Home / Blog
Field notes from the engagements
Blog
What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.
AI and LLM Security
AI-Driven Penetration Testing For Evolving Threats: A CISO Guide
Cyber threats don’t wait for next quarter’s test cycle. Verizon DBIR 2025 coverage shows attackers exploit vulnerabilities in about 5 days on average, while organizations take a median…
Read itApplication Security
A Medical Device on End-of-Life Linux: What You Do When You Cannot Patch
Hundreds of thousands of devices in hospitals, an unsupported Linux, and no vendor patches. Removing packages that were never used cut roughly half the problem before we touched…
Read itAI and LLM Security
The Attack Surface Used to Be Code. Now Part of It Is a Conversation.
A scanner for MCP servers sent me down a longer thought. We are used to an attack surface made of code, configuration and permissions. Some of it is…
Read itSupply Chain
The Coding Test That Was a Payload: Attacking Developers Through Trust
A real profile, a real company, a clean Bitbucket repo. Thirty seconds before running it, he asked an AI to check the code - and found an obfuscated…
Read itAI and LLM Security
When the AI Builds Your API Call: IDOR and SSRF, One Layer Up
A document-management system let its internal AI engine turn free text into internal API calls. The result was IDOR - except the input came from a model, not…
Read itAuthorization and Access Control
A JWT That Trusted the Client: How One Shortcut Became Full Admin Access
A penetration test where a JWT carried the user's role in its payload and the server trusted it. Changing one field - and an allowed alg:none - turned…
Read itAPI Security
We Found an SSRF at a Client — What It Is, and Why It Matters
A short, practical explanation of Server-Side Request Forgery, prompted by a finding in one of our engagements.
Read itAI and LLM Security
The Chatbot That Called Our Admin API: LLM Function Calls Without Access Control
A support chatbot was wired straight into the backend with no access-control layer between them. Asking it politely for a little extra produced a call to /api/admin/exportAllUsers.
Read itAuthorization and Access Control
A Valid Token Is Not a Permission: The OAuth Scope Nobody Checked
The Authorization Code flow was textbook. Then the server accepted any valid access token on an admin endpoint, whatever scope it carried - and I created an administrator.
Read itAI and LLM Security
Prompt Injection to Account Takeover: A Real Chain Through an AI Feature
A breach that chained three small weaknesses: blind use of an LLM, SSRF through prompt injection, and a weak JWT. Individually minor; together, full system access.
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.