7asecurity Completes OpenTelemetry Audit

7ASecurity is proud to share the results of our security audit of OpenTelemetry. OpenTelemetry is an open source project for generating and collecting telemetry data for software analysis. With the help of the Open Source Technology Improvement Fund (OSTIF) and the Cloud Native Computing Foundation (CNCF), this project will experience strengthened security health as it moves to graduation status with the …

Level Up Your Hacking Skills This Summer (with a 50% Discount!)

The sun is out, and the days are long – perfect for tackling some cybersecurity learning!  Here at 7ASecurity, we’re celebrating summer with a 50% off sale on all our self-paced courses. Use code SUMMER50 at checkout to unlock a treasure trove of hacking knowledge.  But hurry, this offer ends on August 31st, so don’t …

7ASecurity completes CoverDrop Audit

About CoverDrop Whistleblowers need a secure method to initiate contact and build trust with journalists. Existing tools often cater to later-stage correspondence, leaving crucial, early touch-points vulnerable to surveillance. In addition, many of these tools are difficult to find on newspaper websites, hard to use securely, and offer insufficient user guidance. After conducting workshops with …

Why should You do a Pentest

Why Should You Do a Pentest? Good question! But first things first: What is a pentest? A penetration test, or pentest, is a simulated cyber attack on a computer system, network, or application to identify and exploit security vulnerabilities. The goal is to assess the security posture of the target and provide recommendations for improving …

Why It Is Essential To Conduct Penetration Testing Regularly?

Have you ever wondered why it is essential to conduct penetration testing regularly in today’s evolving digital landscape? With cyber threats becoming more sophisticated, businesses and cybersecurity professionals must stay one step ahead to protect sensitive data and maintain trust. In this blog, we’ll look at penetration testing. We will highlight its importance, benefits, and …

7ASecurity Completes Opaque Security Audit

About Opaque Opaque is a JavaScript package to allow secure password-based, client-server authentication without the server ever obtaining knowledge of the password.  Audit Description Through OTF’s Red Team Lab, 7ASecurity conducted a penetration test and whitebox security review of Opaque. A whitebox review is a form of application testing that provides the tester with complete knowledge of the application …

7ASecurity Completes Disguiser Framework Audit

About Disguiser   Disguiser is a novel framework that enables end-to-end measurement for accurately and comprehensively investigating global internet censorship practices. It’s challenging to conduct large-scale internet censorship measurement, as it involves triggering censors through artificial requests and identifying abnormalities from corresponding responses. Due to the lack of “ground truth” on the expected responses from legitimate services, …

Why do you need a pentest?

In the pursuit of cost-effective cybersecurity solutions, automated “pentests” may seem enticing. However, the real test cost extends beyond affordability. Challenges of Automation: Automated tools miss critical issues, leading to false negatives (missed vulnerabilities) and wasted effort on false positives (fake findings your team must review). The True Test Cost: Skilled testers provide accurate insights, …

Free Pentest Contest 2023! Deadline Approaching?

Time is ticking! With the Free Pentest Contest 2023, you now have just one month left to submit your entry before the ~January 31st, 2024. Don’t miss out on this golden chance to bolster your cybersecurity defenses – act now! This is your chance to win a complimentary, professional pentest and fortify your defenses against …

7ASecurity Completes Security Audit of Node Version Manager

7ASecurity had the privilege to collaborate with the Open Source Technology Improvement Fund (OSTIF), as well as the Node Version Manager (nvm) team, in a recent security audit of the nvm project. What is Node Version Manager? nvm is an open-source version manager for Node.js. It is designed to be secure, reliable and easy to use.nvm operates as …