Company
Date Published
Author
Detectify
Word count
468
Language
-
Hacker News points
None

Summary

Detectify's security updates, released every two weeks, incorporate new findings and improvements from its security researchers and the Crowdsource ethical hacker community to ensure its scanner tool remains current. Recent updates include the addition of tests addressing several vulnerabilities such as a Remote Code Execution (RCE) in Apache Struts, fingerprinting for exposed administration tools, and vulnerabilities in platforms like PrestaShop and Liferay. The updates also cover misconfigurations in technologies such as ACME and Socket.IO, which can lead to issues like clickjacking and session ID exposure, respectively. While not all updates can be disclosed due to confidentiality agreements, these vulnerabilities have been addressed and integrated into the Detectify scanner for immediate use by all users.