Company
Date Published
Author
Detectify
Word count
315
Language
-
Hacker News points
None

Summary

Detectify releases bi-weekly security updates to ensure their tool remains current with the latest security findings, features, and improvements contributed by both their security researchers and the Detectify Crowdsource ethical hacker community. Although confidentiality agreements prevent the public release of all security updates, they are immediately integrated into the Detectify scanner for user access. Recent updates include addressing vulnerabilities in popular software such as WordPress plugins, specifically wp-backup-plus which can expose entire backups, and jQuery-File-Upload, which is frequently targeted for remote code execution exploits. Additionally, the update highlights the common issue of inadvertently uploading Thumbs.db and .DS_Store files, which store directory information and thumbnails, potentially exposing sensitive data. The release also notes ongoing work by Detectify researchers on existing vulnerabilities in Apache Struts, ensuring comprehensive and effective testing.