Skip to content
Book a call

Home / Blog

Field notes from the engagements

Blog

What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.

AI and LLM Security

Exposed AI Agents Are the New Shadow IT – Except They Can Act

175,000 Ollama servers exposed to the internet, 8,000 MCP servers wide open, and 31% of those examined answering with no authentication at all. Same film, new cast -…

Read it

Cloud Security

Attackers Don’t Break Into Your Cloud. They Log In.

No exploit, no zero-day, nothing that trips an alert. A Cognito refresh token can be valid for ten years, and CloudTrail sees everything while understanding nothing.

Read it

AI and LLM Security

Prompt Injection Is the SQL Injection of the AI Era

In 2005 everyone built websites and few asked what happens if someone injects code into a text field. Today everyone builds AI agents, and few ask what happens…

Read it

Cloud Security

There Is No Safe Starter Kit. There Is Only One Nobody Has Tested Yet.

A starter kit that generates IAM roles with wildcard permissions on every resource. AWS's fix was to update the documentation.

Read it

Supply Chain

500 AI-Written Attacks, 90% Stopped by a Default Setting

An AI tool analysed 500 repositories and wrote a custom payload for each. Then it waited for GitHub Actions to run them automatically - which GitHub does not…

Read it

AI and LLM Security

AI Wrote the Code. The CVE Is Still Yours.

Researchers traced real CVEs back through git blame to the commit that introduced them, then checked whether AI wrote it. Code that arrives looking perfect is exactly the…

Read it

Engagements and Process

I Run a Company of Pentesters, and I Watch AI Bots Doing Their Job

Faster, cheaper, and far more of it. The question is not whether AI replaces pentesters - it is which pentesters survive, and what they will need to be…

Read it

AI and LLM Security

Is Your AI Secure? The Dark Reality of LLM Vulnerabilities

Cyber attacks targeting large language model (LLM) based applications are increasing in both frequency and sophistication. Misconfigured chatbots, exposed APIs, and weak integrations with web, cloud, and mobile…

Read it

Supply Chain

A Regex Without Anchors, and a Race to Register a GitHub Account

A webhook filter checked ACTOR_ID with a regex that had no ^ or $. Substring match was enough. This is not a regex mistake - it is a…

Read it

Application Security

What Is Real-Time Penetration Testing And Why It Matters

One quiet vulnerability can be tomorrow’s headline, and the clock is always in the attackers’ favor. IBM’s 2025 Cost of a Data Breach Report just discovered the average global…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue