Blog · 221 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

DAST & Scanning
7 min read
Your App Works in Testing. Attackers Do Not Test the Same Way.

DAST & Scanning
6 min read
The Secret of Database Keys: A Beginner’s Guide to Organizing Data

API Auth
4 min read
Session IDs in Cookies: The Default That Only Stays Safe If You Ignore the URL

DAST & Scanning
7 min read
New AI Threat: 5 Steps to Secure Autonomous “AI Agents” Before They Compromise Your Network
Keep reading
More articles

AI Removed the Barrier to Building. It Did Not Remove the Risk.
dast

Your Users Can See Each Other's Data. No Scanner Will Tell You.
idor

You Can Build an App Without Syntax. You Cannot Secure It Without Thinking.
dast

Why Password Audits Miss Exactly What Hackers Are Looking For to Enter Your System
soc2

The Hidden Security Debt of High-Velocity AI Development
dast

The First Thing AI Does Not Teach You About Building Apps Is Security
dast
