AppCheck Security Blog

The Importance of Regular Vulnerability Scanning

In an earlier article we have covered the importance of vulnerability scanning and why it remains a powerful tool in your security arsenal – in this article we will examine specifically why it is important to leverage one of the most powerful advantages that dynamic application security testing (DAST) or vulnerability scanning has over manual penetration testing: its ability to be scheduled for frequent or continuous assessment.

read more

The Importance of Regular Vulnerability Scanning

In an earlier article we have covered the importance of vulnerability scanning and why it remains a powerful tool in your security arsenal – in this article we will examine specifically why it is important to leverage one of the most powerful advantages that dynamic application security testing (DAST) or vulnerability scanning has over manual penetration testing: its ability to be scheduled for frequent or continuous assessment.

Read more

Common e-commerce vulnerabilities and how to remedy

Modern e-commerce encompasses a broader network of activities and services relating to electronically buying or selling of products on online services or over the Internet. We explore common vulnerabilities that can occur within e-commerce sites and most importantly, how to remedy these.

Read more

The Great Database Heist: Where'd all my Data Just Go!?

This is a brand new session including all new content surrounding SQL and NoSQL Injection attacks, exploits and prevention techniques.

Read more

Got Swagger? How mapping your API helps to protect it.

API security is often barely mentioned. Web application developers are, broadly, aware of vulnerabilities such as the OWASP Top 10, but these barely or tangentially mention API security as of the latest (2017) update.

This may not have been an issue historically, however APIs are no longer a niche or secondary form of traffic. API calls now represent 83 percent of web traffic, according to traffic review detailed in a recent report.

Read more

Case Study - North East London NHS Foundation Trust

NELFT needed a cost effective vulnerability detection solution while ensuring high standards were in place surrounding cyber security.
See how AppCheck helped deliver that.

Read more

Security Testing in the Software Development Lifecycle (SDLC)

In this article, we’ll run through what software development typically looks like for enterprises in 2021, how security tools and processes can, are and should be integrated, and what features to look for to best leverage current approaches to support the development process.

Read more

The Great Database Heist: Where'd all my Data Just Go!?

This is a brand new session we are presenting for the first time including all new content surrounding SQL and NoSQL Injection attacks, exploits and prevention techniques.

Read more

SaltStack scanning tool to detect CVE-2020-11651 & CVE-2020-11652

These CVE's are now being actively exploited in the wild and so we have created a free standalone scanner to detect and report on these.

Read more

Critical Vulnerabilities in SaltStack CVE-2020-11651 & CVE-2020-11652

Vulnerabilities within SaltStack infrastructure automation software may lead to RCE attacks and full system takeover. According to security researchers who found these vulnerabilities, attacks are expected in the wild as soon as today.

Read more

Secure inclusion of third party content using SOP, CSP, SRI & CORS

In this article we’ll take a look at how the origin of resources loaded by your web application – such as third party JavaScript – can impact the security of your organisational and customer data.

Read more