Patchstack’s cover photo
Patchstack

Patchstack

Computer and Network Security

Parnu, Province / State 7,600 followers

Patchstack helps web developers to easily secure web apps from third-party component vulnerabilities.

About us

Patchstack is the leader in open source software vulnerability intelligence, covering the entire lifecycle from detection to mitigation.

Website
https://patchstack.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Parnu, Province / State
Type
Privately Held
Founded
2021
Specialties
Website Security, Website Monitoring, Web Application Security, Web Application Monitoring, Cyber Security, Cyber Security Platform, Web Security Platform, and Website Security Platform

Locations

  • Primary

    Akadeemia 1, Forwardspace

    1

    Parnu, Province / State 80011, EE

    Get directions

Employees at Patchstack

Updates

  • EmDash 1.0 released this week - so we built an app and ran it through our JS vulnerability tool 🥷 One simple to-do app, 744 dependencies, 1 exploitable XSS vulnerability. 🚨 We are releasing our mitigation features for vibecoded apps soon. Apply for early access in comments:

    EmDash hit 1.0 this week. Cloudflare's open source CMS for Astro. It's a lovely bit of work. Congrats Matt Kane and Matt Taylor They launched it as "the spiritual successor to WordPress that solves plugin security," citing our research twice to make the case. 96% of WordPress security issues start in plugins. They're right. Every plugin runs in its own sandbox and can only do what it declared it needs, which is exactly how it should have worked all along. So I built something with Em. One prompt. "Create a simple todo list site with em dash" 744 packages. One reachable, exploitable vulnerability sat there on day one. An XSS in dompurify, disclosed back in March. Zero plugins installed. Plugin security: solved. The other door was never locked. Thats not a dig at EmDash. Its the whole point. Sandboxing shuts the plugin vector and npm strolls in through the dependency tree, and no framework, CMS or AI builder on earth opts out of that. Same 6 month old advisory, brand new stack. And the industrys answer is still shift left. Scan the repo, raise a pull request, feel productive. Meanwhile the thing actually exposed is in production and time to exploit is down to hours. Patchstack for JavaScript starts where the danger is. Build with EmDash, build with Lovable, build with whatever launches next month. You stay protected on the live app while the vulnerable package is still sat there, and you update when youre ready rather than when the shit hits the fan. Safe the same way you when using Patchstack for WordPress Early access is open. Works just as well on EmDash as anything else in this new wave. 🔗 https://lnkd.in/ebsXcXtz

  • Ready to protect the apps you've built with AI? It's time 👉 https://lnkd.in/emxfuMuq

    Most security tools available for the Javascript (and for most AI generated apps) are either built for software engineers or security teams. Today, we'll change that. We're opening early access to Patchstack for Lovable, Replit, Base44 and for any hosted NodeJS applications. Patchstack monitors the codebase for security vulnerabilities in real-time, performs reachability analysis and automatically mitigates exploitable security vulnerabilities without the need to upgrade packages, make any of the changes to the codebase and without having to rebuild the application. Without the fear of breaking the app. Additionally, it comes with Patchstack Live Hardening, which restricts the app from leaking out secrets, API keys and other sensitive information. Security must be easy not to be ignored, so you can use and control Patchstack directly where you're building your app - inside Lovable, Replit, Base44 and other AI builder workspace. For professionals, you get the security overview and full control over every application within the single dashboard, regardless where the app is built or hosted. We've been using this by ourself for a while, as like most companies today, our team too has has built many internal dashboards and apps to automate the day to day work. Patchstack is the user of Patchstack, and it has given us full visibility over what our team has built and confidence that it's all under control. Apply for early access here:

  • You’ve probably noticed more news about vulnerabilities, and attacks getting more frequent. Here’s Maciek Palmowski sharing our insights into what is happening: 👇

    View organization page for Community + Code

    88 followers

    Weeks. Then days. Then five hours. That's how fast a WordPress vulnerability has gone from "discovered" to "actively exploited," according to Patchstack's own numbers, and it's still getting faster. In today's episode of Community + Code, Maciek Palmowski explains why — and what happens when your bug bounty program gets flooded with AI-generated reports faster than your team can read them. Check out the episode here: https://lnkd.in/gntQVMMq

  • 📢Attention all plugin/theme vendors - we will now handle mandatory vulnerability incident reporting to the EU on your behalf: As of September 11, if you are selling your product to EU customers, you are required by law to report all exploited vulnerabilities and serious security incidents via the ENISA single-reporting platform. Or you can ask Patchstack to take care of this for you, for free: ➡️ Sign up for our free mVDP platform for plugin & theme devs ➡️ Request help with CRA Article 14 reporting ➡️ We help you set Patchstack as your "assigned representative" for ENISA reporting ➡️ From there on, we'll do what we've always been doing, but saving you the compliance headache in the process. A win-win. To get started, check the link in comments

    Today, EU Cyber Resilience Act Article 14 came into full power. Digital products (and software like WordPress plugins, etc.) that are made available to EU users must report known exploited vulnerabilities and severe security incidents to EU within 24 hours. Since at Patchstack we have coordinated 10K+ CVE's and already act as a security point of contact for over 1000 open source products - we decided to take a step further and entirely manage the CRA Article 14 for them. Due to our partnerships with the leading web hosting companies in the world and the accuracy and scale of Patchstack RapidMitigate – we are actually uniquely positioned to provide the fastest and most detailed known exploited vulnerabilities (KEVs) detection on the market. So, I'm excited to announce that open source maintainers who need to comply with the Article 14 can now user Patchstack to: - Get automatic vulnerability exploitation monitoring, evidence reporting and real-time alerts. - Completely automate Article 14 reporting where Patchstack acts as the Assigned Representative (AR) and submits the reports in time for compliance. - Next year, CRA will also require VDPs and a single-channel vulnerability reporting. That's already available as well. Oh, and it's all free. 🫡 https://lnkd.in/daG3Wb_3

  • View organization page for Patchstack

    7,600 followers

    "Why should I pay you 5,000... 10,000... 15,000 euros for a website when AI can build it?" Like most service providers these days, Sander Aavik from vDisain gets this question more frequently as of late. His team's response is the best response we've heard: They offer to build the AI version right there on the call... "You can tell me if that's what you want. If so, we can put it up for a fraction of the cost." Then the questions start. And after a real discovery conversation, most clients realize the cheap version isn't what they actually need. If your only value is assembly, you're increasingly at risk. But if the value you bring to the table is knowing what to build and why, you become the trusted partner to execute for your clients.

  • Yesterday, another WordPress core vulnerability dropped - the risk on this one is lower, we felt it's important to write about what it means for website owners. below👇 This vulnerability requires at least an 'Author' account, so it can't be used in the usual automated mass-scale attacks - but websites with a lot of guest writer or member accounts have a risk of targeted attacks. https://lnkd.in/d-mJ6AxX

Similar pages

Browse jobs