惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V2EX - 技术
V2EX - 技术
L
LangChain Blog
IT之家
IT之家
S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
The Blog of Author Tim Ferriss
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
U
Unit 42
B
Blog RSS Feed
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
T
Threatpost
C
CERT Recently Published Vulnerability Notes
Cisco Talos Blog
Cisco Talos Blog
The Register - Security
The Register - Security
Vercel News
Vercel News
S
Schneier on Security
Spread Privacy
Spread Privacy
C
Cyber Attacks, Cyber Crime and Cyber Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
博客园 - 叶小钗
雷峰网
雷峰网
博客园_首页
人人都是产品经理
人人都是产品经理
P
Palo Alto Networks Blog
The Hacker News
The Hacker News
T
Tor Project blog
L
Lohrmann on Cybersecurity
Know Your Adversary
Know Your Adversary
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cybersecurity and Infrastructure Security Agency CISA
P
Privacy International News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tenable Blog
V
Vulnerabilities – Threatpost
大猫的无限游戏
大猫的无限游戏
博客园 - 【当耐特】
V
V2EX
Security Latest
Security Latest
A
About on SuperTechFans
Cloudbric
Cloudbric
S
Security Affairs
MongoDB | Blog
MongoDB | Blog
Y
Y Combinator Blog
Martin Fowler
Martin Fowler
TaoSecurity Blog
TaoSecurity Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It ESET MDR vs Sophos MDR: Compared Time to discover and respond to a threat 15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys Amos Stealer Targets macOS Keychain Files and Browser Passwords Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era New Rokarolla Android Trojan Found Targeting 217 Crypto and Banking Apps Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Best of Android Fax Apps: Top 5 Secure Picks for 2026 Feds Seize CFAKE and SOCFAKE Over Explicit Deepfakes of Famous Women Handala Hacking Group Claims Breach of California Water Service Over 50 Android Apps Found Spreading MagicAd Trojan via Official Stores Hackers Hide New Argamal Malware Inside Working Hentai Games Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks Atomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver Malware ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack The SpaceX Pre-IPO Market: How Crypto Rails Are Opening Synthetic Access Feds Seize AudiA6 and Dark2Web in $389M Crypto Laundering Case ShinyHunters Leak 40GB of University of Nottingham Student Data Authorities Dismantle Decade-Old SniperDZ Phishing Network Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware FBI Seizes China-Linked Fake Consulting Sites Targeting US Clearance Holders How to Turn Images into Animated Videos with AI: A Wondershare Filmora Guide Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer ServiceNow Discloses Security Incident Exposing Customer Data Cloud Security Report Finds Fragmented Tools Widening the Cloud Complexity Gap Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days Network Log Analysis: Why Collecting Logs is Not Enough WhatsApp Says It Blocked Pegasus Spyware Campaign Linked to NSO Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse Instagram Glitch Reportedly Exposed Contact Info of Zuckerberg and Other Users New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account Atlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service Users Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords iFood Confirms Data Breach Affecting 1.2 Million Users in Brazil Why eSIMs Are Replacing Traditional SIM Cards Lazarus Group Uses npm Brandjacking Campaign to Target Developers Five Eyes Warns Chinese Spies Are Using Fake Job Ads to Target Military Staff How to Recover Data from iCloud Backup Without Resetting Your iPhone China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware Alcasec, "Robin Hood of Spanish Hackers," Jailed for 31 Months Over Data Theft Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware Hackers Abused Meta’s AI Support Bot to Hijack Major Instagram Accounts New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions Halo Security Honored with 2026 MSP Today Product of the Year Award Why Encrypted File Sharing Is Essential for Modern Businesses What One Predator Case Can Reveal About an Online Platform’s Safety Gaps RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users How to Get a Reddit API Key in 2026: Step-by-Step Guide Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts How to Get the Most From Your Explainer Video Production Services Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users The Deliverability Problem: How New Platforms Are Solving Inbox Placement The CISO Whisperer's Watch List For The Gartner Security & Risk Management Summit 2026 Can Big Data Predict Market Movements Accurately? Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts? Link11 is fully committed to Europe and is opening a Customer Excellence Hub in Lisbon Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning Claude Mythos AI Identified 10,000+ Software Vulnerabilities in One Month FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack Netherlands Busts Bulletproof Hosting Network Linked to Disinfo and Cybercrime
The Hidden Security Risks of Poor Software Testing
Owais Sultan · 2026-06-11 · via Hackread – Cybersecurity News, Data Breaches, AI and More

A system does not need to be attacked by an advanced hacker to fail. One overlooked flaw in the code, one outdated dependency, or one rushed release can give attackers the access they need,  especially after the exploitation of AI in cybercrime.

Companies can spend heavily on antivirus software, firewalls, endpoint tools, and multi-factor authentication. Those controls matter, but they cannot fully protect a product that was released with avoidable security flaws. Once vulnerable code reaches production, attackers have a real target.

This is why software testing should not be treated as a final checkbox before launch. It should be part of development from the beginning, especially when a product handles customer data, financial information, healthcare records, authentication, payments, or business-critical operations.

What Happens When Testing Is Weak

Weak testing creates problems long before an attacker appears. Vulnerabilities missed during development often become production failures, customer complaints, service downtime, and security incidents.

According to research, an average-sized software system can have 19 critical security findings. Not every critical finding turns into a breach, but each one gives attackers another opportunity if left unresolved.

The cost can be severe. IBM’s 2024 Cost of a Data Breach Report (PDF) placed the global average cost of a data breach at $4.88 million. That figure does not only include technical cleanup. It also includes lost business, legal work, customer notification, regulatory issues, and recovery costs.

For small and medium-sized companies, a serious breach can be devastating. For larger organizations, the cost may be absorbed financially, but the reputational damage can last much longer than the technical incident.

Companies with mature development processes usually treat testing as a separate discipline, not a last-minute task. This includes in-house QA teams, security engineers, automated testing pipelines, and, where internal capacity is limited, external QA outsourcing services that can support functional, performance, and security testing before release.

When vulnerabilities are found after deployment, the situation becomes more expensive and harder to control. Developers must pause planned work to fix urgent issues. Product updates get delayed. Support teams face more complaints. Security teams must investigate whether the flaw was exploited. Management then has to explain what happened to customers, regulators, partners, or investors.

This is the real cost of weak testing. It is not only the price of fixing bad code. It is the disruption across the entire business.

The Hidden Damage of Poor Testing

Some losses are visible immediately. Others appear over time. The hidden damage usually falls into three categories: reputational, operational, and financial.

Reputational damage is often the hardest to repair. For example, if a medical provider leaks patient data, the organization does not only face technical and legal problems. Patients lose trust. Partners may reconsider contracts. Regulators may investigate. In the B2B sector, one incident can be enough to lose major customers.

Operational damage can also be serious. A product that was not tested properly may fail during peak usage. This is especially risky for telecom providers, banks, e-commerce platforms, cloud services, and SaaS companies. A service that works during normal usage may break under load if performance, availability, and security testing were weak.

Financial damage is easier to understand. The later a flaw is found, the more expensive it becomes to fix. A defect found during design or coding can often be repaired quickly. A defect found after release may require emergency patches, customer communication, incident response, legal support, and infrastructure changes.

This is why early testing is cheaper than crisis response.

How Poor Testing Creates Attack Paths

Attackers look for entry points. In modern software, those entry points are often found in source code, configurations, APIs, authentication flows, cloud permissions, or third-party components.

Most vulnerabilities do not appear suddenly at the end of development. They are usually introduced earlier through careless coding, missed requirements, human error, rushed deadlines, or a lack of security review.

Common examples include weak access controls, exposed APIs, hardcoded secrets, insecure file uploads, broken authentication, SQL injection, cross-site scripting, server-side request forgery, and insecure direct object references.

Third-party dependencies add another layer of risk. Many development teams rely on open-source libraries to speed up delivery. That is normal, but every package added to a project also adds trust in someone else’s code.

Open-source software is not automatically unsafe, but it must be checked. According to Software Improvement Group, 50% of enterprise software systems are vulnerable due to security issues in open-source libraries, while 30% contain at least one critical vulnerable dependency.

A popular package can be used by thousands of companies. If a serious vulnerability is found in that package, many systems can become exposed at the same time.

Log4Shell showed this clearly. A flaw in a widely used logging library created an urgent risk for organizations around the world. The lesson was not that open-source software should be avoided. The lesson was that companies need visibility into what their software uses and whether those components are vulnerable.

Why Penetration Testing Alone Is Not Enough

Penetration testing is valuable, but it should not be the only security check.

A pentest usually happens near the end of development or before a major release. By then, the product may already contain architectural issues, dependency problems, insecure coding patterns, or design flaws that are expensive to fix.

If a company relies only on pentesting, it may find serious problems too late. The result is delayed releases, rushed patches, and costly rework.

A stronger approach uses several layers of testing:

  • SCA, or software composition analysis, checks third-party libraries and dependencies for known vulnerabilities.
  • SAST, or static application security testing, scans source code during development to find risky patterns before the product is deployed.
  • DAST, or dynamic application security testing, tests the running application from the outside and helps identify issues in live behavior.
  • Manual security review helps find logic flaws that automated tools may miss.
  • Penetration testing validates how these weaknesses could be used by a real attacker.
  • Used together, these methods give teams a much clearer view of risk. Used separately, each method leaves gaps.

Why Companies Still Release Poorly Tested Software

Poor testing often comes down to pressure. Teams are told to release faster, reduce costs, and meet deadlines. Security and QA work may be compressed into the final stage of development, where there is little time to fix anything properly.

Another problem is a lack of skill. Security testing requires experience. A tester who can verify whether a feature works may not know how to test for privilege escalation, insecure APIs, broken authorization, dependency risk, or authentication bypasses.

Tooling is also a factor. Without proper scanners, test environments, code review processes, and dependency tracking, teams may not even know what risks exist inside their product.

A serious testing strategy requires three things: skilled people, clear processes, and the right tools. Remove any of these, and vulnerabilities become easier to miss.

What Companies Should Do Before Release

Security testing should begin early in development, not after the product is already complete.

Companies should review design decisions before coding begins. Developers should follow secure coding practices. Dependencies should be scanned continuously. Secrets should not be stored in code repositories. Authentication and authorization should be tested carefully. APIs should be reviewed for exposure and abuse cases. Cloud permissions should be checked before deployment.

Automated tools can help, but they are not enough on their own. Human review is still needed, especially for business logic flaws. For example, an automated scanner may not understand that a normal user should not be able to access another customer’s invoice by changing an ID in the URL.

Testing should also continue after release. New vulnerabilities are found every day in libraries, frameworks, platforms, and operating systems. A product that was secure at launch may become vulnerable later if its dependencies are not monitored and updated.

Conclusion

Weak testing is one of the easiest ways to turn a normal software vulnerability into a security incident. A rushed release may save time in the short term, but it can create far greater costs later.

The damage from a single breach can reach millions of dollars. The losses can include downtime, legal costs, customer churn, regulatory action, and long-term reputational harm.

No company can make software completely free of flaws. However, companies can reduce avoidable risk by testing earlier, scanning dependencies, reviewing code, checking access controls, and using penetration testing as one part of a broader security process.

Nevertheless, the real question remains: should your team find the flaw first, or should an attacker?

(Photo by Mohammad Rahmani on Unsplash)