Vulnerability Scanning

No vendor fluff. No recycled threat reports. Real guidance on vulnerability scanning, malware, and attack surface management — written by practitioners.

o

Obaida Al-Sulaiman

Information Security Manager · CISSP · CEH · OSCP

The Joomla vs WordPress security debate usually gets answered with loyalty, not evidence. The honest version is duller and more useful: both platforms ship a secure core, and both get breached through third-party code far more than through a core bug. Joomla bundles more security controls by default, while WordPress patches its core faster and […]
Joomla security features are one of the platform’s real advantages: the core ships controls that most content management systems leave to plugins. Out of the box you get two-factor authentication, granular access control, forced HTTPS, input filtering, and a dedicated Security Strike Team behind the code. This guide walks through every built-in feature Joomla 4, […]
Is Joomla secure? The honest answer is yes, with an asterisk. Joomla ships one of the more hardened cores in the CMS world, with two-factor authentication, granular access control, and a dedicated Security Strike Team built in. But no CMS keeps a neglected site safe. Most hacked Joomla sites fall to an outdated core, an […]
Joomla SQL injection is one of the oldest and most damaging ways an attacker takes over a Joomla site, and it is still live in 2026. A single unfiltered parameter can let an attacker read your database, dump password hashes, or forge an administrator session. Joomla core has been patched against several critical cases over […]
Threat Intelligence vs Vulnerability Management is one of the most common points of confusion in security, and the two are partners, not competitors. Vulnerability management is the internal discipline of finding, prioritizing, and fixing the weaknesses in your own systems. Threat intelligence is the external discipline of understanding attackers, their tools, and which flaws they […]
Learning How to Prioritize Vulnerability Remediation means deciding which security flaws to fix first based on the real risk they pose, not just their severity score. With scanners flagging thousands of findings and no team able to patch them all, prioritization is the decision layer that separates the handful of vulnerabilities attackers can actually exploit […]
Agentless vs Agent Based scanning is the central design choice in cloud security tooling. Agentless scanning assesses your cloud without installing a security sensor inside each workload, using cloud-native techniques such as APIs, snapshots, registries, and logs. Agent-based scanning deploys a sensor on the systems that need deep runtime visibility, watching activity from the inside. […]
Common cloud misconfigurations are security-relevant settings that leave cloud resources more exposed than intended, for example a public data store, an overly broad IAM role, an unrestricted management port, or logging that never reaches the security team. They are usually not zero-days. They are configuration, identity, network, and governance mistakes that can turn otherwise secure […]
A cloud security audit checklist is the structured list of domains and controls you review to confirm your cloud environment is configured, governed, and defended as your policies and obligations require. It spans asset inventory, identity, secrets, data protection, logging, network, configuration, change management, vulnerabilities, workloads, backup, incident response, third-party assurance, and governance, each backed […]
A cloud security scan is an automated assessment of cloud accounts, workloads, data, identities, and configuration settings that looks for vulnerabilities, insecure configurations, excessive permissions, exposed resources, and technical control gaps before an attacker finds them. Depending on the scanner and the integrations enabled, it may assess AWS, Azure, Google Cloud, virtual machines, containers, Kubernetes, […]
Knowing how to check the Drupal version of a website helps you answer a critical security question: does the site still receive security updates? An unsupported Drupal branch can continue running normally while accumulating publicly known vulnerabilities that will never receive an official patch, This guide explains three reliable ways to check the version of […]
Is Drupal secure? The honest answer is yes, with an important condition: Drupal provides a strong security foundation, but the security of a live website still depends on its version, contributed modules, custom code, permissions, hosting environment, and patching process.Drupal core is backed by a formal Security Team and a coordinated disclosure process. However, many […]
An open port in cyber security is a TCP or UDP port that is reachable and has a service accepting network traffic. Ports allow one device to reach a specific service on another, such as SSH on TCP port 22 or HTTPS on TCP port 443. Open ports are necessary for websites, email, DNS, remote […]
A use-after-free vulnerability happens when a program keeps using a piece of memory after it has already handed that memory back to the system. The leftover reference, called a dangling pointer, still points at the old spot. If an attacker manages to fill that spot with their own data, the program may read or run […]
The most common wordpress vulnerabilities almost never live in WordPress core. They hide in the plugins and themes you installed and forgot about. Security researchers logged 7,966 new WordPress vulnerabilities in 2024, and 96% of them sat in plugins, 4% in themes, and only seven in core itself. So the honest version of this guide […]
Knowing how to check if a WordPress plugin is safe before you install it is the single most useful security habit a site owner can build, because plugins, not WordPress itself, cause the overwhelming majority of hacks. A polished-looking plugin can still carry outdated code, an unpatched vulnerability, or in the worst case, deliberately malicious […]
Vulnerability management vs exposure management comes down to one question: are you fixing individual software flaws, or reducing everything an attacker could actually use to get in? Vulnerability management hunts and patches known CVEs. Exposure management is the wider discipline that also covers misconfigurations, exposed identities, shadow IT, and third-party risk, then prioritizes by real-world […]
Learning how to test for SQL injection vulnerability by hand is the fastest way to understand one of the most damaging flaws on the web: a single unescaped quote in a URL can hand an attacker your entire database. This guide walks you through the whole workflow, first testing manually with a handful of safe […]
The POODLE vulnerability is a design flaw in SSL 3.0 that lets a man-in-the-middle attacker decrypt small pieces of an encrypted session, one byte at a time, until they recover something valuable like your session cookie. Tracked as CVE-2014-3566 and disclosed by Google researchers in October 2014, it cannot be patched, because the weakness is […]
An SSL vulnerability is a weakness in the SSL/TLS protocol, its software implementation, or how it is configured that lets an attacker read, alter, or hijack traffic that is supposed to be encrypted. Despite the name, most of these flaws now live in TLS, SSL’s successor, but the label stuck. This guide defines what an […]
Can vulnerability scanning ensure NIS2 compliance? No, and any vendor promising otherwise is selling a false sense of safety. Vulnerability scanning is a required technical control under the NIS2 Directive (EU 2022/2555), but it satisfies only one of the ten risk-management measures in Article 21. Real compliance also demands board governance, 24-hour incident reporting, supply-chain […]
Active vs passive vulnerability scanning comes down to how the scanner looks for weaknesses. Active scanning sends probes and test traffic to your systems and reads the responses, going deep on specific assets. Passive scanning watches existing network traffic quietly, covering everything but only what the traffic reveals. One is a foot wide and a […]
To scan an API for vulnerabilities, you discover every endpoint, feed the scanner an OpenAPI or Swagger definition, authenticate it with the right API key, OAuth, or JWT token, run active and passive tests, then map each finding to the OWASP API Security Top 10 and retest after the fix. APIs cannot be crawled like […]
The difference between an authenticated scan and an unauthenticated scan comes down to one thing: whether the scanner logs in. An unauthenticated scan probes your system from the outside like an anonymous attacker; an authenticated scan uses valid credentials to inspect what sits behind the login. Authenticated scanning finds far more, but unauthenticated scanning shows […]
Continuous vulnerability scanning means your systems get checked for security weaknesses automatically and often, not once a quarter but every day and immediately after anything changes. To set up continuous vulnerability scanning, you discover and tag every asset, choose authenticated or unauthenticated scans, schedule them by risk, prioritize findings with CVSS and real exploit data, […]
A vulnerability assessment in cyber security is a systematic process that finds, ranks, and reports the security weaknesses across your websites, networks, and systems before an attacker exploits them. Think of it as a scheduled inspection of every door and window in your digital environment. This guide explains what a vulnerability assessment is, why it […]
Checking a website for vulnerabilities manually means testing it by hand, the way an attacker would, instead of relying only on an automated scanner. You probe inputs, read HTTP responses, inspect headers, and confirm each finding with real evidence. This guide walks you through How to Check Vulnerability of a Website Manually in seven repeatable […]
Knowing the types of website security vulnerabilities is the difference between fixing a flaw on your schedule and cleaning up a breach on the attacker’s. Most successful attacks do not use exotic zero-days; they exploit the same handful of well-documented weaknesses that appear on site after site. This guide breaks down the 12 most common […]
Choosing between vulnerability scanning vs penetration testing trips up a lot of teams, and picking the wrong one either wastes budget or leaves real holes open. A vulnerability scan is an automated, broad sweep that flags known weaknesses across your whole environment. A penetration test is a human-led, deep attack that proves which of those […]
Vulnerabilities in cyber security are weaknesses in software, hardware, configuration, or human process that an attacker can exploit to gain unauthorized access, steal data, or disrupt operations, and the problem keeps growing: the National Vulnerability Database logged more than 40,000 new CVEs in 2024, and Verizon’s Data Breach Investigations Report found that attackers exploiting vulnerabilities […]