## [The Metaphor Method: How We Penetration Tested an AI Agent Using Nothing But a Fairy Tale](/content/blog/penetration-tested-ai-agent/index.html)

Rakshit Singh | Sr. Offensive Security Consultant  No exploit code. No zero-day. No root access. Just plain English and a castle.  Environment AWS Bedrock AgentCore | OS: Debian GNU/Linux 12 (Bookworm) | Runtime: Python 3.12  There is a class of attack that does not appear in most threat models for AI systems. It does not [...]

## [THE BENEFITS OF USING SAST AND DAST TOGETHER](/content/blog/the-benefits-of-using-sast-and-dast-together/index.html)

Both static application security testing (SAST) and dynamic application security testing (DAST) are methodologies used to test the security of application environments. DAST is a black-box security testing method that tests applications from the outside-in. SAST is a white-box security testing method that tests applications from the inside-out. So, when cyber analysts are using SAST, [...]

## [THE BENEFITS OF WEB AND MOBILE APP PENETRATION TESTING](/content/blog/the-benefits-of-web-and-mobile-app-penetration-testing/index.html)

Mobile applications find many uses in the retail, finance, and health sectors. They’re always just one tap away, and they can include device-specific functionality, which web applications don’t have. One thing which they have in common with web apps, though, is a need to be very careful about their security. Penetration testing for mobile apps is [...]

## [HOW TO SPOT AN INSIDER THREAT](/content/blog/how-to-spot-an-insider-threat/index.html)

Most businesses are aware of the threats posed by external hackers or malicious actors to their business. Thousands—if not millions—of dollars are spent annually by these businesses to safeguard their network against unauthorized external access. However, most businesses do not invest as much effort or resources to guard against insider threats to their business. Insider [...]

## [WHAT MAKES SECURITY SYSTEMS VULNERABLE TO CYBER-ATTACKS?](/content/blog/what-makes-security-systems-vulnerable-to-cyber-attacks/index.html)

Everyone claims to have network security in place. This doesn’t mean that everyone has network security that works. Unverified, untested cybersecurity is better than none at all, but it isn’t enough. Many businesses are stuck in a system of protection that no longer works, if it ever did. Verizon’s 2018 Data Breach Investigations Report suggests that the [...]

## [2018 FACTS AND STATS ON THE STATE OF CYBERSECURITY](/content/blog/2018-facts-and-stats-on-the-state-of-cybersecurity/index.html)

2018 was a more expensive year for businesses that were victims of cyber-attacks compared to the previous years. Hackers and other malicious actors adopted innovative strategies for penetrating business networks and remaining undetected for longer periods. The 2018 cost of a data breach study conducted by the Ponemon Institute showed that there was a 2.2 percent increase [...]

## [INTEGRATION FLAWS IN APIS OFTEN RESULT IN SECURITY BREACHES](/content/blog/integration-flaws-in-apis-often-result-in-security-breaches/index.html)

Many companies regard API security issues as events that only happen to large businesses (250+ employees) like T-Mobile, and McDonalds. It’s true: cyberattacks are most frequently targeted toward companies that possess expansive quantities of data that can be stolen by using the least amount of effort. Even though corporations of that size manage to glide [...]

## [4 CYBERSECURITY TIPS TO HELP AFTER THE MARRIOTT DATA BREACH](/content/blog/4-cybersecurity-tips-to-help-after-the-marriott-data-breach/index.html)

Last week, it was revealed that the Starwood guest reservation system had been hacked, affecting 500 million guests. The Starwood chain is a subsidiary of Marriott International, and they are picking up the pieces of the breach, which dates back to 2014. Personal information of the 500 million guests have been compromised, including names, email [...]

## [HOW I NEARLY GOT HACKED VIA LINKEDIN MESSENGER BY MY NEW FRIEND](/content/blog/how-i-nearly-got-hacked-via-linkedin-messenger-by-my-new-friend/index.html)

On October 25th, I was contacted via LinkedIn Messenger by a new connection I had added five days earlier. The message was pertaining to a potential business opportunity. By reading the text and looking at the compensation offered to sit on a board of directors, I had already noticed something wrong; the compensation didn’t make [...]

## [HOW THE XMRIG TROJAN VIRUS SNEAKS ONTO YOUR COMPUTER SYSTEM](/content/blog/how-the-xmrig-trojan-virus-sneaks-onto-your-computer-system/index.html)

It’s difficult to know what is real and what is fake in the cyber world because most computer users are ignorant of ever-evolving threats. It’s not their fault because professional cybercriminals can mask their viruses, like Trojans. The XMRig CPU Miner is a Trojan Horse that many unsuspecting users install. It hijacks the user’s computer [...]
