Blog

Field notes on agentic offensive security

Deep, practitioner-written pieces on agentic penetration testing, proof-based validation, and how autonomous testing changes offensive security. No fluff, no gated PDFs.

API Security

API security best practices for 2026: the checklist that maps to real breaches

Most API security advice guards the perimeter; the breaches come through broken authorization. Twelve OWASP-mapped controls, a copy-paste checklist, and how to test the ones scanners cannot see.

Read the article →
Security Research

One resident login, an entire apartment complex: the master PIN in Rently's API

The app showed us two codes; the API returned the property's full code table, master PIN included. The story behind CISA advisory ICSA-26-237-01, and the lesson it holds.

Read the article →
API Security

BOLA vs BFLA: the API authorization flaws scanners miss

Authorization, not injection, breaks most modern APIs. The difference between object-level and function-level authorization, why scanners find neither, and how to test for both.

Read the article →
Comparison

Agentic pentesting vs DAST: what's the difference?

DAST matches patterns on one app and hands you unverified alerts. An agentic pentester reasons across your whole surface, chains findings, and proves exploitability. How they differ, and when to use each.

Read the article →
Method

How agentic pentesting proves an exploit

Inside proof-based validation: a step-by-step look at how a leaked token becomes a proven, CVSS-rated critical finding, and why reproducing it before reporting changes everything.

Read the article →
Method

How to pentest an LLM or AI agent

Testing the model, its tools, and its data as one system: prompt injection, tool abuse, and data exfiltration, mapped to the OWASP LLM Top 10.

Read the article →
Get Started

Point the agent at your attack surface

Give us a domain and the rules of engagement. We will return a scoped run and show you what it surfaces, and what it proves.