Vulnerability & Web App Scanning Articles

Guidance on network, agent-based, credentialed and web application scanning: what each finds, how often to run them and how to prioritize what they report.

14 posts

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit
Sep 28, 2026Vulnerability Scanning

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit

A network-only vulnerability program is blind to the laptops and field devices that leave the office. Here is when agent-based scanning earns its place, what each method sees, and the 5-class matrix for running both.

Read the post
Internal vs External Vulnerability Scanning: Why PCI DSS Requires Both
Sep 22, 2026Vulnerability Scanning

Internal vs External Vulnerability Scanning: Why PCI DSS Requires Both

A passing ASV scan proves the perimeter is quiet, not that your environment is safe. We compare internal vs external vulnerability scanning and what PCI DSS 11.3.1.2 requires.

Read the post
Why Credentialed Vulnerability Scans Report Success Even When the Scan Account Has Lost Access
Sep 21, 2026Vulnerability Scanning

Why Credentialed Vulnerability Scans Report Success Even When the Scan Account Has Lost Access

PCI DSS 11.3.1.2 has required authenticated internal scans since March 2025, but the scan account that makes them work degrades quietly. Here are the three failure modes and a 5-point check to prove coverage.

Read the post
What Is a Vulnerability Scan?
Sep 17, 2026Vulnerability Scanning

What Is a Vulnerability Scan?

A vulnerability scan is an automated security test that checks systems, networks and applications for known weaknesses. Learn how scans work, the types, and how they differ from penetration testing.

Read the post
Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding)
Aug 18, 2026Vulnerability Scanning

Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding)

Most vulnerability scanner false positives are not scanner errors, they are evidence problems. Here is what actually closes a disputed finding, and why rescanning never does.

Read the post
Modern Web Applications Are Getting Harder to Secure: Why Basic Scans May Not Be Enough
Jul 15, 2026Vulnerability Scanning

Modern Web Applications Are Getting Harder to Secure: Why Basic Scans May Not Be Enough

Understand the importance of web application penetration testing in identifying vulnerabilities beyond simple vulnerability scanning.

Read the post
How Often Should You Run Vulnerability Scans?
Jun 24, 2026Vulnerability Scanning

How Often Should You Run Vulnerability Scans?

Learn how often to perform vulnerability scans to protect your business from security weaknesses and potential attacks.

Read the post
What NIST’s 2026 NVD Changes Mean for Vulnerability Management Program
Apr 22, 2026Vulnerability Scanning

What NIST’s 2026 NVD Changes Mean for Vulnerability Management Program

Stay informed on the NVD vulnerability enrichment changes 2026, focusing on prioritization and operational updates for vulnerabilities.

Read the post
CVSS Matters; Business Impact Decides the Order
Mar 4, 2026Vulnerability Scanning

CVSS Matters; Business Impact Decides the Order

CVSS alone is a blunt instrument. See how blending severity with business impact, asset value and real-world exploitability produces a remediation queue your team can actually act on.

Read the post
Top 5 API Security Risks Most Scanners Miss and How to Fix Them Before Attackers Find Them
Jul 2, 2025Vulnerability Scanning

Top 5 API Security Risks Most Scanners Miss and How to Fix Them Before Attackers Find Them

APIs now carry more sensitive data than most web apps, and most scanners miss the risks. See the top API vulnerabilities and how targeted testing catches them.

Read the post
Beyond the Obvious: Why Overlooked Industries Need Vulnerability Scanning Too
May 21, 2025Vulnerability Scanning

Beyond the Obvious: Why Overlooked Industries Need Vulnerability Scanning Too

Healthcare and education handle high-value data with lean teams. See why regular scanning and continuous monitoring are the highest-leverage controls you can add.

Read the post
Trust Is Currency: Why Website Security Matters More Than Ever
Apr 23, 2025Vulnerability Scanning

Trust Is Currency: Why Website Security Matters More Than Ever

Website security is now a conversion metric. See how SSL/TLS hygiene and content security policies protect both revenue and brand trust.

Read the post
Log4j Vulnerability
Mar 4, 2022Vulnerability Scanning

Log4j Vulnerability

Log4j reset how the industry thinks about supply-chain risk. Revisit the vulnerability, the mitigation steps and the vendor checks that should now be standard.

Read the post
Vulnerability Scanning Frequency
Mar 4, 2022Vulnerability Scanning

Vulnerability Scanning Frequency

Quarterly ASV scans are the floor, not the ceiling. Get a risk-based framework for how often to scan externally and internally to actually reduce exposure.

Read the post