Broken Object-Level Authorization: The Bug That Needs a Second Test Account
Change one number in a request and you are looking at another customer’s data. Why automated tools miss it, and the four checks that catch it.
Read articlePlain-English breakdowns of the issues we actually find across APIs, mobile, cloud, supply chains and AI systems and the fixes that matter.
Change one number in a request and you are looking at another customer’s data. Why automated tools miss it, and the four checks that catch it.
Read articleSuccessive waves of malicious npm packages have hit thousands of projects through stolen maintainer tokens and typosquatted names. Here is what happened in plain English, why it kept spreading, and the five quick checks every team should run this week.
Read articleHardcoded keys, weak SSL pinning, screenshots leaking secretshere are the recurring issues we still find on iOS and Android, with the fix that actually matters for each.
Read articlePublic S3 buckets and over-permissive IAM roles still cause most cloud breaches we investigate. A short tour of the patterns we keep findingand how to spot them in 10 minutes.
Read articleUntrusted documents can hijack model behavior. We outline trust boundaries, safe retrieval patterns, and guardrails that actually work in production.
Read articleA clear checklist for bounding tool permissions, validating tool outputs, and preventing multi-step action chaining.
Read articlePrevent sensitive prompts, tokens, and embeddings from escaping into logs, traces, or third-party tools used by AI teams.
Read article