https://criadvantage.com/wp-content/uploads/2025/10/Workers-in-office-looking-at-technology.jpg
1250
2000
Abstrakt Marketing
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Abstrakt Marketing2025-10-09 12:47:452026-04-02 09:00:59Uncovering the ServiceNow Zurich Release: What You Need to KnowIn the world of software security, an attacker will almost always take the path of least resistance. Sophisticated exploits won’t ever be used if the front door is wide open. This is why you need to “take the temperature” of your application security. Covering the basics can prevent disastrous consequences.
A good analogy for this is tracking a fever. Knowing whether you have a fever is easy to determine and a valuable indicator of health. It is a standard practice. Everyone expects to have their temperature checked when visiting a doctor for a checkup. What would you think of a doctor’s competence if you went in for an annual physical and did not get your temperature checked?
Look for a moment at the title insurance and settlement services company First American. This company recently acknowledged a security flaw in one of its applications. This flaw (really a lack of controls) made access to hundreds of millions of sensitive customer records possible to anyone on the Internet using a web browser without authentication. In this case, customers access documents using a web link containing a record number that is nine digits long. Simply knowing what this web link looks like allows a user to access unauthorized records by changing this record number.
Next to the user login problem, authorizing all requests for customer records is the next most critical control in applications like First American’s. This is the most fundamental “taking your temperature” control out there. Hindsight is always 20/20, but verifying how you control access to records is one of the first things any competent software security auditor would evaluate. Surely a billion-dollar company could have afforded a review at some point, right?
Software Security Tip #2: Learn From the Mistakes of Others
Share This Post
More Like This
https://criadvantage.com/wp-content/uploads/2025/10/Workers-in-office-looking-at-technology.jpg
1250
2000
Abstrakt Marketing
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Abstrakt Marketing2025-10-09 12:47:452026-04-02 09:00:59Uncovering the ServiceNow Zurich Release: What You Need to Know
https://criadvantage.com/wp-content/uploads/2025/07/A-Beginners-Guide-to-Agentic-AI.jpg
1250
2000
Abstrakt Marketing
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Abstrakt Marketing2025-07-08 06:41:372026-04-02 09:01:03A Beginner’s Guide to Agentic AI
https://criadvantage.com/wp-content/uploads/2025/04/Smiling-male-employees-discussing-cooperation-planning.jpg
1250
2000
Abstrakt Marketing
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Abstrakt Marketing2025-04-04 09:19:322026-04-02 09:01:04How ServiceNow Supports Scalable IT Solutions for Growing Businesses
CRI Advantage Honored as ServiceNow’s Consulting and Implementation Partner of the Year – Premier Segment, Americas Region
CRI, Press Releases
CRI Advantage Achieves Recertification for ISO 27001:2022, ISO 9001:2015, and ISO 20000-1:2018
CRI, Press Releases
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-7-1-1.jpg
800
1200
Nate Riggins
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Nate Riggins2023-09-28 16:31:542026-04-02 09:01:11Cybersecurity Implications for Executives and Boards
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-5-1-1.jpg
800
1200
Nate Riggins
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Nate Riggins2023-06-13 22:20:172026-04-02 09:01:11The Importance of Vendor Cybersecurity: Protecting Your Business
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-11.jpg
800
1200
Nate Riggins
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Nate Riggins2023-03-17 05:26:112025-01-09 13:12:47How the SEC Cybersecurity Risk Management Ruling May Affect You
https://criadvantage.com/wp-content/uploads/2024/12/BLOG-PRESS-RELEASE-COVERS-9.jpg
800
1200
Nate Riggins
/wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png
Nate Riggins2023-02-10 23:40:382025-01-09 13:14:23Getting Started With a Managed Security Operations Center 
ServiceNow IT solutions tailored to your industry-specific needs.


