Insights

Field notes from real engagements.

Notes on what we find, how we test, and what it means for the people who have to fix it.

IDOR is not dead, it just moved to your API
Object-level authorisation remains the most common critical we find. Why it survives code review, and the three checks that catch most cases.
Reading a pentest report as a board member
Which numbers matter, which are theatre, and the four questions to ask your security lead after a report lands.
Mailing list

New writing and open cohort dates.

Roughly monthly. Field notes, course announcements, and nothing else: no drip campaign.

Unsubscribe in one click. We never share or resell your address.