Company
Date Published
Author
Detectify
Word count
381
Language
-
Hacker News points
None

Summary

Detectify's Crowdsource ethical hacker community has been actively providing security updates, including 0-day research, which are promptly integrated into their scanner for user access, although confidentiality agreements prevent public disclosure of all updates. Recent vulnerabilities reported by the community include open redirect issues in Episerver Find, information disclosure in Gitlab via GraphQL, reflected XSS vulnerabilities in Aryanic HighMail CMS and WSO2 Management Console, and SSRF vulnerability in VMWare vRealize Operations Manager API. Additionally, the PHP "Zerodium" backdoor and RCE vulnerabilities in Adobe ColdFusion and F5 Big-IP iControl REST interface were also identified, enabling attackers to potentially gain full control of affected systems. These findings highlight the critical role of ethical hackers in identifying security flaws and enabling rapid response to protect digital assets.