Introducing Dynamic API Scanning
Application environments are more complex than ever, with APIs forming the critical connective tissue. But this proliferation has created a vast, often invisible, attack surface. …
Victor Arellano
The new attack surface overview puts the changes and potential risky exposures to your attack surface front and center. But that’s not all we’ve shipped in February. We’ve improved our Azure domain connector, simplifying onboarding for those users, and sent dozens of new vulnerability tests, such as CVE-2024-27199: TeamCity Authentication Bypass and CVE-2024-21893: Ivanti Connect Secure, Policy Secure SSRF.
Detectify continuously discovers and monitors customers’ attack surface for changes that could lead to potential risky exposures. Exposures include newly fingerprinted technology that may not be approved for use or even a cloud service provider that a user might not recognise. These exposures signal security practitioners to take steps to mitigate these risks that could lead to vulnerabilities. Detectify’s new overview now makes it possible for users to see changes to their attack surface over various periods, which will help spot risks and support post-incident investigations.
About 1 in 3 organizations today use at least two or more cloud providers to run their business (including Detectify). We know that getting the most out of Detectify means that users need a simple and efficient method to connect their DNS data to our platform to benefit from our continuous monitoring of their attack surface. Now, if you don’t provide any Subscription ID and give read access to the subscriptions, we will loop through all subscriptions and add all resources.
Want to learn about the tests we shipped? Here is a snapshot of a few new tests we shipped throughout February:
Read more about all of the vulnerability tests we shipped so far here.
We publish product release notes on this blog every few weeks. If you’d like to review the latest releases to Detectify as they are shipped, follow this link to sign up to get notified: https://changes.detectify.com/en.
Application environments are more complex than ever, with APIs forming the critical connective tissue. But this proliferation has created a vast, often invisible, attack surface. …
The average organization is missing testing 9 out of 10 of their complex web apps that are attacker-attractive targets. To address this, we’re launching new …