Penetration Testing and AppSec HTTP Security Headers: A Practical Guide for Businesses
HSTS, CSP, X-Frame-Options, Permissions-Policy, CORS and cookie flags - which security headers to implement, how to set them correctly and how to verify them.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Penetration Testing and AppSec HSTS, CSP, X-Frame-Options, Permissions-Policy, CORS and cookie flags - which security headers to implement, how to set them correctly and how to verify them.
Penetration Testing and AppSec Rapid Reset (CVE-2023-44487) leverages HTTP/2 multiplexing for record-breaking L7 attacks. We explain the stream mechanism, RST_STREAM and defense.
Penetration Testing and AppSec Pentest, audit and vulnerability scan are three different things, often confused. We explain how they differ, how much they cost and which service to choose for your situation.
Cloud, Infrastructure and DevSecOps Secure container images from Dockerfile and CI through signing, registries and runtime. Use this practical checklist for dependencies and deployment.
Cybersecurity History In 2014, a bug in OpenSSL allowed passwords and keys to be stolen from servers' memory - silently, without a trace. The story of Heartbleed, the era of "branded" vulnerabilities, and lessons about open source.
Penetration Testing and AppSec Before an attack lands, a criminal does reconnaissance. We show what OSINT reveals about your company and how to shrink your digital footprint.
Identity and Access A quantum computer will break RSA and ECC, and the "collect now, decrypt later" attack is underway today. We discuss ML-KEM, ML-DSA, hybrid modes and migration plan.
Penetration Testing and AppSec eBPF allows you to run programs in the Linux kernel without modules - it powers modern monitoring and networking, but can also be a rootkit tool. Technically and about hardening.
Threats and Incidents Black Kite reports disclosed ransomware in Europe rose 55% in 2026, with manufacturing the top target. What it means for companies across the EU.
Penetration Testing and AppSec A well-prepared penetration test delivers more value for the same money. How the process works, what to agree up front and how to read the report.
AI Security RAG connects LLMs to documents but adds prompt injection, data leakage and poisoning. Secure ingestion, retrieval, vector stores and model output.
AI Security AI agents carry out tasks, not just answer questions. Where agentic automation pays off, how to roll it out in stages and how to keep control.
AI Security AI incidents need evidence beyond classic breaches. Prepare response playbooks for prompt injection, data leaks, poisoning and agent tool abuse.
Cybersecurity History Kevin Mitnick was the world's most wanted hacker - and his weapons weren't exploits, but phones and psychology. A story of social engineering, an FBI chase and a second life.
Supply Chain Security Signing without key management (Sigstore) and verifiable build provenance (SLSA) are the new supply chain defense. We translate Fulcio, Rekor, cosign and SLSA levels.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.