logo.png
Guided Website Threat Review

Foregenix Blog

Information Privacy, The General Data Privacy Regulation (GDPR) & Your Business

PCI, PA-DSS and P2PE, GDPR

,30/01/17 16:43

To begin, we'll take the following definitions of 'privacy' and 'information privacy' from the International Association of Privacy Professionals:

Read More
Benjamin Hosack

Vulnerabilities on ManageEngine EventLog 10.7 through 11.2 (Service Pack 11023)

penetration testing

,23/12/16 11:29

We have come across Manage Engine EventLog installations a few times in our penetration tests at Foregenix, and have identified different vulnerabilities in our attempts to compromise it. In most situations a default guest account was left open and becomes a focus point as we attempt to use it to elevate privileges or otherwise influence the profiles behaviour to our advantage. These attempts resulted in the following vulnerabilities being discovered and reported to the vendor. While the installations encountered during the engagements may not be running an up-to-date version of the ManageEngine EventLog software we validated whether the vulnerabilities still exist on the latest version as of the time of reporting them to the Vendor.

Read More

Encryption 102: 5 Methods of Encryption (Part 2)

PCI, PA-DSS and P2PE, Encryption

,07/12/16 16:02

Following on from Encryption 101, this post will focus on different methods of Encryption, when they're applicable and why they are important. 

Read More
Benjamin Hosack

Magento Malicious JavaScript in Action

web security, Magento, malware, JavaScript

,08/11/16 14:48

Magento websites have been under attack from a new malicious JavaScript family of malware - our forensic team has been working with many hacked websites to help them regain control of their online businesses and to limit losses.

Read More
Benjamin Hosack

Magento Websites - Have You Patched SUPEE-8788 Yet?

web security, Magento

,04/11/16 14:28

Last month Magento released SUPEE-8788 to fix a number of security issues – you can read about SUPEE-8788 in detail here.  A LOT of websites have not yet patched and are at risk of being hacked.

Read More

Information Privacy, The General Data Privacy Regulation (GDPR) & Your Business

PCI, PA-DSS and P2PE, GDPR

,30/01/17 16:43

To begin, we'll take the following definitions of 'privacy' and 'information privacy' from the International Association of Privacy Professionals:

Read More
Benjamin Hosack

Vulnerabilities on ManageEngine EventLog 10.7 through 11.2 (Service Pack 11023)

penetration testing

,23/12/16 11:29

We have come across Manage Engine EventLog installations a few times in our penetration tests at Foregenix, and have identified different vulnerabilities in our attempts to compromise it. In most situations a default guest account was left open and becomes a focus point as we attempt to use it to elevate privileges or otherwise influence the profiles behaviour to our advantage. These attempts resulted in the following vulnerabilities being discovered and reported to the vendor. While the installations encountered during the engagements may not be running an up-to-date version of the ManageEngine EventLog software we validated whether the vulnerabilities still exist on the latest version as of the time of reporting them to the Vendor.

Read More

Encryption 102: 5 Methods of Encryption (Part 2)

PCI, PA-DSS and P2PE, Encryption

,07/12/16 16:02

Following on from Encryption 101, this post will focus on different methods of Encryption, when they're applicable and why they are important. 

Read More
Benjamin Hosack

Magento Malicious JavaScript in Action

web security, Magento, malware, JavaScript

,08/11/16 14:48

Magento websites have been under attack from a new malicious JavaScript family of malware - our forensic team has been working with many hacked websites to help them regain control of their online businesses and to limit losses.

Read More
Benjamin Hosack

Magento Websites - Have You Patched SUPEE-8788 Yet?

web security, Magento

,04/11/16 14:28

Last month Magento released SUPEE-8788 to fix a number of security issues – you can read about SUPEE-8788 in detail here.  A LOT of websites have not yet patched and are at risk of being hacked.

Read More

Cyber Security Insights

Duncan Slater
26/05/17 14:08

“Mind the Gap” – As a Small eCommerce Business, Who is Responsible for Your Security?

  Major corporations spend hundreds of thousands of pounds and in some cases employ teams of people dedicated to manage and ensure the security of ...

Read More

Kirsty Trainer
23/05/17 10:48

8 Critical Steps to Reduce the Risk of Ransomware Infection

The WannaCry ransomware infestation is a wake-up call for all entities connected to public networks, such as the internet, to recognise ...

Read More

Mike Hinton
16/05/17 17:24

Foregenix announce new partnership with Juno Web Design

We’re delighted to announce a new partnership between ourselves and Nottinghamshire based agency ‘Juno’. With the rapidly increasing threat to ...

Read More

Kirsty Trainer
05/05/17 09:42

Foregenix choose Australia as launch pad for Asia Pacific expansion

Foregenix are setting-up a new base in Australia, targetting the Asia Pacific region for growth. The new office in Sydney will open in May and be ...

Read More

Kirsty Trainer
11/04/17 12:03

New survey shows 78% of eCommerce websites at risk

47,000 out of 60,000 websites missing critical security patches Over 3,000 are already hacked and losing customer data now External security scans ...

Read More