Penetration testing stories
A race condition vulnerability in nopCommerce gift cards lets attackers redeem the same card repeatedly, exploiting a flaw in the checkout process.
Zyxel Networks adopts CISA's Secure by Design Pledge, enhancing SMB networking security with MFA, unique passwords, and transparent vulnerability reporting worldwide.
LevelBlue's acquisition of Trustwave creates the world's largest pure-play managed security services provider, enhancing global cyber defence capabilities.
New research reveals 84% of fintechs lack robust API security, exposing sensitive payment data to significant cyber risks beyond regulated sectors.
LevelBlue will acquire Trustwave, creating the world's largest pure-play managed security services provider with enhanced global cybersecurity capabilities.
AI powers 80% of phishing attacks, causing USD $112 million in losses in India by May 2025, as cybercrime evolves with machine-generated deception.
Trustwave reveals a surge in AI-driven and ransomware attacks, with tech firms facing 85% of global ransomware incidents amid rising cyber threats.
A new report reveals a widening gap between AI innovation and enterprise security, with 36% of firms struggling to keep up with generative AI risks.
Over 80,000 Microsoft Entra ID accounts have been targeted in the UNK_SneakyStrike takeover campaign exploiting the TeamFiltration penetration testing tool.
LevelBlue will acquire Aon's Cybersecurity and IP consulting teams, including Stroz Friedberg, adding 300 experts and boosting global cyber defence services.
Audrey Adeline of SquareX warns the browser, where 80% of device time is spent, is the new cybersecurity battleground in an evolving threat landscape.
Cobalt updates its Offensive Security Platform to streamline pentesting with faster launches, real-time collaboration, clearer risk prioritisation, and workflow automation.
Retailers face a surge in cyber-attacks as weak defences and lapses in multi-factor authentication make them prime targets for criminals seeking valuable data.
Picus Security launches Exposure Validation, a tool using real-time attack simulations to identify which vulnerabilities are truly exploitable in organisations.
Qantas has revealed a cyberattack on a third-party call centre, exposing personal data of 5.7 million customers and raising serious security concerns.
Spectrum names Deane Jessep CTO to lead New Zealand's sovereign AI strategy, tackling cloud costs, data sovereignty, and AI governance in enterprise and government sectors.
e2e-assure and Validato have partnered to enhance cyber resilience in public sector organisations through continuous security validation and staff training.
Outpost24 is named the only European Overall Leader in the 2025 KuppingerCole report, advancing from Challenger to lead in Attack Surface Management.
Ekco has acquired Manchester cyber security firm Predatech, expanding its pen testing services and opening its first northern England office in the UK.
The Legal Aid Agency has suffered a major cyber-attack, exposing personal data of over two million individuals dating back to 2010 in England and Wales.