The OWASP Top 10 was rebuilt for 2025. Here is what moved, what is new, and the questions worth asking before your next web application penetration test.
penetration testing
-
-
The Certighost AD CS privilege escalation bug will get patched. The Windows default that made it possible, an unreviewed machine account quota, will not fix itself.
-
Hugging Face was breached by an autonomous AI agent that logged 17,000 actions in a weekend. Here’s the practical checklist any business can run against the same weaknesses.
-
A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.
-
A 16-year-old hypervisor escape vulnerability in Linux KVM shows guest isolation is an assumption, not a fact. Here’s why that should change how you scope security testing.
-
Penetration testing as a service and a traditional scoped engagement solve different problems. A side-by-side comparison and a simple way to decide which your business needs.
-
What happens during a thick client penetration test, what testers find most often, and how to choose a provider.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
Black box vs white box testing comes down to how much access you give your penetration testers. Here’s how each approach, plus grey box testing, affects realism, depth, cost and …
-
Not sure whether to commission a penetration test or start a bug bounty programme? A practical checklist covering compliance, cost and timing for UK businesses.