BSidesNoVA 2021 – Andy Piazza’s And James Nixon’s ‘Vendor Hacking: How To Make Your Tools Suck Less’

Our thanks to BSidesNoVA for publishing their outstanding videos on the organization’s YouTube channel.
Permalink
The post BSidesNoVA 2021 – Andy Piazza’s And James Nixon’s ‘Vendor Hacking: How To Make Your Tools Suck Less&#821… Continue reading BSidesNoVA 2021 – Andy Piazza’s And James Nixon’s ‘Vendor Hacking: How To Make Your Tools Suck Less’

BSidesNoVA 2021 – Opening Keynote Address

Our thanks to BSidesNoVA for publishing their outstanding videos on the organization’s YouTube channel.
Permalink
The post BSidesNoVA 2021 – Opening Keynote Address appeared first on Security Boulevard.
Continue reading BSidesNoVA 2021 – Opening Keynote Address

Malicious Redirects Through Bogus Plugin

Recently we have been seeing a rash of WordPress website compromises with attackers abusing the plugin upload functionality in the wp-admin dashboard to redirect visitors and website owners to malicious websites.
The payload is the following bogus plu… Continue reading Malicious Redirects Through Bogus Plugin

Password Attacks 101

According to the 2020 Data Breaches report by Verizon, 25% of all breaches involved the use of stolen credentials. And for small businesses, that number hit 30%. Brute force attacks have a similar share, accounting for 18% of all breaches, and 34% of … Continue reading Password Attacks 101

Server Side Scans and File Integrity Monitoring

When it comes to the ABCs of website security server side scans and file integrity monitoring are the “A” and “B”. In fact, our server side scanner is one of the most crucial tools in Sucuri’s arsenal. It’s paramount in maintaining an effective securi… Continue reading Server Side Scans and File Integrity Monitoring

WPScan Intro: How to Scan for WordPress Vulnerabilities

In this post, we look at how to use WPScan. The tool provides you a better understanding of your WordPress website and its vulnerabilities. Be sure to check out our post on installing WPScan to get started with the software.
Big Threats Come from Unex… Continue reading WPScan Intro: How to Scan for WordPress Vulnerabilities

Teaching Cybersecurity to Children

A new draft of an Australian educational curriculum proposes teaching children as young as five cybersecurity:

The proposed curriculum aims to teach five-year-old children — an age at which Australian kids first attend school — not to share information such as date of birth or full names with strangers, and that they should consult parents or guardians before entering personal information online.

Six-and-seven-year-olds will be taught how to use usernames and passwords, and the pitfalls of clicking on pop-up links to competitions.

By the time kids are in third and fourth grade, they’ll be taught how to identify the personal data that may be stored by online services, and how that can reveal their location or identity. Teachers will also discuss “the use of nicknames and why these are important when playing online games.”…

Continue reading Teaching Cybersecurity to Children

How to Find & Fix Mixed Content Issues with SSL / HTTPS

Note: We’ve updated this post to reflect the evolving security standards around mixed content, SSLs, and server access as a whole.
With the web’s increased emphasis on security, all sites should operate on HTTPS. Installing an SSL allows you to make t… Continue reading How to Find & Fix Mixed Content Issues with SSL / HTTPS

WordPress Continues to Fall Victim to Carding Attacks

Unsurprisingly, as WordPress continues to increase in popularity as an e-commerce platform, attackers continue to attempt to steal credit card information from unsuspecting clients. Currently, the WordPress plugin WooCommerce accounts for roughly a qu… Continue reading WordPress Continues to Fall Victim to Carding Attacks

How to Know If You Are Under DDoS Attack

Nowadays, the term DDoS probably raises the heart rate of most webmasters. Though many don’t know exactly what a DDoS attack is, they do know the effect: an extremely sluggish or shut-down website. 
In this article, we’ll focus on how to know if your … Continue reading How to Know If You Are Under DDoS Attack