Blog

Security design flaw in Storage by Zapier

Security design flaw in Storage by Zapier

Posted on 2020-08-05by alexeiin Vulnerability Disclosure


Recently, we discovered a design flaw in how Storage by Zapier was verifying authentication. This flaw could allow attackers to compromise other users’ data stored within Storage by Zapier if the victim mistakenly chose a weak key or a key that was already in use.

Continue reading
How could Twitter have stopped the attack? (Part 2)

How could Twitter have stopped the attack? (Part 2)

Posted on 2020-07-22by mattin Business Security, Social Engineering


Last week Twitter had a successful social engineering attack that pushed through a Bitcoin scam. The scam netted about $120k for the scammers, but for Twitter it caused huge damage to their brand with the news of this attack going around the world.

Continue reading
How could Twitter have stopped the attack? (Part 1)

How could Twitter have stopped the attack? (Part 1)

Posted on 2020-07-21by mattin Business Security, Social Engineering


Last week Twitter had a successful social engineering attack that pushed through a Bitcoin scam. The scam netted about $120k for the scammers, but for Twitter it caused huge damage to their brand with the news of this attack going around the world.

Continue reading
What do you learn from your security reviews?

What do you learn from your security reviews?

Posted on 2020-07-16by mattin Business Security


The results of the security review come in and they’re…let’s just say “less than ideal”. Vulnerabilities that could be used to break in, steal data, and potentially get the organisation in the news. Better fix those right away!

Continue reading
We just need to test this one project…but will I be secure?

We just need to test this one project…but will I be secure?

Posted on 2020-06-25by mattin Business Security


What is in scope for a penetration test will be tested and what isn’t in scope for a penetration test won’t be tested. Simple enough, right? The problem comes when the hackers don’t follow the same scope that the penetration testers follow.

Continue reading
Zoom’s lesson on responding to security issues

Zoom’s lesson on responding to security issues

Posted on 2020-06-09by mattin Business Security


When investigating software to use, I’ll inevitably have a look at their security record. What vulnerabilities have they had? Should I be worried?

Continue reading
Third party systems in your pentest

Third party systems in your pentest

Posted on 2020-05-21by mattin Business Security


What is in scope for a penetration test will be tested and what isn’t in scope for a penetration test won’t be tested. Simple enough, right? The problem comes when the hackers don’t follow the same scope that the penetration testers follow.

Continue reading
The security supply tree

The security supply tree

Posted on 2020-05-13by mattin Business Security


How many organisations have access to your customer data?

Continue reading
Business partnerships in infosec

Business partnerships in infosec

Posted on 2020-05-08by alexeiin Industry


Partnering with other business is a huge part of the Volkis business model. We spend significant effort finding, talking to, and proving our worth to potential partners. But why do we do it? It goes back one of our core principles:

Continue reading
How likely is it that you’ll be hacked?

How likely is it that you’ll be hacked?

Posted on 2020-04-29by mattin Business Security


There I was again, staring at the report. In each security issue in our penetration testing and compliance work we have our risk assessment rating which is a pretty simple process based on ISO 31000. You identify the risk, figure out the likelihood and impact, and then use the risk matrix to give it a risk rating. Although a fair few companies now have their own risk matrix which we are happy to use in our reports for them, our standard risk matrix looks like this:

Continue reading