Technical
Resources Blog

Technical

Keep up to date with the latest offensive security news, knowledge, and resources.
Axios Got Backdoored Through a Trusted Account. Your CI/CD Pipeline Has the Same Problem.

Axios Got Backdoored Through a Trusted Account. Your CI/CD Pipeline Has the Same Problem.

The Axios supply chain attack exposed why dependency scanning fails against credential compromise. Learn how attackers backdoor popular packages and what your penetration tests are missing.
Popping Printers: How Your MFPs Are Handing Attackers Domain Admin

Popping Printers: How Your MFPs Are Handing Attackers Domain Admin

Multifunction printers silently store domain credentials, expose unauthenticated management interfaces, and sit on flat networks. Learn how attackers exploit MFPs to achieve domain admin in minutes.
Starting Strong: Successful Onboarding with Sprocket Security

Starting Strong: Successful Onboarding with Sprocket Security

The fastest path from kickoff to testing starts with alignment, preparation, and the right people in the room.
Please Show Your Work: Bypassing JavaScript Proof-of-Work CAPTCHAs

Please Show Your Work: Bypassing JavaScript Proof-of-Work CAPTCHAs

Understanding how SiteGround’s proof-of-work CAPTCHA silently disrupts automated WordPress security scans and how to work around it.
Vulnerability Hunting a Retired App Part 1 - Auth Bypass

Vulnerability Hunting a Retired App Part 1 - Auth Bypass

Decompiling a retired .NET application reveals how a single middleware misconfiguration leads to full authentication bypass.
Putting the Token Before the Cart? A Guide on E-Commerce API Pentesting

Putting the Token Before the Cart? A Guide on E-Commerce API Pentesting

Why traditional API pentests miss real commerce risk and how cart tokens, checkout flows, and cross-layer auth gaps expose customer data.
1 2 3 4 5