Practical security insights for teams without a SOC

No vendor fluff. No recycled threat reports. Real guidance on vulnerability scanning, malware, and attack surface management — written by practitioners.

o

Obaida Al-Sulaiman

Information Security Manager · CISSP · CEH · OSCP

Cross-site scripting (XSS) is a web application vulnerability that allows untrusted data to reach a browser in a context where the browser interprets it as executable code instead of ordinary content. The attacker does not need to compromise the browser itself. The vulnerable website delivers or processes the attacker-controlled content in a way that makes […]
A Magecart attack steals payment and personal data from ecommerce customers by compromising the website, its checkout code, or software that the page trusts. The best-known Magecart technique uses malicious JavaScript to watch a payment form in the customer’s browser, copy card data as it is entered, and send a stolen copy to attacker-controlled infrastructure […]
WordPress vs Drupal security is not as simple as comparing vulnerability counts. Drupal generally provides stronger security and governance defaults for complex, multi-user websites, especially around permissions, configuration management, and controlled deployments. WordPress core also has a mature security process and stronger native update automation, but its enormous plugin and theme ecosystem creates more third-party […]
A JavaScript npm supply chain attack targets the software and infrastructure between an npm package maintainer and the application that eventually installs that package. Instead of exploiting a flaw in your own JavaScript first, an attacker may compromise a trusted package, publish a lookalike dependency, abuse package resolution, steal publishing credentials, or execute malicious code […]
If you want to know how to scan JavaScript for vulnerabilities, do not rely on a single security check. A modern JavaScript application can contain weaknesses in the code your team writes, known vulnerabilities in npm dependencies, and security issues that appear only after the application runs in a browser. A useful JavaScript security assessment […]
Internet exposed services are applications, protocols, or management interfaces that can be reached from the public internet. A public website is intentionally exposed, while an administration panel, database, remote desktop service, or forgotten staging system may be exposed unintentionally. Exposure alone does not mean a service is vulnerable, but every reachable service gives an external […]
If you want to know how to scan an IP address for vulnerabilities, the process goes beyond checking whether a few ports are open. A proper assessment verifies the correct and authorized target, identifies reachable TCP and relevant UDP services, fingerprints the software behind them, runs vulnerability-specific checks, validates important findings, prioritizes confirmed weaknesses, applies […]
An IP vulnerability scan checks a specific IP address for security weaknesses that can be detected from the scanner’s location. It identifies reachable ports and services, gathers evidence about the software or configuration behind them, and checks that evidence for known vulnerabilities and security issues. This matters because internet-facing services remain an important route into […]
API security testing is the process of checking application programming interfaces for vulnerabilities, misconfigurations, authorization failures, unsafe input handling, and business-logic weaknesses before attackers can exploit them. Effective testing combines code analysis, dynamic scanning, fuzzing, specification-based testing, and human review across development and production. This guide explains what to test, which methods and tools to […]
By Obaida Al-Sulaiman, Information Security Manager (CISSP, GXPN, GWAPT). Reviewed September 2026. REST API security is the set of methods and controls that protect RESTful APIs from unauthorized access, data theft, and abuse. It spans authentication, authorization, encryption, rate limiting, inventory, and continuous testing. In Salt Security’s Q1 2025 survey, 99 percent of respondents said […]
API fuzzing is an automated security testing technique that floods your API endpoints with malformed, random, and unexpected inputs to find the bugs and vulnerabilities that normal testing never triggers. Instead of checking whether an endpoint returns the right answer for valid data, an API fuzzer asks what breaks when the data is wrong. This […]
An open ports security risk assessment is the process of finding every internet-facing port, identifying the service behind it, and scoring how likely an attacker is to exploit it. Not every open port is dangerous. Port 443 running patched HTTPS is fine. Port 3389 exposing Remote Desktop Protocol to the whole internet is not. This […]
Cross-site scripting (XSS) is a web application vulnerability that allows untrusted data to reach a browser in a context where the browser interprets it as executable code instead of ordinary content. The attacker does not need to compromise the browser itself. The vulnerable website delivers or processes the attacker-controlled content in a way that makes […]
A Magecart attack steals payment and personal data from ecommerce customers by compromising the website, its checkout code, or software that the page trusts. The best-known Magecart technique uses malicious JavaScript to watch a payment form in the customer’s browser, copy card data as it is entered, and send a stolen copy to attacker-controlled infrastructure […]
WordPress vs Drupal security is not as simple as comparing vulnerability counts. Drupal generally provides stronger security and governance defaults for complex, multi-user websites, especially around permissions, configuration management, and controlled deployments. WordPress core also has a mature security process and stronger native update automation, but its enormous plugin and theme ecosystem creates more third-party […]
A JavaScript npm supply chain attack targets the software and infrastructure between an npm package maintainer and the application that eventually installs that package. Instead of exploiting a flaw in your own JavaScript first, an attacker may compromise a trusted package, publish a lookalike dependency, abuse package resolution, steal publishing credentials, or execute malicious code […]
If you want to know how to scan JavaScript for vulnerabilities, do not rely on a single security check. A modern JavaScript application can contain weaknesses in the code your team writes, known vulnerabilities in npm dependencies, and security issues that appear only after the application runs in a browser. A useful JavaScript security assessment […]
If you want to know how to scan an IP address for vulnerabilities, the process goes beyond checking whether a few ports are open. A proper assessment verifies the correct and authorized target, identifies reachable TCP and relevant UDP services, fingerprints the software behind them, runs vulnerability-specific checks, validates important findings, prioritizes confirmed weaknesses, applies […]
An IP vulnerability scan checks a specific IP address for security weaknesses that can be detected from the scanner’s location. It identifies reachable ports and services, gathers evidence about the software or configuration behind them, and checks that evidence for known vulnerabilities and security issues. This matters because internet-facing services remain an important route into […]
API security testing is the process of checking application programming interfaces for vulnerabilities, misconfigurations, authorization failures, unsafe input handling, and business-logic weaknesses before attackers can exploit them. Effective testing combines code analysis, dynamic scanning, fuzzing, specification-based testing, and human review across development and production. This guide explains what to test, which methods and tools to […]
By Obaida Al-Sulaiman, Information Security Manager (CISSP, GXPN, GWAPT). Reviewed September 2026. REST API security is the set of methods and controls that protect RESTful APIs from unauthorized access, data theft, and abuse. It spans authentication, authorization, encryption, rate limiting, inventory, and continuous testing. In Salt Security’s Q1 2025 survey, 99 percent of respondents said […]
API fuzzing is an automated security testing technique that floods your API endpoints with malformed, random, and unexpected inputs to find the bugs and vulnerabilities that normal testing never triggers. Instead of checking whether an endpoint returns the right answer for valid data, an API fuzzer asks what breaks when the data is wrong. This […]
An open ports security risk assessment is the process of finding every internet-facing port, identifying the service behind it, and scoring how likely an attacker is to exploit it. Not every open port is dangerous. Port 443 running patched HTTPS is fine. Port 3389 exposing Remote Desktop Protocol to the whole internet is not. This […]
The port 445 vulnerability is the security risk of exposing Server Message Block (SMB) traffic, which runs over TCP port 445, to an untrusted network. Attackers target port 445 for wormable remote code execution, ransomware, and lateral movement, and it drove the 2017 WannaCry outbreak through the EternalBlue exploit. This guide covers the key CVEs, […]

Written by

o

Obaida Al-Sulaiman

Information Security Manager, Dubai

12+ years in information security. Specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations.

Browse by topic

New CVEs, practical guides, and scan methodology updates. One email per week. No sales pitch.
No spam. Unsubscribe any time. GDPR compliant.

Editorial standards: All ScanTitan blog content is reviewed by certified InfoSec professionals before publication. Technical claims are tested against live scan results or cited from primary sources (CVE database, OWASP, NIST NVD). We do not accept sponsored posts or paid placements.

Try a free scan

Run a free vulnerability scan on your domain. No account required.
Loading posts...