Company
Date Published
Author
Detectify
Word count
771
Language
-
Hacker News points
None

Summary

Research from Detectify, a SaaS security company, reveals a significant rise in subdomain takeovers, which have become more challenging to monitor due to increased vulnerabilities in domains. The study highlights a 25% increase in vulnerabilities detected in 2021 compared to 2020, with the median number of vulnerabilities per domain doubling. This surge underscores the importance of External Attack Surface Monitoring (EASM) tools in enhancing organizational security, as modern infrastructure's dependence on DNS for internal and third-party services expands attack surfaces and potential cyber threats. Subdomain takeovers occur when attackers exploit DNS misconfigurations to gain control over subdomains, posing risks such as data theft and phishing. Despite being pioneered by ethical hackers and highlighted by Detectify in 2014, this vulnerability remains prevalent, exacerbated by the rise of cloud solutions. Detectify's Surface Monitoring tool leverages a network of ethical hackers to monitor subdomains, detect vulnerabilities, and alert organizations to potential takeovers, emphasizing the necessity of maintaining a comprehensive subdomain inventory and deploying EASM tools to mitigate risks.