Select Page
Cross-Site Scripting (XSS): More Than a Pesky Alert

Cross-Site Scripting (XSS): More Than a Pesky Alert

By Porter Throckmorton, CRTO, OSCP, CBBH, PNPT, eWPTSenior Consultant, Technical Testing Services It is likely you have seen the number 1 in an alert box if you have ever had a penetration test performed on your web application. The alerted number is the most common...
OCR Risk Analysis, an Update for Covered Entities

OCR Risk Analysis, an Update for Covered Entities

A review of OCR Enforcement Findings from 2025 (March-July) OCR’s latest enforcement push is driving healthcare organizations to conduct a thorough review of their HIPAA risk analysis to find any weaknesses or gaps — before the agency does. OCR Risk Analysis update...
Assumed Breach Simulation: Lateral Movement

Assumed Breach Simulation: Lateral Movement

By Fabian Crespo, OSEP, OSCP, CRTOPrincipal Consulting, Technical Testing In our Clearwater Monthly Cyber Briefings, we often emphasize that today’s cyberattacks don’t always begin with a high-profile perimeter breach. More often, they start quietly, with a single...
Commentary on the Oracle Health Breach

Commentary on the Oracle Health Breach

Steve Cagle, Clearwater CEO   As many in the healthcare sector are aware, it has been reported that Oracle Health customers have individually received notification letters from Oracle Health advising that it detected a security breach on February 20, 2025 and...