Skip to main content

Security guides and articles

Every CompleteStatus blog post tagged Security — 34 articles, newest first.

Articles

soc2 compliance

How Monitoring Supports SOC 2 and Compliance Evidence

How uptime and security monitoring supports SOC 2 audits, cyber-insurance questionnaires and client security reviews, and what evidence they ask for.

6 min read
change-detection defacement

Website Change Detection: Catch Defacement Before Your Visitors Do

How website change detection works (rendered DOM vs raw HTML, tuning out dynamic noise) and how to catch defacement before your visitors do.

6 min read
dns dns-monitoring

DNS Monitoring: What to Watch, and Why Hijacking Is the Scary Part

Which DNS records to monitor, how to spot hijacking and unauthorized changes, TTL strategy, registrar security, and why domain expiry is the worst case.

7 min read
safe-browsing security

Google Safe Browsing Blacklist Removal: Fixing "Deceptive Site Ahead" Step by Step

Google flagged your site with "Deceptive site ahead"? Why legit sites get blacklisted, how to clean up, request a review, and how long delisting takes.

6 min read
checklist dns

The January Infrastructure Audit: A Checklist for Everything You've Been Ignoring

Expiring domains, stale DNS records, untested backups, orphaned access. The once-a-year infrastructure audit that prevents this year's outages.

6 min read
ssl certificates

Chrome Stops Trusting New Entrust Certificates: Check Your Chain This Week

Entrust TLS certificates issued after October 31 are no longer trusted by Chrome. How to find Entrust certificates on your estate and switch CAs cleanly.

5 min read
security supply-chain

The polyfill.io Supply-Chain Attack — Every Script Tag Is a Trust Decision

The polyfill.io CDN is injecting malicious code into 100,000+ sites. What happened, why SRI didn't save anyone, and how to defend against the next one.

6 min read
wordpress monitoring

Monitoring WordPress Sites — What Breaks, and How to Catch It

WordPress runs over 40% of the web and fails in WordPress-specific ways. Keyword checks, wp-cron heartbeats, defacement detection and xmlrpc abuse.

6 min read
security supply-chain

The xz Backdoor: A Multi-Year Con Caught by Half a Second of Latency

A backdoor in xz-utils 5.6.0 and 5.6.1 targeted sshd on Linux. What we know three days in, how to check your systems, and why a slow login mattered.

6 min read
security vulnerabilities

MOVEit Transfer: When the File Transfer Server Becomes the Breach

A zero-day in Progress MOVEit Transfer is being mass-exploited for data theft. What we know so far, and what it says about internet-facing appliances.

6 min read
security openssl

OpenSSL 3.0.7: The Critical Bug That Wasn't, and Why the Fire Drill Still Paid Off

OpenSSL pre-announced a critical fix, then shipped two high-severity bugs instead. How to find every OpenSSL 3 copy you run, and why the inventory matters.

6 min read
security log4shell

Log4Shell — What CVE-2021-44228 Is Teaching Us, Mid-Scramble

Log4Shell (CVE-2021-44228) is a trivially exploitable RCE in Log4j, and patching is still under way. What the scramble teaches every team, Java or not.

6 min read

More topics