Skip to content
Book a call

Home / Blog

Field notes from the engagements

Blog

What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.

Application Security

The Same Flaws Keep Entering at the Code Stage. Here Is What We Put in the Way.

Across the assessments and code reviews we run, the same security problems enter systems at the code stage - sometimes without the developers being aware of it at…

Read it

Engagements and Process

“Just Send Me a Quote and We’ll See” – Why I Don’t Work That Way

A prospective client asked for a price before telling me what the systems do. In security testing, a quote without a scope is a guess, and the person…

Read it

Application Security

PHP Security Code Review Cheat Sheet

In today’s development landscape among our customers, it’s rare to encounter production PHP code. However, when we do, the story is always the same. Typically, such code is…

Read it

Cloud Security

Still Using SSRF to Take Over Cloud Deployments Once Again

How Server-Side Request Forgery Can Lead to Full Cloud Compromise - and What You Can Do About It Contents Introduction Server-Side Request Forgery (SSRF) is a powerful exploit…

Read it

AI and LLM Security

How Prompt Injection Actually Works, in Two Requests

User input gets planted inside a prompt the server sends to the model. From there the road to prompt injection is very short - and MathGPT's API key…

Read it

Application Security

ReDoS

How a Simple Test Brought Down a Server You sanitized your input fields for XSS? You might have opened a new door for attackers… Imagine this: You're a…

Read it

Mobile Security

Hacking Android Apps Through Exposed Components

by Tal Melamed In almost every Android application, developers expose activities without sufficient protections. Exposing activities can lead to various attacks. For example, an attacker or a malicious…

Read it

Application Security

Cryptography as a Solution – Using Advanced Techniques for Data Protection

Introduction to Data Protection In the world of information security it is highly advised to implement security solutions in layers. Solutions such as authentication, authorization, input validation and…

Read it

Supply Chain

Secure Development Lifecycle for Open Source Usage

Secure Development Lifecycle for Open Source Usage  by Yaron HakonPrefaceHow do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems…

Read it

Authorization and Access Control

Sandwich Attacks: From Reset Password to Account Takeover

Once Upon a Password Reset… You’ve just forgotten your password for a website. No big deal, you click "Forgot Password," they send you a link, and you reset…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue