Blog

Practical, no-hype articles on the security issues we scan for — what they are, how attackers actually use them, and how to fix them.

Hardening
HTTP security headers explained: the six that matter
What Content-Security-Policy, HSTS, X-Frame-Options and friends actually protect against — and how to deploy them without breaking your site.
Read →
DNS & infrastructure
Subdomain takeover: how a forgotten DNS record gets hijacked
A dangling CNAME to a deleted cloud resource lets an attacker publish content on your subdomain. How takeovers happen and how to prevent them.
Read →
Information disclosure
Exposed .git directories: how source code leaks from production
A deploy that copies your repository into the web root can expose its entire history — source, config, credentials. How attackers find and download it.
Read →
WordPress
How attackers find your vulnerable WordPress plugins
Most WordPress compromises start with an outdated plugin, not core. How version fingerprinting and user enumeration work, and the hardening that helps.
Read →
Web application security
CORS misconfiguration: when Allow-Origin becomes a data leak
Wildcard and reflected-origin CORS policies can hand authenticated API responses to any site a victim visits. The risky patterns and the correct configs.
Read →
Threat intelligence
Infostealer malware: stolen browser sessions that bypass MFA
Infostealers lift saved passwords and session cookies from infected browsers and sell them in bulk. Why MFA alone does not stop them — and what does.
Read →
DNS & infrastructure
Behind Cloudflare but still exposed: finding the origin IP
A WAF or CDN only protects traffic that goes through it. Certificate transparency, DNS history and stray records reveal origin servers every day.
Read →
TLS & encryption
Still serving TLS 1.0 or 1.1? What deprecated protocols cost you
Browsers dropped TLS 1.0 and 1.1 in 2020 and PCI DSS forbids them. What old protocol versions expose, how to check yours, and how to retire them safely.
Read →
Wondering how your own site scores on these checks? Run a scan with Cyber Report — external, non-intrusive, and free to start.