Home / Companies / Detectify / Blog / November 2025

November 2025 Summaries

8 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Applications have transitioned from monolithic to complex, cloud-native architectures, rendering traditional security testing methods obsolete. To keep up, Dynamic Application Security Testing (DAST) must evolve by revisiting the core fundamentals of black box testing: state, payloads, and assertions. Historically, application states were URL-driven, making it simpler to identify vulnerabilities, but modern architectures use actions and client-side changes that obscure state and technology stack. As payloads now often traverse multiple components, context-aware strategies are required to ensure they work across different systems. The need for modern black box testing to adapt is highlighted by the challenges of hidden tech stacks, delayed payload triggers, and noisy system behaviors, as seen in examples like the Log4j vulnerability. Detectify's approach includes innovations such as Dynamic Payload Rotation, which leverages machine learning to adaptively refine testing methods, ensuring they evolve alongside the applications they aim to protect.
Nov 28, 2025 848 words in the original blog post.
Holm Security and Detectify are compared in terms of how they assist AppSec teams with visibility, context, and application testing. Holm Security provides comprehensive coverage across various IT environments, utilizing a proprietary unified risk score for prioritized risk management, making it an effective tool for consolidated risk reporting. In contrast, Detectify specializes in External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST), focusing on external applications. Detectify's approach includes Asset Classification for scanning recommendations and 100% payload-based testing to ensure accurate results, thus minimizing validation time and effort. The comparison is based on feedback from prospective clients, former Holm Security users evaluating Detectify, and resources from Holm Security’s documentation and demos.
Nov 20, 2025 171 words in the original blog post.
CVE-2025-64446 is a critical authentication bypass vulnerability affecting Fortinet's Web Application Firewall, FortiWeb, which allows attackers to gain unauthorized administrative access by exploiting a flaw in the system's user impersonation mechanism. This vulnerability, with a CVSS score of 9.8, involves a combination of a Relative Path Traversal and a logic flaw that permits attackers to bypass standard login procedures and execute administrative commands, ultimately leading to the creation of persistent admin accounts. The flaw was exploited in the wild before a public patch was released, highlighting its zero-day status, and Fortinet has since issued security updates to address the issue. Users are advised to immediately apply these patches and review their administrative user lists for signs of compromise, while Detectify provides tools to test for the specific exploit conditions.
Nov 17, 2025 465 words in the original blog post.
The Detectify security research team explores CVE-2025-59287, a critical remote code execution vulnerability in Microsoft Windows Server Update Services (WSUS), caused by unsafe deserialization of untrusted data. This flaw allows attackers to exploit unauthenticated endpoints to execute arbitrary code with SYSTEM privileges, posing significant risks by targeting core update management infrastructure within enterprises. The vulnerability has a CVSS score of 9.8 and has been actively exploited to deploy malicious payloads like infostealers and pre-ransomware, threatening sensitive data, especially in regulated environments. The presence of public proof-of-concept exploits exacerbates the threat landscape, making it crucial for enterprises to apply vendor patches promptly. Detectify assists its customers by running payload-based assessments to identify this vulnerability, emphasizing the importance of proactive security measures.
Nov 14, 2025 381 words in the original blog post.
The review conducts a comparative analysis of two external security platforms, Halo Security and Detectify, through the lens of Application Security engineers, focusing on Visibility and Context, Assessment, and Usability. It explores how each platform discovers and classifies assets, their technical methodologies for identifying vulnerabilities, and evaluates the workflow and operational efficiency. The comparison is based on feedback from prospective clients and former Halo Security users considering Detectify, alongside information from Halo Security’s official resources, documentation, and publicly accessible demos.
Nov 14, 2025 118 words in the original blog post.
Alfred, an AI Agent developed to autonomously build security tests, has significantly transformed workflows by delivering over 450 validated tests against high-priority threats, with 70% requiring no manual adjustments, thereby allowing human security researchers to focus on more complex issues. Recently, Alfred's capabilities have been enhanced by integrating real-world threat actor intelligence directly into its core system, enabling it to prioritize and generate tests for actively weaponized CVEs, which speeds up and enhances the relevance of protection for Detectify customers. The initial vulnerability catalog used by Alfred focused on CVEs utilized by Advanced Persistent Threats and other active threat actors, but with the integration of active threat intelligence, Alfred now emphasizes CVEs actively exploited by malicious actors. The updated processing pipeline captures a broader scope of relevant CVEs, enhancing the likelihood of translating them into actionable security tests, and leverages the combined power of the Detectify Crowdsource community and the AI Researcher Alfred to continually deliver high-value security research.
Nov 10, 2025 324 words in the original blog post.
Application Security leaders and engineers face a choice between Rapid7 and Detectify, each representing distinct approaches to security management; Rapid7 offers a comprehensive, SOC-centric platform that integrates application flaws with infrastructure risks, while Detectify is tailored for the specific needs of external application security workflows. In assessing these platforms, the analysis considers their ability to provide visibility and discover attack surfaces, the effectiveness of their technical assessment engines, and their usability within modern remediation processes. The comparison draws on feedback from prospective clients, former Rapid7 users who evaluated Detectify, and resources including Rapid7's official website, documentation, and demos.
Nov 07, 2025 150 words in the original blog post.
Detectify and Invicti are two competing security platforms designed for vulnerability assessment and attack surface management, each with distinct approaches. Detectify utilizes a forward-thinking philosophy with a proprietary, payload-based scanning engine and a multi-source intelligence model powered by a community of elite ethical hackers and an AI researcher, allowing it to detect novel vulnerabilities that are not covered by CVE listings. On the other hand, Invicti relies on its "Proof-Based Scanning" engine, which verifies publicly known vulnerabilities but requires significant initial configuration time and does not address emerging, zero-day threats. These fundamental differences in their assessment philosophies influence the platforms' value, usability, and the workflow of application security teams, as highlighted through feedback from potential Invicti clients who have considered Detectify as an alternative, alongside information from Invicti's official resources and documentation.
Nov 03, 2025 180 words in the original blog post.