Everything You Ever Wanted to Know About Content Security Policy
CSP is a powerful XSS defense that is routinely misconfigured. How it works, a strict 2026 policy, and the bypasses you will actually run into.
Read the post →The latest security trends, threat analysis, testing methodology, and more — from the people doing the work.
111 posts
CSP is a powerful XSS defense that is routinely misconfigured. How it works, a strict 2026 policy, and the bypasses you will actually run into.
Read the post →CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →The HIPAA Security Rule overhaul slipped again, and the 240-day compliance window is the part nobody reads. Where the rule stands and what it will demand.
Read the post →One phishing simulation a year measures a single day with a single pretext. Why cadence beats the annual checkbox, and which metric is worth reporting.
Read the post →Bad grammar and generic greetings no longer identify a phishing email. The tells that still work: the ask itself, the channel, and unexplained urgency.
Read the post →Researchers documented JadePuffer, the first known ransomware attack run end to end by an AI agent. What it actually demonstrates, and what it does not.
Read the post →Every supplier you onboard makes their security part of yours. Five questions to ask before handing over a login, an integration, or a copy of your data.
Read the post →Someone walks past every firewall you own because a colleague held the door. Why physical security still decides breaches, and how testing exposes it.
Read the post →A video call from your boss authorising an urgent payment, except it is not her. A plain guide to deepfakes and the process changes that defeat them.
Read the post →Your staff already use AI tools you have not approved, exactly as they once used Dropbox. What is genuinely at risk, and why blocking it does not work.
Read the post →