Blog
Findings from the field.
Real vulnerabilities we keep finding across continuous engagements, and how to fix them.
Your Firewall Protects a Door Next to an Open Window
33 percent of the apps we attacked had an origin server reachable directly, bypassing the WAF entirely. How attackers find it, and how to close it.
When Your Integrations Lie to You
22 percent of the companies we attacked had webhook endpoints that could be forged, queried, or abused. How to make your webhooks prove themselves.
The Internet Archive Remembers the Tokens You Forgot to Expire
36 percent of the companies we attacked had tokens, keys, or signed links recoverable from public web archives. How to make them useless to an attacker.
Your Dead Subdomains Are Someone Else's Phishing Kit
19 percent of the companies we attacked had subdomains that were dangling, parked, or pointing somewhere they shouldn't. How to find and kill them.
Everything Your JavaScript Bundle Tells an Attacker
33 percent of the apps we attacked shipped secrets in public JavaScript: signing keys, license keys, storage keys. Here's what attackers do, and the fix.
The Staging Environment Everyone Forgets to Defend
23 percent of the apps we attacked expose staging or QA to the internet, often with production data and weaker defenses. What attackers find, and the fix.
Your Internal Tools Are Not Internal
30 percent of the apps we attacked expose internal tools to the internet: dashboards, admin panels, observability. What attackers find inside, and the fix.
Missing Authorization: The Finding We Report More Than Any Other
45 percent of the applications we attack have endpoints that never check who is calling. Why missing authorization tops our reports, and how to fix it.
The Email Finding We Keep Reporting
46 percent of the domains we assessed publish DMARC with p=none, or no DMARC at all. Here's why that lets attackers send email as your company, and how to fix it in four steps.