Blog · 226 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

API Auth
7 min read
The Authorization Gap: Why Authentication is Solved and Authorization is Still a Mess

Secrets & Credentials
9 min read
Autonomous Intrusions: How Hackers Weaponized LLM Agents via the Marimo RCE (CVE-2026-39987)

API Auth
8 min read
Beyond Scanners: How AI Agents Register, Navigate, and Exploit Applications Like Real Attackers

DAST & Scanning
9 min read
The GlassWorm Takedown: Disrupting the Ultimate Developer Supply Chain Attack
Keep reading
More articles

Burner Identities: How Hackers are Bypassing 2026 Biometric Security Checks
dast

Multi-Tenant SaaS Security: How Tenant Isolation Failures Become Your Worst Breach
secrets

The Invisible Proxy: How Hackers Abuse Shared CDN Infrastructure in 2026
dast

The Mini Shai-Hulud Supply Chain Attack on AntV: A Deep Dive for Security Engineers
supply chain

The Invisible Attack Surface: How AI Coding Assistants Introduce Vulnerabilities in Real-Time
dast

Why Most “Secure by Default” Frameworks Are Only Secure Until a Developer Touches Them
dast
