Skip to content
Live newsroom 144 readers online
Friday, August 21, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingChinese memory firm CXMT relied on leaked Samsung technology to skip years of R&D, court testimony claims
Business AVOID AMZN Stage 4 (Conv: 3/5 | Size: 10%)

Why ‘nothing’s gone wrong yet’ isn’t website security

Barracuda’s Jesus Cordero-Guzman warns attackers chain small vulnerabilities together, and the average website has 20 of them waiting. If you think your website is probably fine because nothing’s gone wrong yet, new research might change your mind. Barracuda has found that the average web application carries around 20 security vulnerabilities, any of which could let […]

By deepak · August 21, 2026 · 4 min read

Barracuda’s Jesus Cordero-Guzman warns attackers chain small vulnerabilities together, and the average website has 20 of them waiting.

If you think your website is probably fine because nothing’s gone wrong yet, new research might change your mind. Barracuda has found that the average web application carries around 20 security vulnerabilities, any of which could let an attacker steal data, hijack accounts, or slip into systems they shouldn’t be anywhere near.

Researchers went through hundreds of Barracuda Application Security Insight scans collected over five months in 2026, and found that just seven categories of vulnerability account for roughly 90% of everything they detected. The biggest offender, at 25% of flaws, is what’s called information disclosure. That’s when an application accidentally reveals too much about its own structure, hidden pages, backend routes, internal services, giving attackers a head start on mapping out where the weak points are without setting off any alarms.

Close behind, at 23%, is brand impersonation and spoofing. These are the kinds of weaknesses that make it easier for someone to clone your website, pretend to be your business, and trick customers into handing over passwords or personal details.

Client-side attacks, things like cross-site scripting, make up 14% of the flaws found. This is where attackers exploit weaknesses in how a page displays or runs content, letting them run malicious scripts inside a user’s browser, steal session cookies, or trick people into clicking something they shouldn’t.

Data exposure sits at 10%, covering situations where sensitive information leaks out through webpages, APIs, logs, cookies or tracking scripts that weren’t locked down properly. The remaining categories, weak or missing encryption (6%), outdated software and insecure configurations (6%), and poor session or credential management (5%), round out the list.

“Web applications are a critical interface for organisations, from website storefronts to interactive interfaces for customers, partners and operations. Keeping them secure is essential,” said Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec and XDR International at Barracuda. “An average of 20 vulnerabilities per application means attackers have multiple opportunities to probe, test and exploit weaknesses. While not every issue is critical on its own, attackers often chain together several low and medium risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorised access. Organisations need a proactive, layered approach to application security that continuously identifies and addresses risks before they can be exploited.”

It’s easy to read a report like this and assume it’s mostly about big enterprise platforms. It isn’t. If your business runs a website with a contact form, a booking system, a customer login, or an online store, you’re carrying the same categories of risk, often with a lot less oversight watching for them.

The numbers back that up locally. Roughly seven in ten small businesses have a website, but only about a third check it for updates on a weekly basis. That gap, between having a website and actually maintaining it, is exactly where the kind of “basic oversights” Barracuda flags tend to creep in.

There’s also a real cost attached to getting this wrong. The average self-reported cost of cybercrime for Australian small businesses has climbed to around $49,600. For a lot of SMEs, that’s not a line item you can just absorb.

You don’t need an enterprise security team to close most of this gap. The Australian Cyber Security Centre’s Essential Eight is the go to local framework, a set of eight prioritised mitigation strategies designed specifically with resource-constrained organisations in mind. For website security specifically, the ACSC’s guidance is blunt: secure your website login with multi-factor authentication or a strong password, and keep your systems and plugins updated regularly.

A few practical steps line up directly with what Barracuda’s research flagged:

Lock down login access. MFA on your website admin, hosting account and domain registrar closes off a huge share of unauthorised access attempts, and it takes minutes to set up.

Patch on a schedule, not when you remember. Outdated software and insecure configurations made up 6% of the vulnerabilities Barracuda found, and they’re some of the easiest to fix once you actually notice them.

Know what your site is revealing. Information disclosure was the single biggest category at 25%. A basic external scan can show you what an attacker would see first, hidden admin pages, exposed routes, unnecessary detail about your backend.

Source: Read the original article on dynamicbusiness.com