Why Whitelisting Security Controls Can Lead to a Better Penetration Test
When conducting a penetration test, being asked to whitelist a tester’s IP address from certain security controls might sound counterintuitive. After all, aren’t those controls there to protect the application? They are. But depending on the objective of the penetration test, leaving them in place can actually prevent testers from properly assessing the security of… Continue reading Why Whitelisting Security Controls Can Lead to a Better Penetration Test
Why Are We Still Finding XSS in 2026?
“What is the most common vulnerability you still find in 2026?” It is a question we ask our penetration testers regularly. While Cross-Site Scripting (XSS) may not necessarily be the most common vulnerability we find, it is one that continues to stand out — both because of its potential impact and because, with the maturity… Continue reading Why Are We Still Finding XSS in 2026?
What has changed in penetration testing over the last 12 months?
Without wishing to jump on the bandwagon, like the rest of the IT world it has to be the large scale adoption of generative AI in all parts of our industry, and even the whole online world. The proliferation in the security environment of AI products is impacting everything from the development and deployment cycle… Continue reading What has changed in penetration testing over the last 12 months?
Infostealers – The Risk Continues to Grow
Over recent years, Info stealer malware, also called infostealers, has grown as a formidable adversary for businesses worldwide, particularly in Australia. These malicious software programs are designed to infiltrate networks, stealthily collect sensitive data, and transfer it to cybercriminals who use it for financial gain, espionage, or other illicit activities. As Australian enterprises increasingly rely… Continue reading Infostealers – The Risk Continues to Grow
Building an Effective Cyber Security Plan
Building an effective cyber security strategy is no longer optional for medium to large businesses in today’s digital world. Businesses face an increasing threat to their systems, their data and criminal behaviour. Australian companies face not just local threats but a global spectrum of cyber risks, including data breaches, malware, ransomware, and phishing attacks. A… Continue reading Building an Effective Cyber Security Plan
Understanding Common Code Programming Issues Leading to Security Breaches
A great deal of focus when thinking about and or discussing security breaches is generally directed to issues with networks and or social engineering. In reality, many of these breaches stem from common issues in code writing. This blog explores different types of breaches, the potential damage each can inflict, and preventive measures that can… Continue reading Understanding Common Code Programming Issues Leading to Security Breaches
Embracing Zero Trust Security: A Strategic Imperative for Modern Businesses
Cyber threats are continuing to evolve, grow in sophistication and be more pervasive, causing traditional security measures to be no longer sufficient. This inadequacy has paved the way for the adoption of Zero Trust security strategies, a paradigm shift in how security is approached and implemented within organisations. Organisational adoption of Zero Trust security frameworks… Continue reading Embracing Zero Trust Security: A Strategic Imperative for Modern Businesses
The Rise of Info Stealer Malware: A Growing Threat to Businesses
Stealer malware, or information-stealing malware, is a type of malicious software designed to gather sensitive information typically targeting personal, financial, or business-related data. The data collected could include passwords, financial information, corporate data, and personal identification details. Once installed, this malware operates discreetly, often without triggering any noticeable alarms, making it particularly dangerous. The functionality… Continue reading The Rise of Info Stealer Malware: A Growing Threat to Businesses
Will AI Kill the Pen Testing Star
Those who use the different AI support technology available, are seeing a trend, that the results, generally speaking, produced by the tools are getting better every month. There is still the old computing issue of garbage in, garbage out, but as we learn to better seed the bots and the bots learn what data we… Continue reading Will AI Kill the Pen Testing Star
How AI is Impacting Cybersecurity and Penetration Testing
In the era of rapid technological advancement, the proliferation of AI platforms is revolutionising the way we interact with digital information, enhancing productivity, and streamlining decision-making processes. However, this same technology, designed to simplify and enrich our lives, is being weaponized by hackers and bad actors. These individuals exploit the capabilities of AI to orchestrate… Continue reading How AI is Impacting Cybersecurity and Penetration Testing









