MOL Move flaws let users turn accounts into employees
MOL Move field-level authorization flaws allowed role, email and loyalty data changes. We examine the facts, root cause and disclosure failure.
Penetration testing and application security across web, API, mobile, business logic, secure development, hardening and actionable evidence.
MOL Move field-level authorization flaws allowed role, email and loyalty data changes. We examine the facts, root cause and disclosure failure.
Why object-level authorization fails most often: overlooked IDOR variants, UUID myths, durable fix patterns, a testing method and log-based detection.
Why extension checks solve nothing: filenames, types, serving, parsers, archives and limits. A target upload pipeline and a practical testing method.
Parameters bind values, not identifiers, and every ORM has escape hatches. Where SQLi survives: sorting, reports, blind and second-order variants.
How SSTI differs from XSS, why a template engine sandbox is not a security boundary, and how to test, fix and detect this class of vulnerability.
Webhooks have two sides and two attack surfaces. How to verify signatures, block replay, design idempotency and avoid building SSRF on request.
How external entities turn an XML parser into a file reader and HTTP client. Where XML sneaks in, how to disable DTDs, and how to test and detect XXE.
GitHub has added AI detections to code scanning and a /security-review command. Understand the prerequisites, limitations and a safe rollout plan for engineering teams.
GitHub's 18-hour test exposed legacy TLS clients before permanent SHA-1 removal on 15 September. Find risk across Git, APIs, CI/CD and vendor integrations.
How professional web application penetration testing works: scope, OWASP methodology, reporting, retesting, pricing and vendor selection.
A practical API penetration testing checklist for REST, GraphQL, OAuth, JWT, BOLA, access control, rate limits, business logic, reporting and retesting.
A practical mobile app penetration testing guide covering Android, iOS, MASVS, MASTG, backend APIs, preparation, reporting and retesting.
A practical OWASP ASVS 5.0 guide covering L1–L3, versioned requirements, evidence, procurement, testing and implementation across a secure SDLC.
How much does a penetration test cost in 2026? Compare pricing factors, realistic scopes, deliverables and quotes without choosing a misleading bargain.
Red team or penetration test? Compare objectives, scope, duration, cost, detection goals and deliverables to choose the right security assessment.
Content Security Policy limits XSS impact. Learn Report-Only rollout, nonces, strict-dynamic, reporting and how to enforce a production CSP safely.
RFC 9700 updates OAuth 2.0 security. Learn PKCE, exact redirect URIs, token rotation, audience validation and a practical implementation checklist.
Vulnerability disclosure and bug bounty programs differ. Design safe harbor, scope, triage, SLAs, rewards and a responsible launch process.
Plan a cloud pentest within provider rules. Scope IAM, storage, networks, Kubernetes, serverless, CI/CD, logging and safe rules of engagement.
Memory-safe languages remove major vulnerability classes. Learn how to prioritise components, control FFI risk and plan a practical Rust migration.
Secure by Design puts security outcomes on manufacturers. Apply CISA principles through safe defaults, transparent metrics and product governance.
A free website security scanner: HTTPS, headers, cookies, SPF/DMARC, library versions checked against OSV and more. Get a report under its own shareable link.
You scanned your site and see a grade and a list of issues — now what? We explain every finding type and show how to fix it, concretely.
HSTS, CSP, X-Frame-Options, Permissions-Policy, CORS and cookie flags - which security headers to implement, how to set them correctly and how to verify them.
Rapid Reset (CVE-2023-44487) leverages HTTP/2 multiplexing for record-breaking L7 attacks. We explain the stream mechanism, RST_STREAM and defense.
Pentest, audit and vulnerability scan are three different things, often confused. We explain how they differ, how much they cost and which service to choose for your situation.
Before an attack lands, a criminal does reconnaissance. We show what OSINT reveals about your company and how to shrink your digital footprint.
eBPF allows you to run programs in the Linux kernel without modules - it powers modern monitoring and networking, but can also be a rootkit tool. Technically and about hardening.
A well-prepared penetration test delivers more value for the same money. How the process works, what to agree up front and how to read the report.
A regular domain account is enough to download a Kerberos ticket and crack the password of an offline service account. We explain TGS-REP, RC4 vs AES and effective defense.
DNS rebinding bypasses the same-origin policy and allows a website in the browser to reach the router, IoT or LAN admin panel. Mechanism and effective defense.
Threat modeling is the cheapest way to detect design errors before they become code. We explain the STRIDE method, data flow diagrams and a practical approach.
WordPress powers most of the web and is the top target for attacks. Ten practical steps to secure your site — no coding knowledge required.
APIs are now the most common target for application attacks. We cover the key OWASP API Top 10 flaws — led by BOLA — and how to avoid them.
A guide to the OWASP Top 10 for teams that want to understand real risks — from broken access control, through injection, to SSRF.
Insecure deserialization in Java, .NET, and Python: identify trust boundaries, test without unsafe gadget chains, and remove the root cause of RCE.
Active Directory is the top target once inside a network. We cover common attack paths — Kerberoasting, excessive privileges — and how to close them.
Understand prototype pollution in JavaScript and Node.js, trace pollution sources and gadgets, test safely, and harden applications effectively.
Learn how web race conditions and TOCTOU flaws break business logic, how to test concurrency safely, and which atomic controls actually fix them.
A technical LAN and segmentation pentest methodology covering flow matrices, Active Directory, IPv6, detection, hardening and safe evidence.
A practical guide to hardening Linux servers — no copying hundred-item checklists, with an emphasis on the highest-impact actions.
Test SaaS tenant isolation across APIs, databases, caches, queues, storage and support tooling with a safe, evidence-led penetration testing method.
A technical gRPC and Protobuf pentest methodology covering reflection, HTTP/2, mTLS, metadata, interceptors, schemas, streaming, limits and hardening.
A technical WebSocket pentest methodology covering handshakes, CSWSH, Origin, cookies, tokens, message authorisation, subscriptions, limits and hardening.
How to test web cache poisoning and cache deception safely: cache keys, URL normalisation, CDN policy, Vary, private responses, detection and hardening.
How to test HTTP request smuggling, CL.TE, TE.CL and HTTP/2 downgrades safely. A technical methodology for detection, hardening and retesting.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.