<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Security insights | MoShield</title><link>https://moshieldapp.com/en/blog/</link><description>Practical website and API security guidance for small businesses. Understand the scope, ask better questions and turn findings into improvements.</description><language>en</language><item><title>Website security checklist for small businesses</title><link>https://moshieldapp.com/en/blog/website-security-checklist/</link><guid>https://moshieldapp.com/en/blog/website-security-checklist/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Start with the public services you operate, the data they handle and the people responsible for them. A useful security check ends with assigned remediation work, not just a scanner score.</description></item><item><title>Black-box security testing vs vulnerability scanning</title><link>https://moshieldapp.com/en/blog/black-box-testing-vs-scanning/</link><guid>https://moshieldapp.com/en/blog/black-box-testing-vs-scanning/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Black-box describes the tester&#39;s visibility into a system. Automated scanning describes a technique. They are not competing labels: a scoped assessment can use both automation and manual investigation.</description></item><item><title>How to prepare for an authorized website security test</title><link>https://moshieldapp.com/en/blog/prepare-authorized-security-test/</link><guid>https://moshieldapp.com/en/blog/prepare-authorized-security-test/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Before testing, agree the assets, permitted actions, time window and emergency contact. A clear operating plan helps the business and tester recognize when to pause rather than improvise.</description></item><item><title>API authorization: why login is not enough</title><link>https://moshieldapp.com/en/blog/api-object-authorization/</link><guid>https://moshieldapp.com/en/blog/api-object-authorization/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Authentication tells an application who the user is. Object-level authorization decides whether that user may access the specific record being requested. Both are needed in a customer-facing API.</description></item><item><title>Secure file uploads for contact and consultation forms</title><link>https://moshieldapp.com/en/blog/secure-file-upload-forms/</link><guid>https://moshieldapp.com/en/blog/secure-file-upload-forms/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Treat an uploaded attachment as untrusted data. File checks, private storage and controlled retrieval serve different purposes; accepting only a familiar extension is not a complete upload policy.</description></item><item><title>Login security: review recovery as well as passwords</title><link>https://moshieldapp.com/en/blog/login-security-basics/</link><guid>https://moshieldapp.com/en/blog/login-security-basics/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>A login review should include account recovery and sensitive account changes, not only the sign-in screen. A strong primary login can still be undermined by a weaker recovery path.</description></item><item><title>HTTPS is essential, but it is not a website security audit</title><link>https://moshieldapp.com/en/blog/https-is-not-a-security-audit/</link><guid>https://moshieldapp.com/en/blog/https-is-not-a-security-audit/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>HTTPS protects communication in transit. It does not decide whether a logged-in customer may read another customer&#39;s record or whether an uploaded document is stored privately.</description></item><item><title>How to prioritize website security fixes with a small team</title><link>https://moshieldapp.com/en/blog/prioritize-security-fixes/</link><guid>https://moshieldapp.com/en/blog/prioritize-security-fixes/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Prioritize with both technical evidence and business context. A severity label is a starting point for discussion, not a substitute for knowing what is exposed and who can fix it.</description></item><item><title>How to read a website security report as a business owner</title><link>https://moshieldapp.com/en/blog/read-a-security-report/</link><guid>https://moshieldapp.com/en/blog/read-a-security-report/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>Read the scope and limitations before the findings count. Then identify which issues need a business decision, which need engineering work and which still need clarification.</description></item><item><title>Security retesting: what to check after a fix</title><link>https://moshieldapp.com/en/blog/security-retesting-after-fixes/</link><guid>https://moshieldapp.com/en/blog/security-retesting-after-fixes/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>A fix should be verified in the environment where it matters. Retesting should confirm the original problem is addressed and that expected legitimate behavior still works.</description></item></channel></rss>