Category: Mix

When Audits Fail: Four Critical Pre-Auth Vulnerabilities in TRUfusion Enterprise
30
Sep
2025

When Audits Fail: Four Critical Pre-Auth Vulnerabilities in TRUfusion Enterprise

In early 2025, we encountered a mission-critical software component called TRUfusion Enterprise on the perimeter of one of our customers…

How do I know I'm paying the right amount of bug bounty?
30
Sep
2025

How do I know I’m paying the right amount of bug bounty?

You asked, and we answered. At Intigriti, we’ve been paying close attention to the questions most frequently asked by those…

29
Sep
2025

Do Humans Really Have World Models?

I keep hearing that world models are the way forward for AI. I tend to agree, and have been saying…

29
Sep
2025

The Problem with Human 2.0 and the Promise of Human 3.0

So here’s what I’ve been thinking about lately. We’ve got 8 billion people on this planet, right? And maybe—maybe—0.01% of…

Hunting for SSRF vulnerabilities in Next.js targets
28
Sep
2025

Hunting for SSRF vulnerabilities in Next.js targets

Next.js is a powerful open-source React framework that enables developers to build fast, interactive, and SEO-friendly web applications. With almost…

Product comparison: Detectify vs. Nessus
26
Sep
2025

Product comparison: Detectify vs. Nessus

Nessus Pros Authenticated scanning of internal assets (workstations, network devices). Widely accepted for compliance and audit reporting (e.g., PCI DSS)….

Product comparison: Detectify vs. Burp Enterprise
26
Sep
2025

Product comparison: Detectify vs. Burp Enterprise

Burp Enterprise Pros: Offers granular control and customization to fit the distinct needs of a mature security program. Empowers expert…

Product update: Dynamic API Scanning, Recommendations and Classifications, and more
26
Sep
2025

Product update: Dynamic API Scanning, Recommendations and Classifications, and more

We know the importance of staying ahead of threats. At Detectify, we’re committed to providing you with the tools you…

AI agents building security tests
25
Sep
2025

AI agents building security tests

The Detectify AI Agent Alfred fully automates the creation of security tests for new vulnerabilities, from research to a merge…

[tl;dr sec] #298 - Good CISO / Bad CISO, AWS Infra Canarytokens, Protect Yourself from Compromised NPM Packages
25
Sep
2025

[tl;dr sec] #298 – Good CISO / Bad CISO, AWS Infra Canarytokens, Protect Yourself from Compromised NPM Packages

How to be an effective CISO, deploy decoy assets that fit in to your AWS environment, tips and tools to…

25
Sep
2025

AJ Debole on the Business-Tech Divide, Breach Readiness, and AI Risks — API Security

AJ Debole is Field CISO at Oracle, but her journey began far from the corporate boardroom. After starting out in…

AI Comprehension Gaps: When Humans and AI See Different Things: · Joseph Thacker
25
Sep
2025

AI Comprehension Gaps: When Humans and AI See Different Things: · Joseph Thacker

There’s an AI Security and Safety concept that I’m calling an “AI Comprehension Gap.” It’s a bit of a mouthful,…