Web Security Lab

129 posts

Web Security Lab banner
Web Security Lab

Web Security Lab

@WebSecurityLab

Public-interest cybersecurity & digital trust initiative. Advancing digital safety, rights, and security capacity across Africa.

เข้าร่วม Ocak 2024
41 กำลังติดตาม92 ผู้ติดตาม
ทวีตที่ปักหมุด
Web Security Lab
Web Security Lab@WebSecurityLab·
We’ve published Volume I of our ByteToBreach campaign analysis: a full technical post-mortem of the Sterling Bank Plc breach. This report reconstructs the complete attack chain from initial access (March 18, 2026) through to the Cardinal Stone pivot.
Web Security Lab tweet media
English
1
3
6
512
Web Security Lab
Web Security Lab@WebSecurityLab·
5. 3,009 employee records enumerated via an unauthenticated API endpoint. 6. Cardinal Stone Partners’ investment database accessed via phpMyAdmin with no network isolation. The report is written for security professionals, CISOs, incident responders, and regulators.
English
1
0
0
117
Web Security Lab
Web Security Lab@WebSecurityLab·
We’ve published Volume I of our ByteToBreach campaign analysis: a full technical post-mortem of the Sterling Bank Plc breach. This report reconstructs the complete attack chain from initial access (March 18, 2026) through to the Cardinal Stone pivot.
Web Security Lab tweet media
English
1
3
6
512
Web Security Lab
Web Security Lab@WebSecurityLab·
The affected subdomains were used for SEO spam hosting and redirect-based monetisation infrastructure for an extended period prior to remediation. We found no evidence of intrusion into core NIMC systems. Internal impact assessment remains the responsibility of NIMC.
Web Security Lab tweet media
English
1
0
0
36
Web Security Lab
Web Security Lab@WebSecurityLab·
Web Security Lab has identified and documented coordinated subdomain abuse affecting multiple hosts under the National Identity Management Commission (NIMC) domain namespace.
Web Security Lab tweet media
English
1
0
0
65
Web Security Lab
Web Security Lab@WebSecurityLab·
The incident was identified and responsibly disclosed. Following escalation to the authoritative DNS operator, the affected subdomain was taken offline. 📝 Read the full report here: websecuritylab.org/wp-content/upl…
English
0
0
0
40
Web Security Lab
Web Security Lab@WebSecurityLab·
Hundreds of indexed pages were identified, generating search visibility under a trusted government domain and increasing the likelihood of public exposure.
Web Security Lab tweet media
English
1
0
0
26
Web Security Lab
Web Security Lab@WebSecurityLab·
Web Security Lab has published a technical incident report on a subdomain takeover involving the Nigeria Police Service Commission website infrastructure.
Web Security Lab tweet media
English
1
0
0
63
Web Security Lab
Web Security Lab@WebSecurityLab·
From all of us at Web Security Lab, we wish everyone a Merry Christmas and a safe, secure, and uninterrupted holiday season.
Web Security Lab tweet media
English
0
1
0
70
Web Security Lab
Web Security Lab@WebSecurityLab·
As a certified cybersecurity professional, Jack brings emerging professional capability to Africa’s growing cybersecurity workforce. He represents a new generation of practitioners supporting secure digital growth across the continent.
English
0
0
1
45
Web Security Lab
Web Security Lab@WebSecurityLab·
Big congratulations to @Cy_berJack, one of our Fellows, on passing the CompTIA Security+ certification. Jack is a Fellow of the Web Security Lab Professional Security Fellowship, a structured program focused on developing practical security capability & professional readiness.
Web Security Lab tweet mediaWeb Security Lab tweet media
English
1
2
6
144
Web Security Lab รีทวีตแล้ว
David Odes
David Odes@chiefdavidsays·
Mariam Ibrahim, a corps member, was arrested in October 2025 after the Nigerian Police claimed that a number tied to a January 2024 kidnapping case was linked to her National Identity Number (NIN). There was just one obvious problem: she bought the SIM card in April 2025. I spoke to The Punch Newspaper about how Nigeria’s MSISDN lifecycle management allows new SIM owners to inherit the digital footprint and criminal exposure of previous owners, and why our identity verification infrastructure needs stronger procedural safeguards around number reassignment and investigative protocols. punchng.com/marked-identit…
David Odes tweet mediaDavid Odes tweet mediaDavid Odes tweet mediaDavid Odes tweet media
English
0
15
15
15K
Web Security Lab
Web Security Lab@WebSecurityLab·
That’s why conversations like this matter, and why we’re proud to contribute our voice to the broader ecosystem work shaping Africa’s digital future and strengthening a safer, more accountable internet for everyone.
English
0
0
0
33
Web Security Lab
Web Security Lab@WebSecurityLab·
This Saturday, our Founder David Odes joins industry leaders at the Global Data Protection Tech Summit in Lagos. Stronger digital ecosystems grow when people understand how their data is collected, used, and protected—and when organisations act responsibly.
Web Security Lab tweet media
English
1
3
2
203
Web Security Lab
Web Security Lab@WebSecurityLab·
Building cybersecurity capacity begins with people. A stronger, safer digital Africa starts with education and collaboration.
Web Security Lab tweet mediaWeb Security Lab tweet media
English
0
0
1
36
Web Security Lab
Web Security Lab@WebSecurityLab·
ISO 27701:2025 separates privacy from security. The update removes the need for ISO 27001 certification, allowing independent privacy certification. With strengthened governance and leadership requirements, businesses can now adapt more easily. websecuritylab.org/what-every-bus…
Web Security Lab tweet media
English
0
1
0
52