Company
Date Published
Author
Detectify
Word count
457
Language
-
Hacker News points
None

Summary

Detectify regularly updates its security tool every two weeks to incorporate new findings and improvements from its security researchers and the Crowdsource ethical hacker community, though not all updates are publicly disclosed due to confidentiality. Recent enhancements include the addition of tests for NGINX Variable Disclosure and Cisco ASA Path Traversal vulnerabilities, which were reported through the Crowdsource platform. These updates highlight potential security threats, such as the ability to control innocent content on web pages or bypass authentication, inspired by new research like Portswigger's Practical Web Cache Poisoning. Detectify also emphasizes improving the accuracy of its tool to reduce false positives, based on customer feedback, and encourages users to start scans for the latest vulnerabilities.