Phishing – The Most Important Thing?
Phishing is still the number one way organizations get breached. Why technical controls alone do not stop it, and what a realistic test program looks like.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
115 posts
Phishing is still the number one way organizations get breached. Why technical controls alone do not stop it, and what a realistic test program looks like.
Read the post →TLS 1.0 through 1.3, what changed at each step, and why a scanner still complains about the old ones. A short guide to which versions to turn off, and when.
Read the post →WordPress runs a huge share of the web, which makes it a standing target. The updates, plugin hygiene, and access limits that prevent the common compromises.
Read the post →A flat network means one compromised host reaches everything. What belongs in a DMZ, what controls it needs, and how segmentation limits a breach.
Read the post →External attack surface management means finding what you expose to the internet before somebody else does. Why the inventory is always bigger than expected.
Read the post →Your scanner flagged an SSL certificate signed with a weak hashing algorithm. What that actually means, why SHA-1 fails, and how to replace the certificate.
Read the post →Data privacy is not the same as data security, and the difference matters when regulators ask. What personal data you hold, and the steps to protect it.
Read the post →If one vulnerability class deserves to be called a classic, injection is it. SQL, command, and cross-site scripting, why they persist, and how to stop them.
Read the post →Brackish researchers found authenticated stored XSS in several locations in TutorTrac 4.2.170210. Where the injection points were, and how to remediate them.
Read the post →The OWASP entry nobody notices is missing until an incident, when there is nothing to investigate with. What to log, what to watch, and free tools to start.
Read the post →