Blog · 225 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

SOC 2 & Compliance
8 min read
The Third-Party AI Dilemma: Auditing the Security of Your SaaS Vendors' LLMs

DAST & Scanning
7 min read
Kubernetes RBAC is Broken: Why Your Clusters Are One Misconfiguration Away from Disaster

DAST & Scanning
5 min read
Startup Security Posture Assessment: A Founder’s Checklist Before Series A

DAST & Scanning
8 min read
Living off the Cloud: How Hackers Pivot Inside AWS and Azure Environments
Keep reading
More articles

Server-Side Request Forgery in Cloud Environments: How Attackers Reach Your Metadata API
dast

AI in the Boardroom: Translating Cyber Risk and Autonomous Defense into Business Metrics
dast

The Autonomous SOC: Defeating Alert Fatigue with AI-Driven Triage
dast

Infrastructure as Code (IaC) Poisoning: The Silent Compromise of Terraform and Pulumi
dast

Why Authentication Workflows Are Still the Weakest Link in Modern Applications
api auth

Broken Access Control in 2026: The OWASP Number One Vulnerability Explained With Real Examples
dast
