Emerging Cyber Threats: Preparing Your Organization for the Future
Threats that were theoretical a few years ago are routine now. How the landscape has shifted, and the preparation that survives the next shift too.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
115 posts
Threats that were theoretical a few years ago are routine now. How the landscape has shifted, and the preparation that survives the next shift too.
Read the post →Cloud, mobile, remote work, and third parties expand what you expose without anyone deciding to. What attack surface management covers, and why it never stops.
Read the post →The TSA’s proposed rule puts pipeline, rail, and bus operators under real cybersecurity obligations. What it asks for, and where testing fits the requirements.
Read the post →Most testers fuzz badly: wrong wordlists, wrong extensions, no attention to responses. Our rules for fuzzing properly, plus a custom tool to get started.
Read the post →Default credentials are the shortest path from the outside to full control, and they are still everywhere. Where we find them, and how to hunt yours down.
Read the post →What penetration testing is, the main types, the misconceptions worth clearing up, and why doing it regularly changes what it is worth to you.
Read the post →Mobile apps write more to the log than their developers think. Reading iOS and Android logs to find the sensitive data an app leaks without meaning to.
Read the post →Badge cloning, tailgating, and unlocked comms rooms bypass every network control you own. What a physical penetration test covers, and why it gets skipped.
Read the post →Some testing you can genuinely do yourself on a tight budget. Where to start, which tools are worth learning, and the point at which you need an outside team.
Read the post →Source maps hand an attacker your original, unminified code including comments and endpoints. How to check whether yours are public, and what to do next.
Read the post →