Blog · 227 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

IDOR & Broken Access Control
10 min read
Securing Multi-Tenant SaaS: How to Test for Cross-Tenant Data Leakage at Scale

DAST & Scanning
19 min read
CVE Breakdown: The SSRF-to-RCE Chain Nobody Patched in Time

Secrets & Credentials
17 min read
IDOR at Scale: Why One Broken Object Reference Can Mean a Full Customer Data Leak

SOC 2 & Compliance
18 min read
GraphQL's Blind Spots: Why Introspection, Batching, and Nested Queries Are an Attacker's Playground
Keep reading
More articles

Business Logic Flaws Won't Show Up in Your OpenAPI Spec: Here's Where They Hide
dast

125 APIs, 20 Vulnerabilities, Zero Manual Setup: What API Sprawl Really Looks Like
dast

Password Reset Poisoning: The 15-Minute Bug That Takes Over Every Account on Your Platform
api auth

Email Verification Isn't Authentication: The Gap Every Signup Flow Gets Wrong
api auth

Weak Tokens, Weaker Assumptions: Why JWT 'alg: none' Attacks Still Work in 2026
api auth

SSO Isn't a Security Feature, It's an Attack Surface: 7 Misconfigurations We Keep Finding
api auth
