Home / Companies / Detectify / Blog / March 2025

March 2025 Summaries

3 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
A series of vulnerabilities, collectively termed IngressNightmare, have been identified in the ingress-nginx, a popular Kubernetes ingress controller, which can be exploited to inject configurations via the Validating Admission Controller, potentially allowing unauthorized access to sensitive data and complete cluster takeover. These vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) affect all versions of ingress-nginx but are remedied in versions 1.12.1 and 1.11.5. Detectify has released a vulnerability assessment tool to identify exposed Ingress NGINX admission controllers by analyzing TLS certificates, offering a reliable detection method due to the unique characteristics of Kubernetes' self-signed certificates. As mitigation, users are advised to upgrade to the latest patched versions or temporarily disable the Validating Admission Controller if immediate patching is not possible. The article also highlights that Detectify continues to provide updates in their product log and offers support and trial options for users seeking to enhance their security posture.
Mar 26, 2025 521 words in the original blog post.
The article explores the critical role of the Domain Name System (DNS) in modern cybersecurity, emphasizing its importance in managing the exposure of services to the internet. It discusses the potential risks associated with DNS mismanagement, such as subdomain takeovers and misconfigured DNS settings, which can pose significant security threats. The text highlights the complexity of DNS lookups, involving multiple components such as root servers, top-level domains (TLDs), registrars, and DNS providers, each with their own vulnerabilities. Real-world examples illustrate the potential for DNS-related security incidents, including BGP manipulation and errors in name server pointers. The article underscores the necessity of automation in DNS management to prevent misconfigurations and to monitor domain status effectively, stressing the need for organizations to adopt robust processes to safeguard their DNS infrastructure.
Mar 18, 2025 1,575 words in the original blog post.
Detectify has introduced Alfred, an AI-driven system designed to autonomously collect and prioritize threat intelligence, and generate security tests for the most exploitable Common Vulnerabilities and Exposures (CVEs). This innovation leverages large language models to process CVE details, prioritize vulnerabilities using the Exploit Prediction Scoring System (EPSS), and create payload-based exploits for integration into Detectify's platform, all while ensuring quality assurance. By automating these processes, Alfred allows Detectify's security researchers to focus on more advanced threats, enhancing the value for customers by providing faster and broader access to relevant CVE tests. Alfred operates alongside insights from Detectify's Crowdsource community and internal experts, offering an always-on, comprehensive security research tool that aims to reduce false positives and address vulnerabilities not covered by traditional CVE assessments. As a result, Detectify positions itself as a unique AppSec tool that combines AI research with ethical hacking expertise.
Mar 10, 2025 802 words in the original blog post.