One cross-site scripting flaw is enough to take over a user account in AWS Cognito. How the attack works, what it achieves and what prevents it.
For this analysis of the Log4j attacks we evaluated the data from our own honeypots and servers. With Log4Shell, the first hours decide the outcome.
The IBM Cyber Security Intelligence Index attributes 95 percent of successful attacks to human error. What that means concretely for phishing, ransomware and the role of the people in an organisation.
From the voice assistant to the connected coffee machine: what connected devices do to the attack surface at home and at work, and where their security falls down.
A pentest, short for penetration test, is a simulated attack on a system, a network or a web application. This article sets out what one is, how it runs, and which types exist.
There are two main approaches to protecting systems and networks: offensive security and defensive security. This article looks at both, and at what blue teaming and red teaming actually mean.