Thank you for Subscribing to CIO Applications Weekly Brief

Detectify Witnesses Considerable Rise in the Number of Vulnerabilities Discovered Thanks to Its Crowdsource Community
Among the notable discoveries made by the Detectify Crowdsource community are:
By
CIO Applications | Tuesday, February 01, 2022

Accepted vulnerabilities were included in Detectify's products as security tests to protect clients from recent threats.
Fremont, CA: Among the notable discoveries made by the Detectify Crowdsource community are:
- Cloudkit - While hacking Cloudkit in September 2021, Detectify co-founder Frans Rosen discovered three serious issues in iCrowd+, Apple News, and Apple Shortcuts. The Apple Security Bounty program reported and resolved all flaws.
- Grafana 0-day - Grafana released an emergency security fix for major vulnerability CVE-2021-43798, following the publication of proof-of-concept code to exploit the problem online. Grafana was initially made aware of the 0-day by Jordy Versmissen, a Detectify Crowdsource security researcher who discovered and reported it to Grafana.
- Froxlor 0-day - Detectify Crowdsource hacker Valerio Brussani discovered and reported a 0-day in Froxlor - a server administration program - currently assigned as CVE-2020-29653, which might allow attackers to steal login credentials and impersonate a target user.
"Crowdsourced security provides a way for security teams to expand their efficiency, especially when it comes to managing their external attack surface," said Rickard Carlsson, Co-founder, and CEO of Detectify. "Hackers have eyes and ears all over the web, and they're constantly monitoring attack surfaces for exploitable entry points. Leveraging ethical hackers as part of an overall security program gives organizations the ability to identify and remediate security issues in a wide range of technologies before they risk being exploited by attackers."
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Detectify, a SaaS security startup driven by ethical hackers, ended 2021 with considerable corporate momentum, fueled by its Crowdsource community. Detectify discovered 44percent more unique middle - high severity vulnerabilities within the customers' systems in 2021 than in 2020, illustrating the outsized impact crowdsourced security would have on an organization's overall security.
The Crowdsource group, handpicked by Detectify, comprises freelance ethical hackers dedicated to making current technology and the Internet a safer environment. Each ethical hacker gets dedicated to discovering online vulnerabilities throughout the tech stack, such as in a CMS, framework, or library. Accepted vulnerabilities were included in Detectify's products as security tests to protect clients from recent threats.
More in News

