Web Application Pentest Methodology: What Testers Find

The 2026 Verizon Data Breach Investigations Report confirmed a shift the report itself calls a first in its 19-year history: “Using software flaws (31%) has surpassed stolen credentials for the first…
NTLM Relay in Active Directory: What Pentests Find

An NTLM relay attack inside an Active Directory pentest remains the most reliable critical-severity finding CTDefense reproduces during internal engagements. LLMNR poisoning captures an NTLMv2 hash.…
Cloud Workload Vulnerability Testing: What CSPM Misses

Two H2 2025 threat reports converged on the same finding: known, well-catalogued weaknesses on cloud-hosted workloads have overtaken misconfiguration and credential abuse as the most common way…
Machine credentials on the dark web: what infostealers steal

The dominant mental model for dark web monitoring is still built around one credential type: a human email address paired with a password, appearing in a paste, a combolist, or an infostealer log.…
VPN Exploits: What an External Pentest Catches First

An external network pentest perimeter devices review answers a question vendor patches and scanners cannot. On 8 June 2026, CISA added CVE-2026-50751, a CVSS 9.3 authentication bypass in a widely…
Mobile Banking App Pentest: What It Actually Finds

Banking trojans no longer steal credentials and walk away. They sit on the device, overlay the legitimate banking screen, intercept the second factor, and complete the transaction while the customer…
Web App Vulnerabilities Your Scanner and WAF Miss

The web application vulnerabilities scanners miss are rarely the ones a CVE feed will tell you about. They sit one layer above signatures, in the logic of how an application decides who is allowed to…
Active Directory Attack Paths Your Annual Pentest Misses

Most internal pentest engagements at mid-to-large enterprises follow an annual cadence. That cadence creates a structural gap: the active directory attack path annual pentest cycle leaves a 12-month…
CI/CD Secrets: The Cloud Attack Path Reviews Miss

A typical annual cloud security review captures the state of an environment on the day the engagement closes. Two weeks later, a developer adds a third-party integration, a CI/CD workflow gets a new…
External Pentest: What Attackers Find on Your Perimeter
On 14 May 2026, CISA added a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog, with active exploitation already confirmed in the wild. That…