Skip to content
  • About
  • Our Services
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • Blog

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

Edit Content

    Brute Force

    • Home
    • Blog
    • Brute Force
    Brute Force

    What Is Real-Time Penetration Testing And Why It Matters

    January 25, 2026 Lior Gershon No comments yet

    One quiet vulnerability can be tomorrow’s headline, and the clock is always in the attackers’ favor. IBM’s 2025 Cost of a Data Breach Report just discovered the average global breach cost, not surprisingly, is $4.44 million, which obviously highlights how expensive “later” can be. Penetration testing mitigates that risk by imitating actual attacks so that exploitable holes crop […]

    Still Using SSRF to Take Over Cloud Deployments Once Again
    Brute Force

    Still Using SSRF to Take Over Cloud Deployments Once Again

    January 16, 2025 Michael Yermakov No comments yet

    How Server-Side Request Forgery Can Lead to Full Cloud Compromise – and What You Can Do About It Introduction Server-Side Request Forgery (SSRF) is a powerful exploit that enables attackers to trick a vulnerable server into making arbitrary HTTP requests on their behalf. While some view SSRF as merely a method to force the server […]

    Brute Force

    Hacking Android Apps Through Exposed Components

    December 25, 2024 AppSec Labs No comments yet

    by Tal Melamed In almost every Android application, developers expose activities without sufficient protections. Exposing activities can lead to various attacks. For example, an attacker or a malicious app installed on the same device, can call those exposed activities to invoke internal pages of the application. Calling internal pages puts the application at risk of […]

    Brute Force

    Cryptography as a Solution – Using Advanced Techniques for Data Protection

    December 24, 2024 AppSec Labs No comments yet

    Introduction to Data Protection In the world of information security it is highly advised to implement security solutions in layers. Solutions such as authentication, authorization, input validation and others help us maintain order and security when dealing with access to data. It is important to note that these techniques do not help with the data […]

    Brute Force

    Secure Development Lifecycle for Open Source Usage

    December 24, 2024 AppSec Labs No comments yet

    Secure Development Lifecycle for Open Source Usage     by Yaron Hakon Preface How do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems we develop and maintain? This is a question I hear a lot lately from our customers in some recent SDL projects we […]

    Black Box Testing, Brute Force, Hacking

    Sandwich Attacks: From Reset Password to Account Takeover

    December 18, 2024 Nathan Touati No comments yet

    Once Upon a Password Reset… You’ve just forgotten your password for a website. No big deal, you click “Forgot Password,” they send you a link, and you reset it. At the time the feature was designed, it was decided that this reset link would include a UUID token. The reasoning seemed sound—since UUIDs are unique, […]

    Search

    Categories

    • Black Box Testing (5)
    • Brute Force (6)
    • Code Review (1)
    • Hacking (11)
    • White Box Testing (4)

    Recent posts

    • Is Your AI Secure? The Dark Reality of LLM Vulnerabilities
    • Securing the Lifeline: A Guide to Medical Device Penetration Testing
    • What Is Real-Time Penetration Testing And Why It Matters

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • Guy Nachum (CRO):
    • guy@appsec-labs.com
    • +972 52-433-9393
    • Sales:
    • sales@appsec-labs.com
    • General Requests:
    • info@appsec-labs.com

    © AppSec Labs 2024. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy