Vulnerability & Web App Scanning Articles
Guidance on network, agent-based, credentialed and web application scanning: what each finds, how often to run them and how to prioritize what they report.
14 posts

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit
A network-only vulnerability program is blind to the laptops and field devices that leave the office. Here is when agent-based scanning earns its place, what each method sees, and the 5-class matrix for running both.

Internal vs External Vulnerability Scanning: Why PCI DSS Requires Both
A passing ASV scan proves the perimeter is quiet, not that your environment is safe. We compare internal vs external vulnerability scanning and what PCI DSS 11.3.1.2 requires.

Why Credentialed Vulnerability Scans Report Success Even When the Scan Account Has Lost Access
PCI DSS 11.3.1.2 has required authenticated internal scans since March 2025, but the scan account that makes them work degrades quietly. Here are the three failure modes and a 5-point check to prove coverage.

What Is a Vulnerability Scan?
A vulnerability scan is an automated security test that checks systems, networks and applications for known weaknesses. Learn how scans work, the types, and how they differ from penetration testing.

Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding)
Most vulnerability scanner false positives are not scanner errors, they are evidence problems. Here is what actually closes a disputed finding, and why rescanning never does.

Modern Web Applications Are Getting Harder to Secure: Why Basic Scans May Not Be Enough
Understand the importance of web application penetration testing in identifying vulnerabilities beyond simple vulnerability scanning.

How Often Should You Run Vulnerability Scans?
Learn how often to perform vulnerability scans to protect your business from security weaknesses and potential attacks.

What NIST’s 2026 NVD Changes Mean for Vulnerability Management Program
Stay informed on the NVD vulnerability enrichment changes 2026, focusing on prioritization and operational updates for vulnerabilities.

CVSS Matters; Business Impact Decides the Order
CVSS alone is a blunt instrument. See how blending severity with business impact, asset value and real-world exploitability produces a remediation queue your team can actually act on.

Top 5 API Security Risks Most Scanners Miss and How to Fix Them Before Attackers Find Them
APIs now carry more sensitive data than most web apps, and most scanners miss the risks. See the top API vulnerabilities and how targeted testing catches them.

Beyond the Obvious: Why Overlooked Industries Need Vulnerability Scanning Too
Healthcare and education handle high-value data with lean teams. See why regular scanning and continuous monitoring are the highest-leverage controls you can add.

Trust Is Currency: Why Website Security Matters More Than Ever
Website security is now a conversion metric. See how SSL/TLS hygiene and content security policies protect both revenue and brand trust.

Log4j Vulnerability
Log4j reset how the industry thinks about supply-chain risk. Revisit the vulnerability, the mitigation steps and the vendor checks that should now be standard.

Vulnerability Scanning Frequency
Quarterly ASV scans are the floor, not the ceiling. Get a risk-based framework for how often to scan externally and internally to actually reduce exposure.