Blog, Identity and Access Management Blog, LOGON Blog
Inside the CoinDCX Breach: What Happened and How It Could Have Been Prevented
On July 19, 2025, CoinDCX—one of India’s largest cryptocurrency exchanges—confirmed a major security breach resulting in the loss of approximately $44 million (Rs. 378 Crore). While no customer funds were affected, the scale and sophistication of the attack raise critical questions about infrastructure-level security in the digital asset space. In this blog, we’ll break down what really happened, why it matters, and how the right security measures—like Privileged Access Management (PAM) and Multi-Factor Authentication (MFA)—can make all the difference.
Read MoreBlog, EAM Blog, Identity and Access Management Blog, LOGON Blog, Phishing Attack
Phishing 2.0 Bypasses Email Filters – Here’s How We Keep You Protected
In a rapidly evolving cyber threat landscape, phishing attacks continue to grow more sophisticated, leveraging novel techniques to bypass even the most advanced security measures. A recent phishing campaign has set off alarm bells, not just for its cleverness but for its ability to bypass traditional email security systems — even fooling Gmail completely.
Read MoreApplication Security Blog, Blog, LOGON Blog
DAST VS Manual Testing in Application Security
Many corporate stakeholders still hold the outdated belief that having an in-house (or third-party) pen tester running manual tests once or twice a year is a “complete security solution.” Manual Testing is Point-in-Time, Pen testing is typically scheduled quarterly, biannually, or annually. Dynamic Application Security Testing tools scan your running applications, as attackers would. They work continuously, detecting vulnerabilities as your application evolves — DevOps speed needs DevSecOps tools. DAST does not replace manual testing. Manual pen testing can find business logic flaws or complex chained exploits. DAST handles the routine, scalable, OWASP Top 10 kind of threats continuously.
Read MoreBlog, IT Management Blog, ITAM Blog, Lansweeper Blog, LOGON Blog
Review on Darknet Diaries Ep10: A Use Case for IT Asset Management in Government Cybersecurity
The recent episode of Darknet Diaries, a podcast on stories from the dark side of the internet, left a lasting impression regarding the Misadventures of a Nation State Actor (Episode 10). This episode tells a fictionalized but eerily realistic story of a nation-state actor attempting to infiltrate a foreign ministry’s network to steal highly classified data, displaying the cyber kill chain, from reconnaissance to weaponization, delivery, and beyond. What if that foreign ministry had ITAM Technology implemented?
Read MoreBlog, EASM Blog, LOGON Blog
Maximize your Cybersecurity ROI: Strategies for Smart Risk Prioritization
As businesses rapidly adopt new technologies, move to the cloud, and rely more on third-party vendors, they unknowingly expand their digital footprint. With that growth comes greater exposure to cyber threats, especially from unknown or unmanaged external assets. This is where External Attack Surface Management (EASM) steps in. It helps you find and secure what you didn’t even know existed.
Think of EASM as a live blueprint of your organization’s online presence, illuminating exposed assets such as servers, cloud applications, and forgotten domains. By continuously uncovering and prioritizing hidden risks, EASM empowers you to take proactive measures before adversaries know where to strike.
But here’s the real question: How do you ensure that your cybersecurity efforts actually deliver business value? The answer lies in risk prioritization, which, when done right, can drive real Return On Investment (ROI).
Read MoreApplication Security Blog, Artificial Intelligence, Blog, LOGON Blog
Integrate AI into Application Security Testing: Best Practices for Continuous Security
For most banking companies in the APAC region, digital transformation isn’t just a buzzword—it is their reality.
As a growing number of banks shift operations to the cloud, partner with innovative fintech providers, and enable a fully remote workforce, everything looks promising: scalable infrastructure, customer convenience, and operational agility. However, beneath this promising surface, security is struggling to keep up.
Read MoreBlog, ImmuniWeb Blog, Third-Party Risk
ImmuniWeb Launches an Advanced Third-Party Risk Management (TPRM) Solution
Originally published by ImmuniWeb. ImmuniWeb has launched ImmuniWeb® Discovery TPRM, providing an in-depth overview of vendor cyber risks and incidents, complementing our Cyber Threat Exposure Monitoring (CTEM) packages.
Read MoreBlog, EASM Blog, LOGON Blog
When Visibility Ends, Risk Begins: How A Bank Took Control of Its Digital Footprint with EASM
For most banking companies in the APAC region, digital transformation isn’t just a buzzword—it is their reality.
As a growing number of banks shift operations to the cloud, partner with innovative fintech providers, and enable a fully remote workforce, everything looks promising: scalable infrastructure, customer convenience, and operational agility. However, beneath this promising surface, security is struggling to keep up.
Read MoreBlog, Portswigger Blog
Q&A from The Future of AppSec Webinar | PortSwigger
Originally published by PortSwigger. Portswigger recently wrapped up their biggest-ever webinar, The Future of AppSec: PortSwigger’s Vision, with thousands of security professionals tuning in live; the questions came thick and fast. Q&A topics range from on-prem deployments of Burp Suite DAST to AI models and product roadmaps. Whether you’re curious about how Burp AI works behind the scenes, Burp Suite DAST support, or just wondering what’s next for Burp Suite, this Q&A is for you.
Read MoreBlog, Endpoint Security Blog, LOGON Blog, Patch Management Blog
Accelerating Patch Management: The 48-Hour Rule and NIST Guidelines
Learn about the “48-Hour Rule” of patch management, showing the urgency to address vulnerabilities before exploitation occurs. Organizations must implement strategies like real-time visibility, automation, and testing to ensure rapid and safe patch deployment. It also references NIST guidelines for effective patch management and stresses the importance of updating firmware to mitigate risks. LOGON Software Asia provides solutions that help organizations manage vulnerabilities proactively, with automation being key to staying ahead of cyber threats.
Read MoreApplication Security Blog, Blog, LOGON Blog, SaaS Procurement and Management Blog, Software License Management Blog
Navigating Hong Kong’s New Cybersecurity Law (CI Bill): What to Do Next
Learn about Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Bill ( the “CI Bill”), effective January 1, 2026. It mandates critical infrastructure operators to strengthen cybersecurity measures, report incidents, and comply with various obligations. Organizations should assess their status as critical operators, allocate resources, conduct gap analyses, and enhance cyber resilience. LOGON Software Asia offers tailored solutions and support to help businesses navigate these new regulations effectively.
Read MoreBlog, Identity and Access Management Blog, LOGON Blog
“Banana Bait” – Click the Links, Fall for Scams: How Hong Kong is Battling Cyber Scams with Smart Identity and Access Management
In response to a surge in cyber scams, Hong Kong has launched an innovative public awareness campaign featuring the “despicable banana” to educate residents about online threats. The campaign, titled “Click the Links, Fall for Scams!”, highlights the critical need for vigilance and the implementation of effective Identity and Access Management (IAM) solutions. With over 44,000 scam cases reported in 2024 alone, organizations must equip themselves with robust IAM strategies to safeguard sensitive information and combat the evolving threat landscape. LOGON Software Asia offers comprehensive IAM solutions designed to empower organizations in managing identities, controlling access, and enhancing overall security.
Read MoreBfore.AI Blog, Blog
AI-Based Predictive Security: Evolution & Benefits | Bfore.AI
Learn how AI-based predictive security stops attacks before they start. Discover PreCrime’s IoFAs and see how LOGON Software Asia can deploy this solution for your business.
Read MoreBlog, Reflectiz Blog
Reflectiz | New Research: The State of Web Exposure 2025
Originally published by Reflectiz. This groundbreaking research is comprehensive in scope, offering valuable web statistics that all online businesses should examine. It evaluates web risk exposure for the top 100 websites in each industry (by visitor count) using Reflectiz’s proprietary Exposure Rating system.
Read MoreBlog, ImmuniWeb Blog
Top 10 Cybersecurity, Cybercrime, Cyber Law & AI Predictions for 2025 | ImmuniWeb
Originally published by ImmuniWeb. After the successful launch of its Global Internet Security Statistics Center in November, ImmuniWeb’s cybersecurity experts and engineers, who currently serve over 1,000 enterprise customers from more than 50 countries, compiled their predictions for 2025 based on the firsthand practical experience over many years.
Read MoreBlog, InstallShield Blog, Revenera Blog
InstallShield 2024 R2 Now Available!
The InstallShield 2024 R1 version is now live, with new features and enhancements, including: Support for .NET Core Custom Actions; Ability to prevent multiple setup.exe executions ; Run a suite installation without downloading updates ; Hide property values in verbose log to protect sensitive data ; Enhanced database import wizard for SQL Scripts
Read MoreBlog, Endpoint Security Blog, LOGON Blog
ConvoC2: A Red Teamer’s Tool to Exploit Microsoft Teams for Remote Command Execution
On December 15, 2024, cybersecurity enthusiasts and professionals were introduced to ConvoC2, a stealthy Command-and-Control (C2) infrastructure tool tailored for Red Team operations. ConvoC2 reveals how cyber attackers can exploit trusted collaboration platforms like Microsoft Teams to execute system commands remotely on compromised systems. This innovative tool underscores the vulnerabilities within widely adopted collaboration tools, posing new security challenges for organizations.
Read MoreBlog, ISDecision Blog, UserLock
UserLock 12.2 Now Live | IS Decisions
Originally published by IS Decisions. Get early access to 2FA Push notifications with the all-new UserLock Push authentication app, now available in beta.
Read MoreBlog, Identity and Access Management Blog, LOGON Blog, Phishing Attack, Ransomware, Zero Trust Security Blog
The New Fileless Remcos RAT Malware
Cybercriminals are now leveraging an Excel vulnerability (CVE-2017-0199) in a recent phishing campaign to deliver a fileless variant of Remcos RAT. This malware allows attackers to remotely control infected systems and steal sensitive data by deploying the RAT directly into memory, bypassing traditional detection methods.
Read MoreBlog, InstallAnywhere Blog, Revenera Blog
InstallAnywhere 2024 Now Available!
The InstallShield 2024 R1 version is now live, with new features and enhancements, including: Support for .NET Core Custom Actions; Ability to prevent multiple setup.exe executions ; Run a suite installation without downloading updates ; Hide property values in verbose log to protect sensitive data ; Enhanced database import wizard for SQL Scripts
Read More