Skip to content
Book a call

Home / Blog / Application Security

Category

Application Security

Application penetration testing write-ups from real engagements, by the people who ran them.

Application Security

We checked 1,237 fixes. One in four was not fixed.

Between October 2021 and August 2026 our clients sent 1,237 fixes back to us and asked us to confirm they worked. 307 of them did not.That is more…

Read it

Application Security

What 890 security engagements actually find

6,048 findings across 700 tests. The most common are configuration and hygiene. The most dangerous are authorization - 133 high and critical, against 115 for XSS.

Read it

Application Security

The Most Expensive Vulnerability Is a Token Nobody Rotated

No sophisticated SQL injection. No state actor with three APT teams. A developer pushed code with a secret in it, and a drug worth billions walked out.

Read it

Application Security

What Is Real-Time Penetration Testing And Why It Matters

One quiet vulnerability can be tomorrow’s headline, and the clock is always in the attackers’ favor. IBM’s 2025 Cost of a Data Breach Report just discovered the average global…

Read it

Application Security

A Medical Device on End-of-Life Linux: What You Do When You Cannot Patch

Hundreds of thousands of devices in hospitals, an unsupported Linux, and no vendor patches. Removing packages that were never used cut roughly half the problem before we touched…

Read it

Application Security

Almost Every Real Penetration Test Starts by Hunting for Secrets

An API key left in git. A token embedded in an image or a PDF. A config.old.js somebody forgot to delete. Google open-sourced a secret scanner, and it…

Read it

Application Security

The Ultimate Guide to Securing Applications Through Software Security Testing

Software application security testing is essential in safeguarding applications against vulnerabilities and potential cyber-attacks. With increasing threats, ensuring the security of applications through thorough testing is crucial for…

Read it

Application Security

The Same Flaws Keep Entering at the Code Stage. Here Is What We Put in the Way.

Across the assessments and code reviews we run, the same security problems enter systems at the code stage - sometimes without the developers being aware of it at…

Read it

Application Security

PHP Security Code Review Cheat Sheet

In today’s development landscape among our customers, it’s rare to encounter production PHP code. However, when we do, the story is always the same. Typically, such code is…

Read it

Application Security

ReDoS

How a Simple Test Brought Down a Server You sanitized your input fields for XSS? You might have opened a new door for attackers… Imagine this: You're a…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue