Articles by phewadm

OWASP AISVS: The AI Security Standard the Industry Has Been Missing

On 24 June 2026, OWASP released version 1.0 of the Artificial Intelligence Security Verification Standard, AISVS for short, and for those of us who test web applications (and increasingly the AI features bolted onto them) this is the standard we have been waiting for. Until recently, testing an AI-enabled feature meant improvising. Testers could borrow adjacent controls from the OWASP Application Security Verification Standard (ASVS), lean on the OWASP Top 10 for LLM Applications for a sense of the risk landscape, and draw techniques and methodology from the AI Testing Guide that OWASP published in late 2025. But the rest

Read More

LastPass Breach (2H22) – FAQ

Background & Summary LastPass released information on 22 December 2022 confirming that a threat actor had accessed backups of LastPass user vaults along with associated metadata likely connecting those vaults with customer identities.  Technically this was a further update on previous partial disclosures, indicating that a breach in August 2022 was worse than they had initially thought (or let on). This is a bad headline for LastPass and its users, but the potential for an encrypted password vault to fall into the wrong hands is something that modern password managers are designed to be robust to. Information is still scant,

Read More

Was Kaseya A Supply-Chain Attack, And Why Does It Matter?

If the Kaseya attack was a “supply-chain attack” in terms of the industry accepted definition then it is a stretch of that definition. The distinction is important, because software supply-chain compromises are harder for customers of software solutions to detect using usual defensive measures, and generally involve exploitation techniques that fall outside the scope of web application penetration testing standards. So there is a feeling that essentially no blame rests with the software customer, and perhaps reduced blame rests with the software vendor. In this post we explore the implications for Kaseya of mis-categorising this attack as a supply-chain attack.

Read More

Cert NZ Quarterly Update Q1 2021

What’s New? Cert NZ has released its first quarterly report for 2021. The Cert NZ reports provide an interesting snapshot of recent cyber security incidents reported by both individuals and organisations in New Zealand. The latest report shows that a total of 1,431 incident reports were made to CERT NZ in the first quarter of 2021, involving losses of almost $3 million. Notable Increases Reports of ‘unauthorised access’ increased significantly this quarter. Unauthorised access involves an attacker gaining access to an account without your knowledge. Often this happens because of weak passwords, or login credentials that have been leaked in

Read More

Additional Steps For Sophos Central Installations on MacOS 11 BigSur

Additional Steps For Sophos Central Installations on MacOS 11 BigSur   MacOS 11 Big Sur requires additional System Extension permissions beyond what is detailed in Additional Steps For Sophos Central Installations on MacOS 10.15 Catalina.  Apple has enforced these permissions, and they no longer be added automatically by software vendors such as Sophos. Important: If the System Extensions are not allowed, Sophos Central protections will not function properly, in spite of the Sophos Central application being installed. If the Full Disk Access permissions are not added, malware scanning will not function properly. Without Proxy permission, Web Protection cannot function. During

Read More

Pen-testing: The What, Why and How

Online Security Online apps and tools have become an integral part of how we live and work. If you own or run one of these systems, you will be aware of the constant threat of a cyberattack, and the risks this poses to your business. If you use cloud services you should also be aware of the assumptions you are making about the security of those services, or have a basis for trusting the security assertions the vendor is making. Regular, pre-emptive penetration testing (or “pen-testing”) can mitigate these risks, provide knowledge and confidence, and improve the security and privacy

Read More

Spotting Covid-19 Scams

As you might expect, the bad guys are trying to use the global Covid-19 pandemic for malicious purposes.  The hunger for information, plus the disruption from half the world going into lock-down, perhaps combined with increased receptiveness to community support, all make this a pandemic rich and morally decrepit online hunting ground. The purpose of this post is not to add fear or reduce receptiveness to (online) community support.  But we do think it is important to know what sorts of things are going on, and to be on the look-out for them, particularly in this early period where everything

Read More

Should I Download this Application or Update?

Sometimes you might get something prompting you, on your desktop or laptop computer, to download or update an application.  The question is, should you, and (here’s a clue) why not? The general rule is: don’t accept an offer to do something you weren’t otherwise trying to do. There, just carry that rule around and you will be safe from this category of attacks.   But for those who want a bit more detail, here are some of the layers below that general maxim: Don’t download any application that you didn’t go looking for If something pops up anywhere offering you

Read More

How to Handle Web Links in Emails and Texts

How to handle web links in email and texts Here our are tips for how to avoid being phished, or having your credentials harvested.  These are steps that should be understandable and accessible to the majority of users.  Some of the steps assume you have a good understanding of how to “right-click” your mouse and copy a link, without actually clicking on that link.  If you are unsure about this, or any other aspect of the advice in this article, we recommend you do not proceed with that step, and ask us or someone else for help first. Don’t click

Read More
Scroll to Top