
7 Common Web Application Security Threats
Most web-application breaches still come from a small set of well-known threats. Here are the seven that matter most and how to stop them.
Writing
Page 18 of 20.

Most web-application breaches still come from a small set of well-known threats. Here are the seven that matter most and how to stop them.

IAM is the discipline of giving the right people the right access and proving it after the fact. Concepts, controls, and how to design a modern program.

Cybercriminals often make use of email-based attack campaigns to target all kinds of organizations.

Formjacking attacks are designed and executed by cybercriminals to steal financial and banking details from payment forms that can be captured directly on

Strong passwords still matter, but the rules have changed. Here is how to pick passwords that actually defeat modern attacks.

Contact-form spam, scraping, and abuse are now industrialised. Here are the layered defences that actually keep bots out without annoying humans.

Identity proofing is how you verify a person is who they claim to be at sign-up. Here is why it matters and how it works end to end.

In reality, there are so many mistakes that can make your account vulnerable to cyber attacks.

80% of data breaches involve compromised credentials. Yet most organizations are still fighting 2026 threats with 2015 defenses.

Hacking your smartphone may feel like someone has stolen your home. Go through this checklist to protect your phone from being hacked.

The SAFE DATA Act proposed a federal privacy baseline in the US. Here is what it would have covered and what it tells us about where US privacy is heading.

> Virtual networks are separated from other virtual networks and from the underlying physical network, offering the least privileged protection concept.

Security problems are an alternative way to recognise your customers when they have forgotten their password, entered too many times the wrong passwords,

Cloud security failures are almost always configuration failures. Five challenges that actually break companies and the certifications worth caring about.

How I built LoginRadius into an IDaaS platform that handles hybrid environments, SSO, MFA, and compliance at scale.

With no end in sight for the Covid-19 pandemic, countries around the world are struggling to bring their economies back on track.

> Let's talk about the current scope of blockchain and how it helps in securing digital identities for companies.

Single-page apps changed how auth works. Here is how we approached SPA security at LoginRadius and the patterns worth keeping.

> In relentless pursuit of automation and velocity, DevOps teams can reduce the software development cycle and ensure that their products are responsive

Whether you are a small enterprise, a large corporation, or something in between, phishing is one of the most damaging and vicious threats that you have

Mobile auth is harder than web auth. Here is how we approached enterprise mobile security at LoginRadius and what every team should ship.

In 2020, consumer data is the most valuable asset for businesses, and cybercriminals are well aware of this fact.

Smart cities promise efficiency and convenience, but their backbone is identity, data, and trust. Here is what will make them work.

Why we shipped a consumer-level audit trail at LoginRadius and what it changed for enterprise risk and compliance teams.

Online gambling is a top target for fraud, ATO, and money laundering. Here is what operators must lock down to keep players and revenue safe.

Every day, we are creating and sharing data at an astounding rate. With each email, text, tweet, tap and stream, more data is available for companies to

> App developers are increasingly turning to customer identity and access management (CIAM) solutions as B2C companies look to offer an elevated user

Designing a CIAM platform that survives a decade of changing privacy laws, new threats, and new device types. What we did at LoginRadius.

Authentication proves who you are. Authorization decides what you can do. Here is why mixing them up causes most access-control bugs.

2FA or MFA (Two or Multi-Factor Authentication) The two-factor (2FA) or multi-factor authentication (MFA) method uses two or more factors to authenticate