Blog
Field notes fromour research team.
Findings from real incidents, pen test debriefs, and breach analysis. Plain-English writeups of what our consultants are seeing in the wild.
Pen Test Debrief · 12 Aug 2026
Three ways we still get into "PCI compliant" web apps
A walkthrough of the logic flaws and misconfigurations that keep showing up in engagements, despite a clean compliance report.
Incident Response · 5 Aug 2026What the first 60 minutes of a ransomware incident actually look like
Containment decisions, stakeholder communication, and the mistakes that turn a bad day into a bad quarter.
Research · 29 Jul 2026API authorisation flaws: the gap between "authenticated" and "authorised"
Why so many APIs correctly check who you are, but not what you're allowed to do, and how we test for it.
Want this in your inbox?