HTTP/1.1 Must Die: What This Means for AppSec Leadership
Andrzej Matykiewicz | Wednesday, 6 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research, James Kettle, issued a stark warning: request smuggling isn’t…
Andrzej Matykiewicz | Wednesday, 6 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research, James Kettle, issued a stark warning: request smuggling isn’t…
Whether you’re troubleshooting a technical issue or performing a forensic investigation in your Okta Workforce Identity org, this article introduces a couple of new queries that can quickly get you…
When UltraViolet Cyber evaluated major trends across security threats in Q2, the landscape covered a lot of ground. Highly active threat actors, exploited vulnerabilities, ransomware operations, AI-driven social engineering, identity-based…
Amelia Coen | Wednesday, 27 August 2025 at 09:11 UTC In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair…
At Okta, prioritizing security at the earliest stages of technology development and throughout the Software Development Lifecycle (SDLC) is of utmost importance. This blog article introduces our new Secure Development…
This guide is designed for IT leaders, security professionals, and business decision-makers looking to evaluate some of the top cybersecurity companies and leading cybersecurity vendors in today’s rapidly evolving threat…
Andrzej Matykiewicz | Thursday, 28 August 2025 at 12:07 UTC Enterprise security teams are under more pressure than ever to secure sprawling application estates, without slowing down delivery. That’s why,…
This is the second blog publication in our series on Security Customer Trust. In our first blog, Unveiling the Essence of the Security Customer Trust Function, we explored how Okta’s…
Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress’s REST API and…
Attackers are repurposing an old spam evasion technique to bypass a new generation of AI-powered email security tools. Barracuda researchers say they have identified more than one million retail-themed phishing…