OWASP Top Ten – Vulnerable and Outdated Components
Your application is mostly other people’s code, and that code ages. How outdated dependencies become the easiest route in, and how testing surfaces them.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
115 posts
Your application is mostly other people’s code, and that code ages. How outdated dependencies become the easiest route in, and how testing surfaces them.
Read the post →What a penetration test is, the types available, and what you actually get out of one. A plain introduction for businesses that have never commissioned one.
Read the post →Zero trust is not a product you buy. It is the assumption that nobody inside or outside your network is trusted until they prove who they are, every time.
Read the post →Default credentials turned up in five of our last five engagements, and several led straight to critical access. Why this keeps happening, and the fix.
Read the post →Passwords on a notepad, in a spreadsheet, or the same one everywhere. Here is why a password manager fixes the single habit attackers rely on most.
Read the post →