Skip to content
Book a call

Home / Blog

Field notes from the engagements

Blog

What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.

Application Security

We checked 1,237 fixes. One in four was not fixed.

Between October 2021 and August 2026 our clients sent 1,237 fixes back to us and asked us to confirm they worked. 307 of them did not.That is more…

Read it

Application Security

What 890 security engagements actually find

6,048 findings across 700 tests. The most common are configuration and hygiene. The most dangerous are authorization - 133 high and critical, against 115 for XSS.

Read it

AI and LLM Security

Somebody Wired the Darknet Into Your AI. What Could Go Wrong?

One MCP server packing 66 tools, feeding onion-site content straight into your model's context. The darknet is the most hostile input that exists, and a model cannot tell…

Read it

Authorization and Access Control

Configured Is Not Enforced

AWS shipped four condition keys for DynamoDB and did not evaluate them at runtime. Your policy sat there, looked excellent in code, and did nothing.

Read it

AI and LLM Security

Every Week Someone Asks Me When AI Will Replace Pentesters

Datadog released a scanner that sends your code to an LLM instead of matching patterns. After 20 years in this field: the engine was never the problem. What…

Read it

Application Security

The Most Expensive Vulnerability Is a Token Nobody Rotated

No sophisticated SQL injection. No state actor with three APT teams. A developer pushed code with a secret in it, and a drug worth billions walked out.

Read it

Cloud Security

Cloud Ransomware: Soft-Delete and Versioning Are the Whole Story

One over-permissioned Service Principal leaked through an old configuration, and we could read, delete, replace and encrypt every blob. The difference between 'restored in five minutes' and 'we…

Read it

Engagements and Process

Learn Mode and Enforce Mode Are Sold in the Same Breath. They Are Not the Same Thing.

An agent that scans, finds and proposes, with a human deciding, is where the field should go. An agent that writes and applies exploits on production, unattended, is…

Read it

Supply Chain

One Click, and Every Private Repo You Can Reach Is Theirs

A link, inside the tool you use every day. Simulated keystrokes install an extension, which lifts the GitHub OAuth token - and that token is not scoped to…

Read it

Cloud Security

Attackers Are Running Their C2 on Your Cloud, and You Are Paying for It

No fixed IP to block. No suspicious infrastructure for the SIEM to catch. The traffic belongs to Amazon and the invoice arrives at the end of the month…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue