Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    API Security

    • Home
    • Blog
    • API Security
    API Security

    We Found an SSRF at a Client — What It Is, and Why It Matters

    September 30, 2025 No comments yet

    A short, practical explanation of Server-Side Request Forgery, prompted by a finding in one of our engagements.

    API Security

    Why Message Queues Keep Failing Their Penetration Test

    September 1, 2025 No comments yet

    Every microservice shared one credential with publish and subscribe on every channel. One foothold, one forged message, and a refund was issued – with no authorization at all.

    API Security

    Rate Limiting: The Control Everyone Agrees On and Nobody Implements

    July 21, 2025 No comments yet

    A standard registration form with no limit on requests per minute. A bot fired tens of thousands, flooded the mail queue, and harvested hundreds of real usernames out of the API’s own answers.

    Web Services Testing
    API Security

    Web Services Testing: Safeguarding Your Web Applications Against XXE Attacks

    June 8, 2025 AppSec Labs No comments yet

    As organizations increasingly rely on web services, particularly SOAP-based services, ensuring robust security through meticulous Web Services Testing has become critical. One common and significant vulnerability in these services is XML External Entity (XXE) Injection. This guide will demonstrate how comprehensive Web Services Testing can identify and mitigate such risks. What is XML External Entity […]

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy