Blog
Field notes from the bench.
Technical write-ups on how real vulnerabilities get found, proven, and fixed.
APIAccess ControlOWASP
BOLA vs. BFLA: the two API authorization failures that matter most
Broken object-level and broken function-level authorization top the OWASP API Security list for a reason. Here's the difference, why both are missed, and how to test for each.
March 20, 2026 · 7 min read Read
ReportingMethodology
What a good penetration test report actually contains
The report is the product. Here's what separates one your engineers act on from one that gets filed and forgotten — section by section.
February 24, 2026 · 8 min read Read
WebBusiness LogicMethodology
Business logic flaws: the bugs scanners can't see
The highest-impact vulnerabilities rarely look like vulnerabilities. They're valid requests that do something the business never intended — and only a human can spot them.
February 2, 2026 · 7 min read Read
WebAPIAccess Control
Finding IDOR in multi-tenant SaaS
Broken object-level authorization is the flaw scanners miss most. Here is how tenant-isolation bugs actually happen, and how we prove real impact by hand.
January 14, 2026 · 8 min read Read
Prove what an attacker could actually do.
A short scoping call, no obligation.