Blog · 221 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

DAST & Scanning
8 min read
Poisoning the Well: Securing Your CI/CD Pipeline Against Next-Gen Supply Chain Attacks

DAST & Scanning
6 min read
AI Drift and Regression Management: How to Keep Your Codebase Stable with AI Coding Tools

DAST & Scanning
7 min read
Shadow APIs: The Unseen Attack Vector That's Bypassing Your WAF

DAST & Scanning
6 min read
Emotional Variables in Data Structures: When Your App Listens to How You Feel
Keep reading
More articles

The “Copilot Blindspot”: Why AI-Generated Code is a Ticking Time Bomb for App Security
dast

How Claude's 200K Context Window Is Enabling Whole-System Refactors That Were Previously Impossible
dast

Is Your Phone Spying on You? How the FBI Tracks Deleted Messages (And How to Stop It)
dast

The Nightmare Eclipse Attack: How Hackers Breached FortiGate VPNs (And How to Protect Your Startup)
dast

Seiko USA's Press Lounge Was Defaced. The Shopify Breach Claims Are Still Unverified
dast

The Efficiency Paradox: Why "Vibe Coding" Is Creating a Leadership Crisis
api auth
