Acunetix Blog, Blog
IIS Security Best Practices: How to Secure Your IIS Server | Acunetix
Learn how to harden IIS servers against misconfigurations, WebDAV exploits, and application-layer attacks. See how Acunetix validates IIS security.
Read MoreAcunetix Blog, Blog
Cookie Security Flags: How to Fix Misconfigured Cookies | Acunetix
Learn how to properly configure HttpOnly, Secure, and SameSite cookie flags. Protect against session hijacking and XSS with Acunetix.
Read MoreAcunetix Blog, Blog
SNI Proxy SSRF: Misconfigurations & Defense | Acunetix
Learn how SNI proxy misconfigurations can lead to SSRF attacks on AWS and Azure metadata services. See how Acunetix detects SSRF vulnerabilities.
Read MoreAcunetix Blog, Blog
What is an IDOR Vulnerability? | Acunetix
Learn what Insecure Direct Object References (IDOR) are and how Acunetix DAST can help prevent broken access control vulnerabilities.
Read MoreAcunetix Blog, Blog
REST API Security Testing: Complete Guide | Acunetix
Learn how to test REST APIs for vulnerabilities like BOLA, injection, and misconfigurations. See how Acunetix DAST automates API security testing.
Read MoreAcunetix Blog, Blog
Acunetix sunsets support for Windows 8 and Server 2012
Originally published by Acunetix. Acunetix Premium releases update 15.7 for Windows and Linux. This update will sunset support for Windows 8, Server 2012, and Server 2012 R2.
Read MoreAcunetix Blog, Blog
Acunetix releases a security check for Fortinet RCE flaw
Originally published by Acunetix. This update from Acunetix aims to enhance security measures by addressing a critical vulnerability in Fortinet’s network security solution. Users are encouraged to upgrade for improved protection against the identified RCE flaw.
Read MoreAcunetix Blog, Blog
Acunetix Premium Update for Windows and Linux: 15.4
Originally published by Acunetix. Server-side request forgery (SSRF) is the only type of vulnerability that has its own category in the OWASP Top 10 2021 list. Several major cybersecurity breaches in recent years involved the use of SSRF as one of the break-in techniques.
Read MoreAcunetix Blog, Invicti Blog, Resource
Enterprise Web Application Security Best Practices: How to Build a Successful AppSec Program | Invicti
Invicti offers AppSec coverage across your entire attack surface. We consider it a security best practice. Read more in Invicti’s whitepaper.
Read MoreAcunetix Blog, Resource
DevSecOps: How to get there from DevOps | Acunetix
Originally published by Acunetix. DevSecOps is a practice that merges the work done by development (Dev), security (Sec), and IT operations teams (Ops) to deliver the most efficient and effective software development practices. But why is it still so rare? Let us take a look at the difficulties of implementing DevSecOps and ways to eliminate them.
Read MoreAcunetix Blog, Resource
7 web application security best practices | Acunetix
Originally published by Acunetix. To maintain the best possible security posture and protect your sensitive data against cyberattacks, you cannot just rely on security products alone. Here is a list of seven key elements that we believe should be considered in your web app security strategy.
Read MoreAcunetix Blog, Blog, Invicti Blog
DAST, IAST, SCA: Deeper coverage in a single scan | Invicti
Originally published by Invicti. With Invicti SCA as part of your application security program, you can track and secure open-source components for deeper coverage in one single scan.
Read MoreAcunetix Blog, Blog
What is server-side request forgery (SSRF)? | Acunetix
Originally published by Acunetix. Server-side request forgery (SSRF) is the only type of vulnerability that has its own category in the OWASP Top 10 2021 list. Several major cybersecurity breaches in recent years involved the use of SSRF as one of the break-in techniques.
Read MoreAcunetix Blog, Blog
What is website security – how to protect your website from hacking | Acunetix
What is website security? How to protect your website? It is the security that protects websites from hacking.
Read MoreAcunetix Blog, Webinar
Invicti Webinar | How to prevent a Hacker Attack on your website
Join this special webinar to learn from Invicti experts on how to prevent a hacker attack on your website. Website hacking is a result from the adoption of web-based technologies for conducting e-business. Hackers attack these vulnerable websites for a number of reasons which can go from stealing sensitive information to SEO purposes.
Read MoreAcunetix Blog, Webinar
Invicti Webinar | What is IAST and How does it work?
Join this special webinar to discover What is IAST and How does it work. Our specialist will be covering how DAST Solution can maximise the scanning capabilities through the use of the IAST methodology/Component.
Read MoreAcunetix Blog
What is continuous web application security? | Acunetix
The term continuous security in the context of web application security is best understood when paired with well-known terms continuous integration and continuous deployment (CI/CD). Continuous security means that security is part of a continuous process – DevSecOps or, even better, SecDevOps.
Read MoreAcunetix Blog
What is HTTP header injection? | Acunetix
HTTP header injection is a technique that can be used to facilitate malicious attacks such as cross-site scripting, web cache poisoning, and more. These, in turn, may lead to information disclosure, use of your application in phishing attacks, and other severe consequences.
Read MoreAcunetix Blog
Integrating Acunetix with GitLab for CI/CD
HTTP header injection is a technique that can be used to facilitate malicious attacks such as cross-site scripting, web cache poisoning, and more. These, in turn, may lead to information disclosure, use of your application in phishing attacks, and other severe consequences.
Read MoreAcunetix Blog, Blog
5 reasons why every MSSP needs a professional web application security solution | Acunetix
Here are the 5 primary reasons why MSSPs need to include web application security in their service portfolio and why a professional web application security solution like Acunetix is the best choice as the basis of such services.
Read More