Blog · 227 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

API Auth
12 min read
Seven Editions, Zero Dashboard Warnings: Triaging the miniOrange SAML Forgery Bugs

13 min read
Your Agent Demo Is Lying to You: A Map of the Production Gap

12 min read
Your AI Agents Are One Audit Question Away From a Finding

11 min read
One Cropper, Three Coordinates: Finding the Android Image Overwrite in Your Dependency Tree
Keep reading
More articles

One Schema Name, Every Stored Credential: CVE-2026-33696 and the n8n Blast Radius
dast

Memory Made Chatbots Useful. It Also Made Them Gossips.
ai agents

One ../ From Copilot: The CVE-2026-32193 Chain, Rebuilt for AKS Defenders
ai agents

The Signature Was Valid and the Boot Was Still Compromised
soc2

Your Dashboard Might Be Someone's Proxy Exit: a Field Check for the DoFun Head Unit Botnet
dast

"No Watermark Detected" Tells You Nothing. The SynthID Removal Toolchain Is Why
dast
