Mark
markmhammond.bsky.social
Mark
@markmhammond.bsky.social
Reposted by Mark
Scanners miss real TLS/PKI issues that clients encounter; like incomplete chains and trust path errors. We break down why this happens and how to test properly in practice.

Read the full post: artais.io/blog/tlspki-...

#PKI #TLS #AppSec #Pentest #infosec
TLS/PKI Testing in Practice: What Scanners Miss — ARTAIS
Automated scanners can't catch every TLS or PKI flaw, especially those that only appear in real-world client scenarios. In this post, we break down why common tools fall short and how practical, clien...
artais.io
January 14, 2026 at 10:04 PM
Reposted by Mark
Fortinet FortiWeb WAFs are in the news again with CVE 2025 64446 and CVE 2025 58034. If your WAF shows up in the KEV list, it belongs in threat models, log review, and red team scope, not just in the change window. #OffSec #AppSec #Fortinet
December 3, 2025 at 9:34 PM