionally, the proliferation of third-party plugins and the rapidly changing digital landscape exacerbate the challenge, as many vulnerabilities are underreported or not included in public patch lists. Research from Detectify highlights that as CVE scores increase, their relevance to modern application tech stacks decreases, indicating a disconnect between scoring and actual risk. The text suggests the need for a more comprehensive and context-aware approach to vulnerability management, emphasizing that a one-size-fits-all model like CVSS is insufficient for effective risk management. Detectify is working on developing a new framework that incorporates asset context and customer priorities to better address these challenges.
Jan 05, 2023 1,257 words in the original blog post.
Gunnar Andrews highlights the significance of External Attack Surface Management (EASM) for both organizations and ethical hackers, emphasizing its role in identifying and monitoring publicly exposed IT assets to mitigate vulnerabilities. EASM involves continuous assessment of assets for availability, vulnerabilities, and updates, which is crucial as an organization's attack surface expands. It addresses both persistent and ephemeral bugs, with the latter requiring swift detection due to their transient nature. Shadow IT assets and outdated software pose significant risks as they often lack regular updates and vulnerability testing. During acquisitions, the acquired company's assets may present additional security challenges, necessitating their integration into the EASM pipeline. Ethical hackers can leverage EASM techniques to enhance their bug bounty efforts by gathering valuable information such as domains, IP addresses, technologies, and monitoring changes in assets. This proactive approach helps organizations stay ahead of potential exploits by malicious attackers, underscoring the importance of adopting a hacker's mindset to safeguard digital assets effectively.
Jan 04, 2023 1,104 words in the original blog post.