Blog

Findings from the field.

Real vulnerabilities we keep finding across continuous engagements, and how to fix them.

29 Sept 2026·7 min read

Your Firewall Protects a Door Next to an Open Window

33 percent of the apps we attacked had an origin server reachable directly, bypassing the WAF entirely. How attackers find it, and how to close it.

by Dmytro Khirnyi
WAFAttack Surface
23 Sept 2026·7 min read

When Your Integrations Lie to You

22 percent of the companies we attacked had webhook endpoints that could be forged, queried, or abused. How to make your webhooks prove themselves.

by Dmytro Khirnyi
API SecurityWebhooks
20 Sept 2026·7 min read

The Internet Archive Remembers the Tokens You Forgot to Expire

36 percent of the companies we attacked had tokens, keys, or signed links recoverable from public web archives. How to make them useless to an attacker.

by Dmytro Khirnyi
API SecurityAuthentication
15 Sept 2026·7 min read

Your Dead Subdomains Are Someone Else's Phishing Kit

19 percent of the companies we attacked had subdomains that were dangling, parked, or pointing somewhere they shouldn't. How to find and kill them.

by Dmytro Khirnyi
Attack SurfaceDNS
11 Sept 2026·8 min read

Everything Your JavaScript Bundle Tells an Attacker

33 percent of the apps we attacked shipped secrets in public JavaScript: signing keys, license keys, storage keys. Here's what attackers do, and the fix.

by Hennadii Ahanesian
API SecuritySecrets Management
9 Sept 2026·7 min read

The Staging Environment Everyone Forgets to Defend

23 percent of the apps we attacked expose staging or QA to the internet, often with production data and weaker defenses. What attackers find, and the fix.

by Dmytro Khirnyi
Attack SurfaceStaging
4 Sept 2026·8 min read

Your Internal Tools Are Not Internal

30 percent of the apps we attacked expose internal tools to the internet: dashboards, admin panels, observability. What attackers find inside, and the fix.

by Hennadii Ahanesian
Attack SurfaceInternal Tools
1 Sept 2026·8 min read

Missing Authorization: The Finding We Report More Than Any Other

45 percent of the applications we attack have endpoints that never check who is calling. Why missing authorization tops our reports, and how to fix it.

by Hennadii Ahanesian
Broken Access ControlAPI Security
24 Aug 2026·4 min read

The Email Finding We Keep Reporting

46 percent of the domains we assessed publish DMARC with p=none, or no DMARC at all. Here's why that lets attackers send email as your company, and how to fix it in four steps.

by Hennadii Ahanesian
DMARCEmail Security