Category: Practical Security

  • The OWASP Top 10 Hasn’t Kept Up

    The OWASP Top 10 Hasn’t Kept Up

    The OWASP Top 10, the canonical list of web application security risks, has been a foundational reference for 20 years. The 2021 edition added four new categories. The 2025 edition is overdue. The categories do not adequately cover the threats that have emerged in the last 5 years: prompt injection, agent autonomy, training data poisoning,…

  • The Password Is Dying. The Passkey Is Not Winning.

    The Password Is Dying. The Passkey Is Not Winning.

    Every year for the last 10 years has been the year the password was going to die. The year has not arrived. The password is still the dominant authentication mechanism. The passkey, the technology that was supposed to replace it, is technically a complete success and is still stuck in adoption.

  • Why Your Vulnerability Scanner Is Missing the Vulnerabilities That Matter

    Why Your Vulnerability Scanner Is Missing the Vulnerabilities That Matter

    The vulnerability scanner is good at finding known CVEs. It is not good at finding the vulnerabilities that lead to breaches, which are misconfigurations, exposed credentials, over privileged identities, exposed secrets, and custom code. The scanner is a compliance tool that produces a 200 page report nobody reads. The actual security work is somewhere else.

  • The Browser Password Autofill Is the Weakest Link in Your Security Stack

    The Browser Password Autofill Is the Weakest Link in Your Security Stack

    The browser based password manager is, in 2026, the least secure password manager you can use. The autofill is the credential capture vector. The dedicated managers are better. The passkeys are best of all.

  • Microsoft Recall: One Year Later

    Microsoft Recall: One Year Later

    A 2026 deep-dive on Microsoft Recall: the original 2024 panic, the April 2025 redesign, the Hagenah TotalRecall Reloaded finding, the same-user malware…

  • The Cost of an API Key Leak in 2026

    The Cost of an API Key Leak in 2026

    The API key leak has become the breach pattern the developer does not take seriously, the pattern the attacker has been quietly exploiting for years, the pattern that has produced more production compromises in 2025-2026 than any other single root cause.

  • Why Your MFA Gets Bypassed Anyway

    Why Your MFA Gets Bypassed Anyway

    Multi factor authentication is the single most effective security control most organisations have ever deployed. It is also, in 2026, the security control most often bypassed in production attacks. The reason is that the threat model MFA was designed for is not the threat model the attacker uses today.

  • TWINLOOT: An Implant That Lives Inside Microsoft’s Cloud

    TWINLOOT: An Implant That Lives Inside Microsoft’s Cloud

    In July 2026, Ontinue recovered a Python-based implant framework running on a Windows endpoint inside a Microsoft 365 tenant. The implant hides its command channel inside SharePoint, tunnels interactive access over Microsoft Teams, and routes every API request through the victim’s own Edge browser.

  • The Antivirus Industry in 2026: A Buyer’s Guide for People Who Actually Read Reports

    The Antivirus Industry in 2026: A Buyer’s Guide for People Who Actually Read Reports

    A comparative review of the 2026 antivirus market: Norton, McAfee, Trend Micro, Kaspersky, Bitdefender, ESET, and Microsoft Defender, with lab data and a…

  • Your Password Manager Is Now Your Most Valuable Target

    Your Password Manager Is Now Your Most Valuable Target

    Every password manager breach in the last 5 years has confirmed the same thing. The vault is the target. Master password strength is now the only thing standing between your entire digital life and the attacker.