Company
Date Published
Author
Detectify
Word count
240
Language
-
Hacker News points
None

Summary

Detectify, a security tool, releases major updates every two weeks to incorporate new findings and improvements from their security researchers and the Crowdsource ethical hacker community. While not all updates can be disclosed due to confidentiality agreements, they are promptly integrated into the scanner for all users. Recent enhancements include addressing several vulnerabilities reported by ethical hackers, such as the Adobe ColdFusion unrestricted file upload, Joomla! JCK-Editor SQL injection, and Atlassian Jira route-based authentication bypass. Other vulnerabilities included default credentials in Nexus Sonatype, DOM XSS in response-proxy, and reflected XSS in Ghost CMS. These updates ensure the Detectify scanner remains effective and up-to-date in identifying security threats.