-
Podcast Jan 12, 2023
Root Causes 268: WAFs Subverted by JSON Bypass
Rising attacks can overcome the protections of Web Application Firewalls (WAF). We explain these attacks and what you should do to ensure you're safe.
-
Podcast Jan 19, 2022
Root Causes 200: Why Not to Copy and Paste Commands from Web Pages
This episode describes newly revealed vulnerabilities where copying and pasting text from a web page can open the site visitor up to attack.
-
Podcast Nov 02, 2021
Root Causes 185: EU Covid Passport Root Key Stolen
The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are for sale on the black market.
-
Podcast Oct 27, 2021
Root Causes 184: Popular College WiFi Vulnerability Revealed
Certificate misconfiguration in commonly used college WiFi can expose logins. We discuss WiFi authentication, EAP, and how this vulnerability occurs.
-
Podcast Oct 21, 2021
Root Causes 183: New MSCA Attack Toolkits
A new white paper and set of toolkits illuminate MSCA root key attacks. We provide a clear action list for IT professionals in charge of Microsoft CA.
-
Podcast Dec 14, 2020
Root Causes 135: The Heartbleed Vulnerability
2014's Heartbleed vulnerability made it possible to steal private keys directly from web servers, requiring certificate replacement by the millions.
-
Blog Post Oct 26, 2020
Those who don’t quite know the nuts and bolts of cybersecurity might use certain terms interchangeably. Logically, it makes sense in some cases. For example, a “vulnerability” sounds a lot like a “risk.” But in web security terms, they are not the same thing.
-
Blog Post Oct 16, 2020
But while the benefits of using a CMS for your website are very obvious, the drawbacks should come as a warning for anyone.
-
Blog Post Oct 12, 2020
Cybercriminals continue to find new, sneaky ways of attacking users. Why? Because it’s lucrative. The more successful attacks they can execute, the more money they can make.
-
Blog Post Oct 08, 2020
Visiting websites can spread viruses via exploit kits and vulnerabilities. Update software & use tools like SiteLock for protection.
-
Blog Post Oct 01, 2020
Malware left unaddressed for too long can cause customers to distrust you, kill your revenues, and damage your reputation in the industry.
If you see the signs of malware on your site, then you need to act fast to get rid of it before its impact is magnified.
-
Webinar Sep 18, 2020
Threat Visibility Is Vital to Website Health
Learn why threat visibility is a leading reason for targeted attacks, the 5 most common types of attacks and more with Michael Fowler and the Sectigo team.