Category: Mix

DOD's DIB-VDP Pilot Hits Six Month Milestone
27
Apr
2023

DOD’s DIB-VDP Pilot Hits Six Month Milestone

Six months into the 12-month pilot with the Department of Defense’s Defense Industrial Base Vulnerability Disclosure Pilot (DOD DIB-VDP Pilot),…

Nginx misconfigurations
27
Apr
2023

Common Nginx misconfigurations that leave your web server open to attack

Nginx is the web server powering one-third of all websites in the world. Detectify Crowdsource has detected some common Nginx…

The Evolution of HackerOne's Live Hacking Events
27
Apr
2023

The Evolution of HackerOne’s Live Hacking Events

If you’ve heard of HackerOne, then you’ve heard about our Live Hacking Events. For years, we’ve been bringing together the…

Detectify Security Updates for November 16
27
Apr
2023

Detectify Security Updates for November 16

Our Crowdsource ethical hacker community has been busy sending us security updates, including 0-day research. For Asset Monitoring, we now push out tests more…

Reflected Cross-Site Scripting in cPanel (CVE-2023-29489) – Assetnote
27
Apr
2023

Reflected Cross-Site Scripting in cPanel (CVE-2023-29489) – Assetnote

Summary A reflected cross-site scripting vulnerability can be exploited without any authentication in affected versions of cPanel. The XSS vulnerability…

How to Use Bug Bounty Program Data to Improve Security and Development
27
Apr
2023

How to Use Bug Bounty Program Data to Improve Security and Development

At HackerOne’s 2021 Security@ conference, two experienced HackerOne program managers, Allie Lugton and Denzel Duncan held a session on tracking…

ecommerce security scan
27
Apr
2023

How to “winterize” and secure your eCommerce website for the holidays

With online retailers and shoppers busy focusing on the upcoming holiday shopping season, cybercriminals are on the hunt for unsuspecting…

Finding XSS in a million websites (cPanel CVE-2023-29489) – Assetnote
27
Apr
2023

Finding XSS in a million websites (cPanel CVE-2023-29489) – Assetnote

cPanel is a web hosting control panel software that is deployed widely across the internet. To be exact, there are…

Bug Bounty vs. VDP | Which Program Is Right for You?
26
Apr
2023

Bug Bounty vs. VDP | Which Program Is Right for You?

What Are the Key Differences between Bug Bounty and VDPs? A VDP is a structured method for third parties, researchers,…

Tom Hudson: Continuously Hack Yourself
26
Apr
2023

Continuously Hack Yourself because WAF security is not enough

Have the WAF security companies got you thinking that a firewall is enough? In a modern landscape, development and security…

What Is a Bug Bounty? Should You Offer One? And How To Do It
26
Apr
2023

What Is a Bug Bounty? Should You Offer One? And How To Do It

What Is a Bug Bounty? A bug bounty is a reward offered by organizations to ethical hackers for discovering security…

Detectify security updates for November 30
26
Apr
2023

Detectify security updates for November 30

Our Crowdsource ethical hacker community has been busy sending us security updates, including 0-day research. For Asset Monitoring, we now push out tests more…