
Recognizing Common Security Breaches
Explore typical security failures leading to breaches, such as weak credentials and misconfigurations.
What is this page about?
An explainer of the most common security failures, opening with Equifax leaving a known Apache Struts vulnerability unpatched for 143 days, leading to 147 million records stolen. It organizes breaches into six categories, credential compromise (default, shared, and hardcoded credentials), unpatched vulnerabilities, misconfiguration (public storage and database exposures, overly permissive access), social engineering and phishing, insider threats, and supply-chain compromise, then explains the organizational dynamics behind chronic failures and how to build defenses that actually work.
What has been corrected on this page?
Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.
-
Robert Kowalski is a logic-programming computer scientist, not a CERT insider-threat author; the Common Sense Guide authors are CERT researchers like Cappelli, Moore, and Trzeciak
Beforeresearchers Robert Kowalski and Dawn Cappelli identified that the majority of malicious insiders
Afterresearchers Dawn Cappelli, Andrew Moore, and Randall Trzeciak identified that the majority of malicious insiders
Why: Verified already correctly fixed on the live site (body content). No mention of Kowalski/Cappelli in faq, excerpt, or meta_description. No further action needed.
View the full record →
Who checked this page?
1 contributor has checked "Recognizing Common Security Breaches" on When Notes Fly. Each name below links to that person's public CitePep profile, where every contribution they have made is listed with the exact change they proposed.