Home / Companies / Detectify / Blog / December 2023

December 2023 Summaries

4 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify experienced significant growth and development throughout 2023, marked by enhancements in its Attack Surface Custom Policies and recognition by influential analysts like Forrester and Gartner. The platform expanded its capabilities to include improved certificate and SSL/TLS assessments, as well as a more intuitive vulnerabilities page and scan management system. A major redesign of Detectify's website and blog improved user experience by offering easier navigation and better content display. The introduction of a new integrations platform and enhanced crawling capabilities allowed for more comprehensive vulnerability findings. Detectify also launched several new pages, including IP, Technologies, and Ports, which offer advanced filtering and insights into software composition evolution. Additional updates to its API and the newly launched changes.detectify.com ensured users received direct notifications about product updates. The company also released new research on the state of External Attack Surface Management (EASM) and published popular blog content and eBooks examining the differences between EASM, CAASM, and DRPS tools, as well as the impact of DAST and Pen Testing methodologies. Overall, Detectify's advancements in 2023 set the stage for continued innovation and customer engagement in the coming year.
Dec 19, 2023 1,048 words in the original blog post.
The "State of EASM 2023" report by Detectify provides insights into the state of attack surfaces across a diverse range of industries, highlighting the limitations of relying solely on established vulnerability frameworks like CVEs. The data from 235 companies across 30 countries reveal that most vulnerabilities identified do not have a CVE assigned, underscoring the need for organizations to prioritize threats based on accurate and context-specific assessments. The report emphasizes that security teams often focus on vulnerabilities without available exploits, missing significant threats, and stresses the importance of leveraging crowdsourced research for a more comprehensive security posture. Common vulnerabilities identified in 2023 include SSL/TLS Hostname Mismatch and SQL Injection, with the Banking & Financial Services and Public Sector industries experiencing the highest share of critical-severity vulnerabilities. Looking ahead to 2024, the report predicts a continued evolution in threat prioritization, increased reliance on high-fidelity findings, continued growth in crowdsourced research, and a need for ongoing market education to effectively integrate External Attack Surface Management (EASM) into existing security strategies.
Dec 18, 2023 664 words in the original blog post.
Detectify has introduced several enhancements to its attack surface management platform, focusing on improving visibility and interaction with fingerprinted technologies and overall attack surface data. The updates include new IP data, insights into covered and uncovered assets, and the ability to view and manage fingerprinted technologies by version. These changes aim to help users quickly respond to vulnerabilities and expand their attack surface coverage. Additional improvements include enhanced Surface Monitoring, updated Jira integration to avoid duplicate vulnerability imports, and new integration recipes for email and Slack notifications for newly discovered vulnerabilities and domains. A new parameter in the assets API endpoint now includes all subdomains in responses. Regular product release updates are available through a subscription to their blog notifications.
Dec 14, 2023 423 words in the original blog post.
Detectify offers an innovative solution for Application Security (AppSec) and Product Security (ProdSec) teams to effectively monitor and manage their expanding attack surfaces through a combination of Dynamic Application Security Testing (DAST) and External Attack Surface Management (EASM). By employing payload-based testing, Detectify enhances accuracy by only flagging vulnerabilities when the payload resolves on the customer's asset, mitigating the issue of false positives common with signature-based methods. This approach enables teams to proactively identify and address exposures such as subdomain takeovers or open ports within 24 hours, thus streamlining the remediation process. Detectify's comprehensive discovery engines and integration with third-party data sources like AWS Route 53 allow it to continuously update asset inventories, providing real-time alerts for new vulnerabilities or changes in the attack surface. This dynamic and expansive monitoring system makes it possible for central security teams to efficiently mitigate threats and maintain up-to-date security postures, ensuring that the attack surface is robustly covered and monitored.
Dec 05, 2023 672 words in the original blog post.