FBI Warns of Dangers in 'Safe' Websites Criminals are using TLS certificates to convince users that fraudulent sites are worthy of their trust.
Cross-Site Scripting Errors Continue to Be Most Common Web App Flaw In vulnerability disclosure programs, organizations are paying more in total for XSS issues than any other vulnerability type, HackerOne says.
Suppliers Spotlighted After Breach of Border Agency Subcontractor Attackers increasingly use third-party service providers to bypass organizations' security. The theft of images from US Customs and Border Protection underscores the weakness suppliers can create.
Microsoft Issues Fixes for 88 Vulnerabilities Four of the flaws are publicly known but none have been listed as under active attack.
Getting Up to Speed on Magecart Greater awareness of how Magecart works will give your company a leg up on the growing threat from this online credit card skimmer. Here are four places to start.
'Have I Been Pwned' Is Up for Sale Troy Hunt, who has been running HIBP solo for six years, launched "Project Svalbard" so the site can evolve with more resources, funding, and support.