Company
Date Published
Author
Detectify
Word count
258
Language
-
Hacker News points
None

Summary

Detectify, a security tool provider, issues major updates every two weeks to ensure their scanner remains current with new findings and improvements from their security researchers and the Crowdsource ethical hacker community. While confidentiality agreements limit the public disclosure of these updates, users have immediate access to them. Recent enhancements to the Detectify scanner include tests for security vulnerabilities identified by the ethical hackers. Notably, these include the CVE-2020-11514 vulnerability in the WordPress SEO plugin Rank Math, which could allow unauthorized privilege escalation, and the CVE-2020-11455 vulnerability in LimeSurvey, which presented a path traversal risk. Additionally, a module has been added to check Atlassian Confluence instances for the public exposure of internal documentation, a concern that has become more significant as companies increasingly migrate online due to COVID-19.