Ridge Security announced the release of the latest version of its flagship product, RidgeBot 4.3.3, at the Black Hat 2024 conference. This update introduces a range of innovative features that significantly enhance the effectiveness of risk management in the cybersecurity area.
Integration with Tenable and Rapid7
One of the key elements of RidgeBot 4.3.3 is seamless integration with Tenable Vulnerability Management and Rapid7 InsightVM platforms via API. Thanks to this feature, RidgeBot can automatically retrieve data about assets and detected vulnerabilities from these systems, and then verify them using payload-based detection and exploitation. Leveraging the rich databases of leading vulnerability management platforms combined with active exploitation verification by RidgeBot helps security teams prioritize and address the most pressing threats, reducing workload and increasing efficiency.
📚 Read the complete guide: OT/ICS Security: Bezpieczeństwo systemów OT/ICS - różnice z IT, zagrożenia, praktyki
Risk Category Expansion
In version 4.3.3, RidgeBot expands the number of risk types from 5 to 10. New categories include:
-
Personal Identification Information (PII)
-
Account Takeover
-
Code Disclosure
-
Access and Authorization Violation
-
Data and Session Hijacking
These more detailed categories provide security teams with better visibility and faster ability to respond to threats.
New and Updated Plugins
RidgeBot 4.3.3 also introduces 36 new and updated plugins. Among them are new plugins for host and application detection, such as:
-
RCE in Apache HugeGraph-Server (CVE-2024-27348)
-
Path Traversal in SolarWinds Serv-U (CVE-2024-28995)
-
Eval Injection in OSGeo GeoServer GeoTools (CVE-2024-36401)
New detection and validation plugins include:
- Adobe Commerce and Magento XML Vulnerability (CVE-2024-34102)
Updated validation plugins include:
-
PyTorch TorchServe SSRF (CVE-2023-43654)
-
WordPress Royal Elementor Addons and Templates Unauthenticated Arbitrary File Upload (CVE-2023-5360)
-
WordPress Forminator Unauthenticated Arbitrary File Upload (CVE-2023-4596)
-
Fortinet SSL VPN Improper Authentication (CVE-2020-12812)
Summary
RidgeBot 4.3.3 is a significant step forward in the field of cybersecurity risk management. Integration with leading vulnerability management platforms, expansion of risk categories, and introduction of new and updated plugins make it an essential tool for any organization striving to increase its security level. RidgeBot 4.3.3 is already available for download, and detailed information about new features and fixes can be found in the included release notes.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- 0-Day Exploit — A 0-Day Exploit (zero-day exploit) is a security vulnerability in a computer…
- Threat Analysis — Threat Analysis is the process of identifying, evaluating, and prioritizing…
- CVE — CVE (Common Vulnerabilities and Exposures) is an international system for…
Learn More
Explore related articles in our knowledge base:
- Chained Exploitation of n8n: How RidgeBot Detects Workflow Takeover in Practice
- Cost Savings Through Automation with RidgeBot
- How Does Artificial Intelligence Think? Deep Analysis of the RidgeBot Engine
- Penetration Testing Automation with RidgeBot
- RidgeBot 6.0: AWS Security Audit and Advanced Windows Testing for Enterprises
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Explore Our Products
Solutions mentioned in this article that can help protect your organization:
- RidgeBot — Ridge Security
- Rapid7 InsightVM — Rapid7
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
