Blog · 225 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

IDOR & Broken Access Control
6 min read
Agentic AI vs. Traditional DAST in 2026 : Why Logic Flaws Require an Autonomous Reasoning Engine

DAST & Scanning
9 min read
VibeJam and the Rapid Prototyping Trap: Why Persistent Iteration Beats Failing Fast

Secrets & Credentials
5 min read
Fiverr Is Leaking Server Credentials and VPN Passwords on Google Right Now

DAST & Scanning
5 min read
Vibe Coding Security: How to Protect Applications Built with AI Chat Interfaces
Keep reading
More articles

The Validation Crisis: Why Your 800+ Critical Findings Dashboard is Failing Your Security Posture
dast

When Multi-Factor Authentication Isn't Enough: How Hackers “Steal the Keys” in 2026
api auth

Shadow Agents: The New Corporate Risk Replacing Shadow AI in 2026
ai agents

The Articulation Barrier: Why Your Vocabulary Is Your New Compiler
dast

Securing the Model Context Protocol (MCP): The New Frontier of AI-Native API Security
api auth

The OWASP Top 10 for Agentic Applications: What AppSec Teams Need to Know in 2026
dast
