Category: Mix

Detectify releases new and improved integrations
27
Apr
2023

Detectify releases new and improved integrations

Integrations are intended to make work and the flow of information smoother. In our case, the integrations expedite critical vulnerability…

[tl;dr sec] #179 - BSidesSF Summaries, Attacking Kubernetes, OpenAI + Burp Suite
27
Apr
2023

[tl;dr sec] #179 – BSidesSF Summaries, Attacking Kubernetes, OpenAI + Burp Suite

Hey there, I hope you’ve been doing well! Conference Montage I have some amusing anecdotes from BSidesSF and RSA that…

Jedox’s Journey with HackerOne: A Q&A with CTO, Vladislav Maličević
27
Apr
2023

Jedox’s Journey with HackerOne: A Q&A with CTO, Vladislav Maličević

Vladislav Maličević is the Chief Technology Officer at Jedox, a leading global provider of cloud-based enterprise performance management solutions for…

Web Cache Entanglement – Novel Pathways to Poisoning
27
Apr
2023

Web Cache Entanglement – Novel Pathways to Poisoning

Each year we anticipate new research from James Kettle at the annual Black Hat USA event and he’s become known…

Vulnerability Disclosure | What’s the Responsible Solution?
27
Apr
2023

Vulnerability Disclosure | What’s the Responsible Solution?

What Is a Vulnerability Disclosure? During a vulnerability disclosure, individuals report security weaknesses in computer systems to the organization. Disclosures…

Detectify security vulnerability scanning
27
Apr
2023

Discover latest security vulnerabilities in minutes with Detectify

25 minutes. That’s how long it took to bring high severity security vulnerabilities to Detectify  Asset Monitoring customers from the…

DOD's DIB-VDP Pilot Hits Six Month Milestone
27
Apr
2023

DOD’s DIB-VDP Pilot Hits Six Month Milestone

Six months into the 12-month pilot with the Department of Defense’s Defense Industrial Base Vulnerability Disclosure Pilot (DOD DIB-VDP Pilot),…

Nginx misconfigurations
27
Apr
2023

Common Nginx misconfigurations that leave your web server open to attack

Nginx is the web server powering one-third of all websites in the world. Detectify Crowdsource has detected some common Nginx…

The Evolution of HackerOne's Live Hacking Events
27
Apr
2023

The Evolution of HackerOne’s Live Hacking Events

If you’ve heard of HackerOne, then you’ve heard about our Live Hacking Events. For years, we’ve been bringing together the…

Detectify Security Updates for November 16
27
Apr
2023

Detectify Security Updates for November 16

Our Crowdsource ethical hacker community has been busy sending us security updates, including 0-day research. For Asset Monitoring, we now push out tests more…

Reflected Cross-Site Scripting in cPanel (CVE-2023-29489) – Assetnote
27
Apr
2023

Reflected Cross-Site Scripting in cPanel (CVE-2023-29489) – Assetnote

Summary A reflected cross-site scripting vulnerability can be exploited without any authentication in affected versions of cPanel. The XSS vulnerability…

How to Use Bug Bounty Program Data to Improve Security and Development
27
Apr
2023

How to Use Bug Bounty Program Data to Improve Security and Development

At HackerOne’s 2021 Security@ conference, two experienced HackerOne program managers, Allie Lugton and Denzel Duncan held a session on tracking…