{"id":50708,"date":"2026-08-21T11:46:11","date_gmt":"2026-08-21T11:46:11","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=50708"},"modified":"2026-08-21T11:46:11","modified_gmt":"2026-08-21T11:46:11","slug":"why-nothings-gone-wrong-yet-isnt-website-security","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=50708","title":{"rendered":"Why \u2018nothing\u2019s gone wrong yet\u2019 isn\u2019t website security"},"content":{"rendered":"<p>Barracuda\u2019s Jesus Cordero-Guzman warns attackers chain small vulnerabilities together, and the average website has 20 of them waiting.<\/p>\n<p>If you think your website is probably fine because nothing\u2019s gone wrong yet, new research might change your mind. Barracuda has found that the average web application carries around 20 security vulnerabilities, any of which could let an attacker steal data, hijack accounts, or slip into systems they shouldn\u2019t be anywhere near.<\/p>\n<p>Researchers went through hundreds of Barracuda Application Security Insight scans collected over five months in 2026, and found that just seven categories of vulnerability account for roughly 90% of everything they detected. The biggest offender, at 25% of flaws, is what\u2019s called information disclosure. That\u2019s when an application accidentally reveals too much about its own structure, hidden pages, backend routes, internal services, giving attackers a head start on mapping out where the weak points are without setting off any alarms.<\/p>\n<p>Close behind, at 23%, is brand impersonation and spoofing. These are the kinds of weaknesses that make it easier for someone to clone your website, pretend to be your business, and trick customers into handing over passwords or personal details.<\/p>\n<p>Client-side attacks, things like cross-site scripting, make up 14% of the flaws found. This is where attackers exploit weaknesses in how a page displays or runs content, letting them run malicious scripts inside a user\u2019s browser, steal session cookies, or trick people into clicking something they shouldn\u2019t.<\/p>\n<p>Data exposure sits at 10%, covering situations where sensitive information leaks out through webpages, APIs, logs, cookies or tracking scripts that weren\u2019t locked down properly. The remaining categories, weak or missing encryption (6%), outdated software and insecure configurations (6%), and poor session or credential management (5%), round out the list.<\/p>\n<p>\u201cWeb applications are a critical interface for organisations, from website storefronts to interactive interfaces for customers, partners and operations. Keeping them secure is essential,\u201d said Jesus Cordero-Guzman, Director, Solution Architects AppSec, NetSec and XDR International at Barracuda. \u201cAn average of 20 vulnerabilities per application means attackers have multiple opportunities to probe, test and exploit weaknesses. While not every issue is critical on its own, attackers often chain together several low and medium risk vulnerabilities to expose sensitive information, steal credentials or gain unauthorised access. Organisations need a proactive, layered approach to application security that continuously identifies and addresses risks before they can be exploited.\u201d<\/p>\n<p>It\u2019s easy to read a report like this and assume it\u2019s mostly about big enterprise platforms. It isn\u2019t. If your business runs a website with a contact form, a booking system, a customer login, or an online store, you\u2019re carrying the same categories of risk, often with a lot less oversight watching for them.<\/p>\n<p>The numbers back that up locally. Roughly seven in ten small businesses have a website, but only about a third check it for updates on a weekly basis. That gap, between having a website and actually maintaining it, is exactly where the kind of \u201cbasic oversights\u201d Barracuda flags tend to creep in.<\/p>\n<p>There\u2019s also a real cost attached to getting this wrong. The average self-reported cost of cybercrime for Australian small businesses has climbed to around $49,600. For a lot of SMEs, that\u2019s not a line item you can just absorb.<\/p>\n<p>You don\u2019t need an enterprise security team to close most of this gap. The Australian Cyber Security Centre\u2019s Essential Eight is the go to local framework, a set of eight prioritised mitigation strategies designed specifically with resource-constrained organisations in mind. For website security specifically, the ACSC\u2019s guidance is blunt: secure your website login with multi-factor authentication or a strong password, and keep your systems and plugins updated regularly.<\/p>\n<p>A few practical steps line up directly with what Barracuda\u2019s research flagged:<\/p>\n<p>Lock down login access. MFA on your website admin, hosting account and domain registrar closes off a huge share of unauthorised access attempts, and it takes minutes to set up.<\/p>\n<p>Patch on a schedule, not when you remember. Outdated software and insecure configurations made up 6% of the vulnerabilities Barracuda found, and they\u2019re some of the easiest to fix once you actually notice them.<\/p>\n<p>Know what your site is revealing. Information disclosure was the single biggest category at 25%. A basic external scan can show you what an attacker would see first, hidden admin pages, exposed routes, unnecessary detail about your backend.<\/p>\n<p><em>Source: <a href='https:\/\/dynamicbusiness.com\/topics\/technology\/technology-security\/why-nothings-gone-wrong-yet-isnt-website-security.html' target='_blank'>Read the original article on dynamicbusiness.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Barracuda\u2019s Jesus Cordero-Guzman warns attackers chain small vulnerabilities together, and the average website has 20 of them waiting. If you think your website is probably fine because nothing\u2019s gone wrong yet, new research might change your mind. Barracuda has found that the average web application carries around 20 security vulnerabilities, any of which could let [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":50709,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,36],"tags":[18,29,33],"class_list":["post-50708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-share-suggestions","tag-impact-amzn","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/50708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=50708"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/50708\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/50709"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=50708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=50708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=50708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}