
API authorization testing: separating evidence from assumptions
What demonstrates access to another user's object, and why a result in a replica cannot be presented as a production result.

Autonomous assessment of infrastructure, web applications, and APIs: from reconnaissance and hypotheses to evidence, remediation guidance, and retesting. Available in the cloud and on-premises.
Read article
What demonstrates access to another user's object, and why a result in a replica cannot be presented as a production result.

From direct injection to tool poisoning and system prompt leakage: attack techniques explained through examples and illustrations.

Two attack chains led to a CMS administrator account and administrative CRM access. Both were validated in practice; the customer fixed the critical vulnerabilities, and retesting confirmed the fixes.

Access to other customers’ orders without signing in, and an attack chain leading to forged conferencing tokens. What was confirmed in the live system and in a controlled replica.
No articles in this category yet.