- September 16, 2026
- 11 min read
A REST API security testing checklist covering auth, BOLA, rate limits, CORS, JWT and input validation. Run it every release with two ordinary accounts.
- September 16, 2026
- 8 min read
Mobile application penetration testing covers what scanners miss: local storage, keychain misuse, pinning, reverse engineering. Here's the real scope.
- September 10, 2026
- 11 min read
What API security testing involves, the OWASP API Security Top 10, and how it differs from web app security testing. A practical guide, not a vendor pitch.
- August 31, 2026
- 9 min read
A Google Play data safety form that contradicts your app gets rejected or pulled. Here's how to check the declaration before Google does it for you.
- August 24, 2026
- 12 min read
Ring, Arlo, Wyze, eufy, Aqara, and Tapo all build genuinely fantastic and innovative security systems. The cameras are sharp, the sensors fire fast, and the locks feel solid in the hand. Yet owners of every one of them keep reporting recurring issues, and they rarely lie with the devices. Smart home security problems most often hide in software, particularly within complex connectivity systems.
- August 12, 2026
- 7 min read
An AI agent cancelled a stranger's gym booking to jump the waitlist, and the flaw it walked through, broken access control, is probably in your product too.
- July 29, 2026
- 8 min read
Ask a company's AI assistant to finish one short sentence, and it might hand over the private instructions its own developers wrote to keep it in line. Our QA engineers tried exactly that on a popular meeting assistant app, and it complied within seconds. That’s only one of the successful prompt injection examples we discovered while testing various AI-powered products. The model powering the product was fine in itself, but the app around it could not tell a hostile instruction from an ordinary request. That weakness sits at the top of every serious list of risks for AI-powered software.
- June 4, 2026
- 12 min read
If you are wondering why LLM red teaming tools are something you must know about today, consider this: cybercrime costs are forecast to exceed $10.5 trillion in 2025, with LLM vulnerabilities now part of that trajectory.
- June 2, 2026
- 16 min read
One sentence. That’s all it took to convince a car dealership’s AI assistant to “agree” to sell a $76,000 SUV for a single dollar back in December 2023.
- May 19, 2026
- 10 min read
Not sure whether to run a penetration testing vs vulnerability scanning? Check out this breakdown of what each covers and when to use which.