Blog · 225 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

DAST & Scanning
8 min read
Why Your QA Team Cannot Replace a Dedicated Vulnerability Scanner (And Why They Shouldn't Try)

DAST & Scanning
18 min read
Why Your Security Tool Stack Has 14 Dashboards and Zero Answers

API Auth
15 min read
The Anatomy of a Subdomain Takeover: How Forgotten DNS Records Lead to Enterprise Breaches

AI Agents
13 min read
Autonomous Cyber Warfare: Defending Against LLM-Powered Hackers with AI Security Agents
Keep reading
More articles

Compliance Theater: What SOC 2 Actually Tests (and What It Quietly Skips)
soc2

The Miasma Worm: Anatomy of the Binding.gyp npm Supply Chain Attack
supply chain

You Have 40 Customers and a Database Full of Their Emails: A Security Starter Kit
dast

Hunting Business Logic Flaws: Why Traditional Scanners Miss BOLA and IDOR Vulnerabilities
idor

CVSS Is Lying to You (Sometimes on Purpose): Reading Severity Scores Like a Skeptic
api auth

Bypassing Multi-Factor Authentication: How Attackers Exploit Flawed OAuth and SSO Implementations
api auth
