Home / Blog
Field notes from the engagements
Blog
What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.
Application Security
The Same Flaws Keep Entering at the Code Stage. Here Is What We Put in the Way.
Across the assessments and code reviews we run, the same security problems enter systems at the code stage - sometimes without the developers being aware of it at…
Read itEngagements and Process
“Just Send Me a Quote and We’ll See” – Why I Don’t Work That Way
A prospective client asked for a price before telling me what the systems do. In security testing, a quote without a scope is a guess, and the person…
Read itApplication Security
PHP Security Code Review Cheat Sheet
In today’s development landscape among our customers, it’s rare to encounter production PHP code. However, when we do, the story is always the same. Typically, such code is…
Read itCloud Security
Still Using SSRF to Take Over Cloud Deployments Once Again
How Server-Side Request Forgery Can Lead to Full Cloud Compromise - and What You Can Do About It Contents Introduction Server-Side Request Forgery (SSRF) is a powerful exploit…
Read itAI and LLM Security
How Prompt Injection Actually Works, in Two Requests
User input gets planted inside a prompt the server sends to the model. From there the road to prompt injection is very short - and MathGPT's API key…
Read itApplication Security
ReDoS
How a Simple Test Brought Down a Server You sanitized your input fields for XSS? You might have opened a new door for attackers… Imagine this: You're a…
Read itMobile Security
Hacking Android Apps Through Exposed Components
by Tal Melamed In almost every Android application, developers expose activities without sufficient protections. Exposing activities can lead to various attacks. For example, an attacker or a malicious…
Read itApplication Security
Cryptography as a Solution – Using Advanced Techniques for Data Protection
Introduction to Data Protection In the world of information security it is highly advised to implement security solutions in layers. Solutions such as authentication, authorization, input validation and…
Read itSupply Chain
Secure Development Lifecycle for Open Source Usage
Secure Development Lifecycle for Open Source Usage by Yaron HakonPrefaceHow do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems…
Read itAuthorization and Access Control
Sandwich Attacks: From Reset Password to Account Takeover
Once Upon a Password Reset… You’ve just forgotten your password for a website. No big deal, you click "Forgot Password," they send you a link, and you reset…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.