Patchstack’s cover photo
Patchstack

Patchstack

Computer and Network Security

Parnu, Province / State 7,576 followers

Patchstack helps web developers to easily secure web apps from third-party component vulnerabilities.

About us

Patchstack is the leader in open source software vulnerability intelligence, covering the entire lifecycle from detection to mitigation.

Website
https://patchstack.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Parnu, Province / State
Type
Privately Held
Founded
2021
Specialties
Website Security, Website Monitoring, Web Application Security, Web Application Monitoring, Cyber Security, Cyber Security Platform, Web Security Platform, and Website Security Platform

Locations

  • Primary

    Akadeemia 1, Forwardspace

    1

    Parnu, Province / State 80011, EE

    Get directions

Employees at Patchstack

Updates

  • Ready to protect the apps you've built with AI? It's time 👉 https://lnkd.in/emxfuMuq

    Most security tools available for the Javascript (and for most AI generated apps) are either built for software engineers or security teams. Today, we'll change that. We're opening early access to Patchstack for Lovable, Replit, Base44 and for any hosted NodeJS applications. Patchstack monitors the codebase for security vulnerabilities in real-time, performs reachability analysis and automatically mitigates exploitable security vulnerabilities without the need to upgrade packages, make any of the changes to the codebase and without having to rebuild the application. Without the fear of breaking the app. Additionally, it comes with Patchstack Live Hardening, which restricts the app from leaking out secrets, API keys and other sensitive information. Security must be easy not to be ignored, so you can use and control Patchstack directly where you're building your app - inside Lovable, Replit, Base44 and other AI builder workspace. For professionals, you get the security overview and full control over every application within the single dashboard, regardless where the app is built or hosted. We've been using this by ourself for a while, as like most companies today, our team too has has built many internal dashboards and apps to automate the day to day work. Patchstack is the user of Patchstack, and it has given us full visibility over what our team has built and confidence that it's all under control. Apply for early access here:

  • You’ve probably noticed more news about vulnerabilities, and attacks getting more frequent. Here’s Maciek Palmowski sharing our insights into what is happening: 👇

    View organization page for Community + Code

    89 followers

    Weeks. Then days. Then five hours. That's how fast a WordPress vulnerability has gone from "discovered" to "actively exploited," according to Patchstack's own numbers, and it's still getting faster. In today's episode of Community + Code, Maciek Palmowski explains why — and what happens when your bug bounty program gets flooded with AI-generated reports faster than your team can read them. Check out the episode here: https://lnkd.in/gntQVMMq

  • 📢Attention all plugin/theme vendors - we will now handle mandatory vulnerability incident reporting to the EU on your behalf: As of September 11, if you are selling your product to EU customers, you are required by law to report all exploited vulnerabilities and serious security incidents via the ENISA single-reporting platform. Or you can ask Patchstack to take care of this for you, for free: ➡️ Sign up for our free mVDP platform for plugin & theme devs ➡️ Request help with CRA Article 14 reporting ➡️ We help you set Patchstack as your "assigned representative" for ENISA reporting ➡️ From there on, we'll do what we've always been doing, but saving you the compliance headache in the process. A win-win. To get started, check the link in comments

    Today, EU Cyber Resilience Act Article 14 came into full power. Digital products (and software like WordPress plugins, etc.) that are made available to EU users must report known exploited vulnerabilities and severe security incidents to EU within 24 hours. Since at Patchstack we have coordinated 10K+ CVE's and already act as a security point of contact for over 1000 open source products - we decided to take a step further and entirely manage the CRA Article 14 for them. Due to our partnerships with the leading web hosting companies in the world and the accuracy and scale of Patchstack RapidMitigate – we are actually uniquely positioned to provide the fastest and most detailed known exploited vulnerabilities (KEVs) detection on the market. So, I'm excited to announce that open source maintainers who need to comply with the Article 14 can now user Patchstack to: - Get automatic vulnerability exploitation monitoring, evidence reporting and real-time alerts. - Completely automate Article 14 reporting where Patchstack acts as the Assigned Representative (AR) and submits the reports in time for compliance. - Next year, CRA will also require VDPs and a single-channel vulnerability reporting. That's already available as well. Oh, and it's all free. 🫡 https://lnkd.in/daG3Wb_3

  • View organization page for Patchstack

    7,576 followers

    "Why should I pay you 5,000... 10,000... 15,000 euros for a website when AI can build it?" Like most service providers these days, Sander Aavik from vDisain gets this question more frequently as of late. His team's response is the best response we've heard: They offer to build the AI version right there on the call... "You can tell me if that's what you want. If so, we can put it up for a fraction of the cost." Then the questions start. And after a real discovery conversation, most clients realize the cheap version isn't what they actually need. If your only value is assembly, you're increasingly at risk. But if the value you bring to the table is knowing what to build and why, you become the trusted partner to execute for your clients.

  • Yesterday, another WordPress core vulnerability dropped - the risk on this one is lower, we felt it's important to write about what it means for website owners. below👇 This vulnerability requires at least an 'Author' account, so it can't be used in the usual automated mass-scale attacks - but websites with a lot of guest writer or member accounts have a risk of targeted attacks. https://lnkd.in/d-mJ6AxX

  • Patchstack reposted this

    In the beginning of June, all WordPress websites stopped receiving updates for the first 24 hours for plugins that have released a new version. Everybody can see that the new version is available at the plugin repository, read through the code changes and see the changelog (e.g "important security fix - update now"). You could even install it to a fresh WordPress install, but on existing WordPress websites - updating was not possible. The goal of this change was to fight against supply chain attacks. Real issue that needs solving, however the implementation is highly questionable. We looked into how many supply chain attacks were stopped (or at least the blast radius reduced) vs how many security updates were kept behind a delay while the new version and the security patch in it was disclosed. By tracking the entire WordPress SVN and the WordPress updates API. We found evidence to 1 supply chain attack where updates were hold back that reduced blast radius. At the same time, 81 releases which patched a CVE were made public while at the same time being blocked to distribute the update to websites. Hackers have always launched attacks as fast as they could to hit as many websites as possible that had not yet been updated. In the WordPress ecosystem, last year it took an average of 5 hours for attacks to go start after a vulnerability was disclosed. Week ago, WordPress core vulnerability was actively exploited in 90 minutes. However, with that new WordPress supply chain protection (delayed yet disclosed updates) hackers can finally chill a bit - hopefully they will use this time to self-reflect. https://lnkd.in/dkhn2jVH

Similar pages

Browse jobs