❌

Reading view

There are new articles available, click to refresh the page.

Keeping the threats at the edge

ISSUE 23.34 β€’ 2026-08-24 ON SECURITY By Susan Bradley It all started when I was assisting someone who was trying to determine whether their Wi-Fi mesh routers were operating at the best possible speed. I tried to log in to the Web-based interface to the mesh system, which indicated that browser access was disabled. Uh-oh. […]

Separating that network

ON SECURITY By Susan Bradley OpenAI’s recent attack on another company’s cloud instances reminds me that sometimes we forget the basics. As we understand the situation at the moment, OpenAI’s test platform was meant to be isolated and not connected to the Internet. But because it needed to download certain items, it was given read-only […]

Using the firewall in your router to secure your SOHO network

NETWORKING By Simon Bisson Small Office/Home Office (SOHO) routers are more secure than you think β€” although they could do with a little help from their friends. Way back when we used dial-up to connect to the Internet, software firewalls such as ZoneAlarm were all we needed to protect our PCs β€” because slow-speed connections […]

Bypassing WAFs Using Oversized Requests

Many web application firewalls (WAFs) can be bypassed by simply sending large amounts of extra data in the request body along with your payload. Most WAFs will only process requests up to a certain size limit. How the WAF is configured to handle these large requests determines exploitability, but some common WAFs will allow it by default.

The post Bypassing WAFs Using Oversized Requests appeared first on Black Hills Information Security, Inc..

Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed

Beau Bullock // If you have been even remotely in touch with technology in the past thirty years you have probably heard of this thing called a β€œfirewall”. If not, […]

The post Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed appeared first on Black Hills Information Security, Inc..

The New Security Fundamentals – Kill Your AV

John StrandΒ // AV is Dead Long Live Whitelisting. We have been discovering more and more of our tests bypass AV controls with ease.Β Β We have yet to see any iteration or […]

The post The New Security Fundamentals – Kill Your AV appeared first on Black Hills Information Security, Inc..

❌