Blog· 203 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

9 min read
Autonomous Intrusions: How Hackers Weaponized LLM Agents via the Marimo RCE (CVE-2026-39987)
By Harsh Nandanwar

8 min read
Beyond Scanners: How AI Agents Register, Navigate, and Exploit Applications Like Real Attackers
By Pallavi M

9 min read
The GlassWorm Takedown: Disrupting the Ultimate Developer Supply Chain Attack
By Harsh Nandanwar

8 min read
Burner Identities: How Hackers are Bypassing 2026 Biometric Security Checks
By Harsh Nandanwar

5 min read
Multi-Tenant SaaS Security: How Tenant Isolation Failures Become Your Worst Breach
By Pallavi M

7 min read
The Invisible Proxy: How Hackers Abuse Shared CDN Infrastructure in 2026
By Harsh Nandanwar

18 min read
The Mini Shai-Hulud Supply Chain Attack on AntV: A Deep Dive for Security Engineers
By Harsh Nandanwar

5 min read
The Invisible Attack Surface: How AI Coding Assistants Introduce Vulnerabilities in Real-Time
By Pallavi M

5 min read
Why Most “Secure by Default” Frameworks Are Only Secure Until a Developer Touches Them
By Pallavi M
