InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Christmas in July - Critical vulnerabilities unwrapped

Presented by

Shubham Shah - SVP of Engineering & Research, Australia

About this talk

Nobody wants a zero-day disclosure just before Christmas! That’s why throughout July, Searchlight Cyber will be publishing a series of vulnerabilities - from pre-authentication command execution vulnerabilities to flaws affecting widely deployed enterprise web properties. Join us to learn how these bugs were identified, responsibly disclosed, and can be remediated. - Vulnerability #1: Persistent XSS on Adobe Experience Manager - Vulnerability #2: Pre-authentication vulnerabilities in DotNetNuke - Vulnerability #3: RCE in survey software Lighthouse Studio, - Vulnerability #4: RCE Vulnerability in ETQ Reliance - Vulnerability #5: Pre-auth vuln on Adobe Experience Manager Throughout July, we’ll reveal how we uncovered several high-impact vulnerabilities in widely used enterprise software. Shubham (Shubs), Searchlight’s SVP of Engineering & Research and prolific bug bounty hunter, will unpack these findings and demonstrate the methodologies and techniques used to identify these critical flaws.
Searchlight Cyber

Searchlight Cyber

2936 subscribers45 talks
Total attack surface visibility, from the surface to the dark web
Searchlight Cyber provides organizations with relevant and actionable threat intelligence, to help them identify and prevent criminal activity. Originally founded in 2017 with a mission to stop criminals acting with impunity on the dark web, we have been involved in some of the world’s largest dark web investigations and have the most comprehensive dataset based on proprietary techniques and ground-breaking academic research. The company has expanded and evolved, adding external threat management capabilities to create a Continuous Threat Exposure Management platform for organizations. Today we help government and law enforcement, enterprises, and managed security services providers around the world to identify threats and prevent attacks. About Assetnote Founded in 2018, Assetnote was born from the collective expertise of some of the leading minds in offensive security, and has grown to reflect the values and ability of our brain trust. Pioneering the Attack Surface Management category, Assetnote’s Continuous Exposure Management platform closes the gap between the attacker’s and defender’s perspectives with industry-leading real-time awareness of your evolving attack surface and the exploitable security exposure identified within. Monitoring millions of assets every hour for our customers, we are proud to be the chosen security platform for a wide array of organizations, from innovative startups to members of the Fortune 500, FTSE 100, and ASX 200. To find out more visit assetnote.io.
Related topics