Application Security
We checked 1,237 fixes. One in four was not fixed.
Between October 2021 and August 2026 our clients sent 1,237 fixes back to us and asked us to confirm they worked. 307 of them did not.That is more…
Read itApplication Security
What 890 security engagements actually find
6,048 findings across 700 tests. The most common are configuration and hygiene. The most dangerous are authorization - 133 high and critical, against 115 for XSS.
Read itApplication Security
The Most Expensive Vulnerability Is a Token Nobody Rotated
No sophisticated SQL injection. No state actor with three APT teams. A developer pushed code with a secret in it, and a drug worth billions walked out.
Read itApplication Security
What Is Real-Time Penetration Testing And Why It Matters
One quiet vulnerability can be tomorrow’s headline, and the clock is always in the attackers’ favor. IBM’s 2025 Cost of a Data Breach Report just discovered the average global…
Read itApplication Security
A Medical Device on End-of-Life Linux: What You Do When You Cannot Patch
Hundreds of thousands of devices in hospitals, an unsupported Linux, and no vendor patches. Removing packages that were never used cut roughly half the problem before we touched…
Read itApplication Security
Almost Every Real Penetration Test Starts by Hunting for Secrets
An API key left in git. A token embedded in an image or a PDF. A config.old.js somebody forgot to delete. Google open-sourced a secret scanner, and it…
Read itApplication Security
The Ultimate Guide to Securing Applications Through Software Security Testing
Software application security testing is essential in safeguarding applications against vulnerabilities and potential cyber-attacks. With increasing threats, ensuring the security of applications through thorough testing is crucial for…
Read itApplication Security
The Same Flaws Keep Entering at the Code Stage. Here Is What We Put in the Way.
Across the assessments and code reviews we run, the same security problems enter systems at the code stage - sometimes without the developers being aware of it at…
Read itApplication Security
PHP Security Code Review Cheat Sheet
In today’s development landscape among our customers, it’s rare to encounter production PHP code. However, when we do, the story is always the same. Typically, such code is…
Read itApplication Security
ReDoS
How a Simple Test Brought Down a Server You sanitized your input fields for XSS? You might have opened a new door for attackers… Imagine this: You're a…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.