Recognizing Common Security Breaches
Technology Corrected & verified

Recognizing Common Security Breaches

Published by When Notes Fly · View original ↗

Explore typical security failures leading to breaches, such as weak credentials and misconfigurations.

Page Summary

An explainer of the most common security failures, opening with Equifax leaving a known Apache Struts vulnerability unpatched for 143 days, leading to 147 million records stolen. It organizes breaches into six categories, credential compromise (default, shared, and hardcoded credentials), unpatched vulnerabilities, misconfiguration (public storage and database exposures, overly permissive access), social engineering and phishing, insider threats, and supply-chain compromise, then explains the organizational dynamics behind chronic failures and how to build defenses that actually work.

Contributions

Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.

  1. 11 July 2026 · corrected by Melik Can Sariyer

    Robert Kowalski is a logic-programming computer scientist, not a CERT insider-threat author; the Common Sense Guide authors are CERT researchers like Cappelli, Moore, and Trzeciak

    Before

    researchers Robert Kowalski and Dawn Cappelli identified that the majority of malicious insiders

    After

    researchers Dawn Cappelli, Andrew Moore, and Randall Trzeciak identified that the majority of malicious insiders

    Why: Verified already correctly fixed on the live site (body content). No mention of Kowalski/Cappelli in faq, excerpt, or meta_description. No further action needed.

    View the full record →

Contributors In This Page