Industry Insights & Expertise

Security Insights Hub

Curated content for the security professional: We cover the latest on frameworks, threats, and cybersecurity trends to keep your organization ahead of emerging risks.

Featured Articles

Legal and Compliance in the Cyber Age: How Law Firms and Regulatory Bodies Are Becoming Prime Cybercrime Targets
Featured
18 min read
September 26, 2025

Legal and Compliance in the Cyber Age: How Law Firms and Regulatory Bodies Are Becoming Prime Cybercrime Targets

The legal and compliance industry holds some of the most sensitive and valuable information in the business world, making it an irresistible target for cybercriminals and nation-state actors. From merger and acquisition details to regulatory investigations and client privileged communications, law firms and compliance organizations possess data that can be worth millions on the dark web or provide significant competitive advantages to malicious actors.

Legal SecurityVendor Risk
Read Article
Capture The Bug is Now CREST Accredited Penetration Testing Provider
Featured
8 min read
July 31, 2025

Capture The Bug is Now CREST Accredited Penetration Testing Provider

In the world of cybersecurity, trust isn't given; it's earned. It's proven through rigorous processes, demonstrable expertise, and an unwavering commitment to quality. Today, we are thrilled to announce that Capture The Bug has earned that trust in a significant new way: we are now officially a CREST-accredited provider for penetration testing services.

CREST AccreditationCompliance
Read Article
How Ethical Hacking Bridges the Gap Between Attackers and Defenders in Modern Cybersecurity
Featured
9 min read
July 21, 2025

How Ethical Hacking Bridges the Gap Between Attackers and Defenders in Modern Cybersecurity

In the chess match between cybercriminals and security professionals, there's a unique group of players who understand both sides of the board. Ethical hacking represents the art of thinking like an attacker while working to strengthen defenses, creating an essential bridge between offensive and defensive cybersecurity strategies.

Ethical HackingRed Team
Read Article

Latest Articles(301 articles)

State of Pentesting in Financial Services and Insurance Industries 2026: What the Data Reveals About the Sector's Blind Spot
4.2 min read
September 1, 2026

State of Pentesting in Financial Services and Insurance Industries 2026: What the Data Reveals About the Sector's Blind Spot

Financial services tests AI more than any sector. Yet red teaming expansion is lowest of all industries and remediation sits mid-pack. Here is what the 2026 data says about the paradox at the centre of financial sector security.

state of pentesting financial services insurance 2026penetration testing financial services industries 2026
Read more
How Capture The Bug Tests Payment APIs for Transaction Manipulation
4.2 min read
August 31, 2026

How Capture The Bug Tests Payment APIs for Transaction Manipulation

Payment APIs fail differently than standard APIs. Scanners miss the attacks that cost money. Here is exactly how Capture The Bug tests for transaction manipulation, IDOR, and race conditions.

payment API penetration testing transaction manipulationpayment API security testing 2026
Read more
How Remote Code Execution Vulnerabilities Become Business-Critical Incidents
4.2 min read
August 27, 2026

How Remote Code Execution Vulnerabilities Become Business-Critical Incidents

An RCE vulnerability does not announce itself. It gives an attacker code execution on your systems with no credentials required. Here is exactly how that becomes a business crisis in under 30 minutes.

remote code execution vulnerabilities business impactRCE vulnerability business risk 2026
Read more
ACSC High Alert: Active Exploitation of N-able N-central RMM Platform Targeting Australian Organisations
4.2 min read
August 26, 2026

ACSC High Alert: Active Exploitation of N-able N-central RMM Platform Targeting Australian Organisations

ASD's ACSC issued a High Alert on August 19 confirming active exploitation of N-able N-central vulnerabilities in Australia. Here is what MSPs and enterprise IT teams need to do right now.

N-able N-central vulnerability Australia 2026ACSC RMM exploitation alert Australia
Read more
How Capture The Bug's Integrations With Slack, GitHub, Jira, and Microsoft Teams Streamline Vulnerability Management
4.2 min read
August 25, 2026

How Capture The Bug's Integrations With Slack, GitHub, Jira, and Microsoft Teams Streamline Vulnerability Management

Most pentest findings sit in a PDF until someone reads them. Capture The Bug integrates with Slack, GitHub, Jira, and Microsoft Teams so findings reach the right engineers the moment they are confirmed.

Capture The Bug Slack GitHub Jira integrationsPTaaS platform integrations vulnerability management
Read more
How Capture The Bug Uses TOTP Authentication to Strengthen Platform Security
4.2 min read
August 24, 2026

How Capture The Bug Uses TOTP Authentication to Strengthen Platform Security

When you share security findings with a pentest provider, the platform holding that data needs to be secured properly. Here is how Capture The Bug uses TOTP authentication to protect every account.

Capture The Bug TOTP platform securityTOTP authentication PTaaS platform
Read more
The State of Penetration Testing in Financial Services and Insurance 2026
4.2 min read
August 21, 2026

The State of Penetration Testing in Financial Services and Insurance 2026

Financial services is the second most expensive sector to breach globally. Here is what the 2026 data says about how banks and insurers in NZ, AU, and the USA are actually testing their security.

state of pentesting financial services 2026penetration testing financial services NZ AU
Read more
Ankita Dhakar Named EY Entrepreneur Of The Year 2026 Finalist
3 min read
August 20, 2026

Ankita Dhakar Named EY Entrepreneur Of The Year 2026 Finalist

Capture The Bug CEO Ankita Dhakar has been named one of 16 finalists for the 2026 EY Entrepreneur Of The Year New Zealand award, recognising her work building a cybersecurity platform from Aotearoa.

Ankita Dhakar EY Entrepreneur Of The Year 2026Capture The Bug New Zealand
Read more
How Attackers Discover Unpatched Assets Across Cloud and SaaS Environments
4.2 min read
August 19, 2026

How Attackers Discover Unpatched Assets Across Cloud and SaaS Environments

Before attackers exploit a vulnerability, they find it. Here is exactly how they discover unpatched assets across cloud and SaaS environments, and what that means for your security posture.

how attackers discover unpatched cloud assetsattacker reconnaissance cloud SaaS 2026
Read more
Why ANZ Companies Are Paying Ransoms Instead of Trusting Their Own Backups
4.3 min read
August 18, 2026

Why ANZ Companies Are Paying Ransoms Instead of Trusting Their Own Backups

34% of ANZ organisations paid a ransom in 2026. Most regretted it. The real reason was not fear of attackers. It was not knowing if their backups would actually work when needed.

ANZ ransomware ransom payment 2026ransomware backup failure Australia New Zealand
Read more
Why Are Known Vulnerabilities Still Being Exploited in 2026?
4.2 min read
August 17, 2026

Why Are Known Vulnerabilities Still Being Exploited in 2026?

Attackers don't need zero-days. They rely on known flaws your team already found but hasn't fixed. Here's the real reason the patch gap keeps growing and what to do about it.

known vulnerabilities exploited 2026patch gap cybersecurity 2026
Read more
Security Is Not a Report. It Is a Live System.
7 min read
August 14, 2026

Security Is Not a Report. It Is a Live System.

The report sitting in that folder is not your security posture. It is a photograph of it, taken on one day, already fading.

continuous security posture management ANZlive security posture New Zealand
Read more

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.