<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software testing security testing tutorials and videos</title>
	<atom:link href="https://www.softwaretestingmagazine.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.softwaretestingmagazine.com</link>
	<description></description>
	<lastBuildDate>Tue, 02 Dec 2025 16:49:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.softwaretestingmagazine.com/wp-content/uploads/favicon.png</url>
	<title>Software testing security testing tutorials and videos</title>
	<link>https://www.softwaretestingmagazine.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Critical Role of Security Testing in IoT Projects</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/the-critical-role-of-security-testing-in-iot-projects/</link>
					<comments>https://www.softwaretestingmagazine.com/knowledge/the-critical-role-of-security-testing-in-iot-projects/#comments</comments>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 17 Nov 2025 17:59:36 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10774</guid>

					<description><![CDATA[<p>Connectivity today reaches far beyond desktops and smartphones. The Internet of Things (IoT) now powers smart homes, industrial automation, automotive systems, medical devices, and nationwide infrastructure. Yet this expanded digital footprint also widens the attack surface-which in the context of IoT means cyberattacks can escalate into physical consequences. Author: Bohdan Savchuk, CTO of Anbosoft, https://www.anbosoft.net/ Security testing in IoT projects is no longer optional. It is a structural requirement for systems that interact with the physical world, collect sensitive data, and operate across heterogeneous environments. This article explores the importance of IoT security testing, the challenges unique to connected devices, and strategies QA, cybersecurity, and automation teams should adopt to build resilient IoT ecosystems. Why IoT Security Testing Matters 1. Physical Consequences and Cascading Failures Traditional software failures are inconvenient; IoT failures can be catastrophic. IoT devices frequently control or monitor realworld systems: HVAC units, manufacturing robots, medical pumps, vehicle components. A compromised device can trigger dangerous actions, cause property damage, or put human life at risk. Because IoT devices typically communicate in real time, vulnerabilities in a single node can cascade into broader system disruptions. One weak endpoint becomes a pivot point, enabling attackers to reach gateways, cloud APIs, internal networks, or other connected devices. 2. Extreme Heterogeneity and Scale IoT ecosystems span thousands (or millions) of devices varying in operating systems, hardware capabilities, communication protocols, and firmware maturity. Unlike conventional IT systems, there is no uniform baseline. This diversity makes security testing exponentially more complex: Devices with limited <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/the-critical-role-of-security-testing-in-iot-projects/" title="The Critical Role of Security Testing in IoT Projects">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/the-critical-role-of-security-testing-in-iot-projects/">The Critical Role of Security Testing in IoT Projects</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
					<wfw:commentRss>https://www.softwaretestingmagazine.com/knowledge/the-critical-role-of-security-testing-in-iot-projects/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Industrializing MFA Testing and Introduction to RPA [Part 3/3]</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/industrializing-mfa-testing-and-introduction-to-rpa-part-3-3/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 20:01:39 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[test automation]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10310</guid>

					<description><![CDATA[<p>We continue our series of articles dedicated to testing systems that integrate Multi-Factor Authentication (MFA or 2FA) security mechanisms! In our first article, we explored how Multi-Factor Authentication (MFA) has become an essential standard for securing online applications and services. Its widespread adoption helps strengthen user account protection against cyberattacks. Increasingly, companies are focusing on implementing these measures, which are becoming mandatory, particularly within the financial sector. However, within enterprises, integrating MFA presents a significant challenge for automated testing. MFA workflows should not simply be disabled in test and UAT environments, as doing so could compromise the reliability of functional validations by creating a scenario that deviates from production conditions (potentially leading to the late discovery of previously untested issues). Therefore, tests must include Multi-Factor Authentication to ensure an experience as close as possible to the real production environment. In the second article, we discussed various strategies for automating these MFA tests. We also introduced tools such as GetMyMFA, MailSlurp, and Receive-SMS-Free.cc, which facilitate automation for receiving and processing MFA codes. In this third article, we will examine how test teams can effectively collaborate in these complex scenarios and how automation through Robotic Process Automation (RPA) can simplify processes that have traditionally been handled manually in production. 1. Using webhooks for collaborative working Automating MFA tests does not eliminate the need to perform manual tests. These tests often involve teams working together on shared accounts, especially when handling codes sent via email, SMS, or TOTP applications. Accessing these codes collaboratively <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/industrializing-mfa-testing-and-introduction-to-rpa-part-3-3/" title="Industrializing MFA Testing and Introduction to RPA [Part 3/3]">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/industrializing-mfa-testing-and-introduction-to-rpa-part-3-3/">Industrializing MFA Testing and Introduction to RPA [Part 3/3]</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Next-Gen Security Testing: How AI and Machine Learning Are Shaping Cybersecurity</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/next-gen-security-testing-how-ai-and-machine-learning-are-shaping-cybersecurity/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Thu, 27 Mar 2025 17:46:12 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10211</guid>

					<description><![CDATA[<p>Cyberattacks are becoming more advanced and are occurring more often, with the cost of cybercrime expected to reach $15.63 trillion by 2029. Older security methods just can&#8217;t keep up with evolving threats, which is where Artificial Intelligence (AI) and Machine Learning (ML) come in. Equipped with advanced systems, these technologies can spot and prevent threats before they happen, leading to smarter and faster security. Businesses are working harder to protect themselves. For example, the average spends on cybersecurity by Fortune 500 companies is approximately $20 million, which includes encryption and fraud detection tools to protect customer accounts. The iGaming sector, for instance, invests heavily in cybersecurity. Online casinos offer players real-money games, which require personal details and financial transactions. Naturally, players expect a secure and trustworthy experience. As writer Liliana Costache from Card Player points out, the best online casinos offer a legal and safe gaming experience with fast withdrawals and reliable payment options, including cryptocurrencies that provide enhanced security and privacy (Source:https://www.cardplayer.com/online-casinos). With online gambling becoming more popular, ensuring safety and transparency is now a top priority for both players and operators. The Evolution of Security Testing Cyberattacks are happening more often and are getting more advanced. Ransomware, for example, hackers lock up your data and demand payment to unlock it. Older tools like firewalls and antivirus programs can&#8217;t handle today&#8217;s threats, so smarter and more adaptable security solutions are needed. A big challenge is human error. Simple mistakes, like setting up a system incorrectly or missing security issues, <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/next-gen-security-testing-how-ai-and-machine-learning-are-shaping-cybersecurity/" title="Next-Gen Security Testing: How AI and Machine Learning Are Shaping Cybersecurity">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/next-gen-security-testing-how-ai-and-machine-learning-are-shaping-cybersecurity/">Next-Gen Security Testing: How AI and Machine Learning Are Shaping Cybersecurity</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Automate your E2E Tests: Overcoming MFA Workflow Testing Challenges [Part 2/3]</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/automate-your-e2e-tests-overcoming-mfa-workflow-testing-challenges/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 24 Mar 2025 15:59:43 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[test automation]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10200</guid>

					<description><![CDATA[<p>We continue our series of articles focused on testing systems that incorporate Multi-Factor Authentication (MFA or 2FA) security mechanisms. In our previous article about MFA testing, we explored why companies operating in regulated industries must adopt these mechanisms to strengthen their security. Although there is a wide range of MFA solutions available, most companies favor those that provide a smooth and simple user experience, such as MFA via SMS, email, or TOTP. In this article, we will delve into a crucial topic: what are the challenges related to testing workflows that include MFA, and what strategies can be adopted to overcome them? 1. Key Challenges in MFA Test Automation 1.1 Dependency on External Devices By design, MFA relies on external devices, such as phones for receiving SMS or apps for generating TOTP codes. This reliance complicates test automation, especially when multiple accounts are involved: Email MFA: QA teams commonly use alias-based email structures (e.g., user+alias@domain.com) to streamline account creation. However, these methods might be limited or disabled in corporate settings, complicating automation efforts. On top of that, retrieving emails from third-party providers is a challenge. SMS MFA: Each user account typically requires a unique phone number. This leads to logistical issues, such as managing physical SIM cards or sharing test phones, which undermines efficiency and scalability. Ever had to call your colleague so they can share the MFA code retrieved on their phone? TOTP MFA: Time-based One-Time Passwords require secure handling of private keys. Automating tests becomes intricate, as these <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/automate-your-e2e-tests-overcoming-mfa-workflow-testing-challenges/" title="Automate your E2E Tests: Overcoming MFA Workflow Testing Challenges [Part 2/3]">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/automate-your-e2e-tests-overcoming-mfa-workflow-testing-challenges/">Automate your E2E Tests: Overcoming MFA Workflow Testing Challenges [Part 2/3]</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Multi-Factor-Authentication Security and the Testing World &#8211; Are They Compatible?</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/multi-factor-authentication-security-and-the-testing-world-are-they-compatible/</link>
					<comments>https://www.softwaretestingmagazine.com/knowledge/multi-factor-authentication-security-and-the-testing-world-are-they-compatible/#comments</comments>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 03 Mar 2025 16:53:02 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[test automation]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10146</guid>

					<description><![CDATA[<p>Welcome to this series of three articles dedicated to an in-depth analysis of testing systems that integrate multi-factor authentication (MFA) mechanisms. If you work in a regulated entity, particularly in the financial or banking sectors, you have likely faced the challenges associated with testing MFA-protected workflows such as authentication and financial transactions. Often, the common solution is to disable these mechanisms and only test them occasionally. We&#8217;ll see during the coming articles that this can be considered a bad practice. Author: Jonathan Bernales This series of articles is designed to provide you with a detailed and practical understanding of the constraints and best practices in this area. The series consists of three articles: Introduction (today&#8217;s article): Understanding what MFA is, and why it&#8217;s becoming more and more popular on your everyday apps. Constraints of MFA in Testing and Automation Solutions (next article): Testing MFA flows rather than skipping them or disabling security. We&#8217;ll talk about tools like GetMyMFA, Bitwarden and &#8220;plus email addressing&#8220;. Further Exploration (last article): Robotic Process Automation (RPA) and integration with third party services for team collaboration. We&#8217;ll talk about Webhooks and UIPath amongst other things. The goal is to provide you with the necessary tools to effectively approach MFA in your testing projects, regardless of whether you&#8217;re working through &#8220;manual&#8221; processes with your team or implementing front-end or API End-To-End tests. 1. Context A. What is MFA, and What Is It For? MFA (Multi-Factor Authentication) or 2FA (Two-Factor Authentication) is a security method requiring users to <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/multi-factor-authentication-security-and-the-testing-world-are-they-compatible/" title="Multi-Factor-Authentication Security and the Testing World &#8211; Are They Compatible?">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/multi-factor-authentication-security-and-the-testing-world-are-they-compatible/">Multi-Factor-Authentication Security and the Testing World – Are They Compatible?</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
					<wfw:commentRss>https://www.softwaretestingmagazine.com/knowledge/multi-factor-authentication-security-and-the-testing-world-are-they-compatible/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title>How to Safeguard Your App by Testing Who Gets Access</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/how-to-safeguard-your-app-by-testing-who-gets-access/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 20 Jan 2025 15:40:31 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=10069</guid>

					<description><![CDATA[<p>What does it mean to safeguard your app? It simply means preventing an infiltration by hackers. However, that&#8217;s only part of the definition. You also need to make sure that only the right people get access to the right data. Imagine if someone unauthorized were to gain access to your app &#8211; They could get all the sensitive user data and confidential information. Isn&#8217;t that scary? It is. And unfortunately, this happens all the time; not just because of weak passwords or unpatched software. It happens because of something called access control. This is why testing access control is important. We keep everything on our apps these days. From little games to help the time pass by faster to financial and health information. And without implementing and testing access control, there&#8217;s a huge risk of data leaks and breaches. Developers will often focus on building cool features and fixing bugs, but they&#8217;ll overlook access control testing because they&#8217;ll assume their code works as it should. And then it doesn&#8217;t because tiny little mistakes become major security issues. What Is Access Control Testing? In simple terms, this is a process that makes sure only authorized users can perform specific actions or access specific data within an app. It&#8217;s a very important factor in app security because it helps prevent unauthorized access to sensitive information. There are different types of access controls, like RBAC, ABAC, and DAC. Role-Based Access Control (RBAC) sets permissions based on the access roles of each individual user <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/how-to-safeguard-your-app-by-testing-who-gets-access/" title="How to Safeguard Your App by Testing Who Gets Access">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/how-to-safeguard-your-app-by-testing-who-gets-access/">How to Safeguard Your App by Testing Who Gets Access</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Top Software Testing Tools for Ensuring Security in Crypto Applications</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/top-software-testing-tools-for-ensuring-security-in-crypto-applications/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Fri, 30 Aug 2024 14:49:37 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=9782</guid>

					<description><![CDATA[<p>The Cryptography market is growing every day and therefore, the need for enhanced security in crypto applications has never been felt before. When using crypto applications, it is important to ensure their security due to the current increase in cyber threats. Some of the most effective means of doing this are through the utilization of high-end software testing tools for security. This article will be sharing the top software testing tools that every crypto application needs to have to protect itself. Introduction to Security in Crypto Applications The interest in cryptocurrencies has grown and attacks on crypto apps have increased too. Security is a big concern because a breach can lead to money loss and shake users&#8217; faith in the app. Take new tokens like BTC Bull Token as an example. They need to make sure their platforms are safe to protect investors&#8217; money. To keep these apps secure, developers need to run different tests using tools that spot and fix weak points. The Importance of Software Testing in Crypto Security Securing crypto applications is highly dependent on software testing. These tools prevent the risks from being activated in the first place and hence protect the user information, transactional information and the overall reliability of the application. Current users and developers of crypto applications are vulnerable to security threats, leading to loss of time, money and other resources if testing is not properly done. Static Application Security Testing (SAST) Tools Such tools as SAST are vital when it comes to <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/top-software-testing-tools-for-ensuring-security-in-crypto-applications/" title="Top Software Testing Tools for Ensuring Security in Crypto Applications">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/top-software-testing-tools-for-ensuring-security-in-crypto-applications/">Top Software Testing Tools for Ensuring Security in Crypto Applications</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Is a Penetration Test Necessary for SOC 2 Compliance?</title>
		<link>https://www.softwaretestingmagazine.com/knowledge/is-a-penetration-test-necessary-for-soc-2-compliance/</link>
		
		<dc:creator><![CDATA[Software Testing Magazine]]></dc:creator>
		<pubDate>Mon, 19 Aug 2024 14:48:53 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[Software Testing Articles & Tutorials]]></category>
		<category><![CDATA[security testing]]></category>
		<guid isPermaLink="false">https://www.softwaretestingmagazine.com/?p=9757</guid>

					<description><![CDATA[<p>Penetration testing, A.K.A pen testing, is a key element to cybersecurity assessments, especially if your company is working towards SOC 2 compliance. SOC 2 stands for Service Organization Controls 2, and was created by the American Institute of CPAs (AICPA). It outlines how businesses should be protecting their customers&#8217; data from unauthorized access, security incidents, and other vulnerabilities. We read about it in the headlines every day- cyberthreats and data breaches are on the rise, and are becoming more sophisticated by the day. While SOC 2 does not explicitly require penetration testing, it is highly recommended by auditors and industry experts as a way to validate security controls and tighten up overall security. So, let&#8217;s dive into why custom penetration testing is important for SOC 2 compliance, its benefits, and some best practices to keep in mind. First Thing&#8217;s First- What is SOC 2? To get SOC 2 attestation, you need to prove that every &#8220;I&#8221; is dotted and every &#8220;T&#8221; is crossed when it comes to all things data security. To do this, your company&#8217;s security controls are put under the microscope to assess whether you&#8217;re truly taking the safety and security of your customers&#8217; data seriously. This assessment revolves around five Trust Service Criteria (TSC): security, availability, processing integrity, confidentiality, and privacy. Here&#8217;s a quick rundown on the five Trust Service criteria and what they&#8217;re all about: Security: Making sure your systems are defended against unauthorized access, both physical and digital. And that you have solid measures in <a class="mh-excerpt-more" href="https://www.softwaretestingmagazine.com/knowledge/is-a-penetration-test-necessary-for-soc-2-compliance/" title="Is a Penetration Test Necessary for SOC 2 Compliance?">[...]</a></p>
The post <a href="https://www.softwaretestingmagazine.com/knowledge/is-a-penetration-test-necessary-for-soc-2-compliance/">Is a Penetration Test Necessary for SOC 2 Compliance?</a> first appeared on <a href="https://www.softwaretestingmagazine.com">Software Testing Magazine</a>.]]></description>
		
		
		
			</item>
	</channel>
</rss>
