main logo icon

Insights & Cybersecurity Stories

Stay up-to-date with our latest tips, trends, and best practices in cybersecurity and penetration testing.

CREST-Accredited Penetration Testing Companies (2026): How to Verify and Who to Shortlist

CREST-Accredited Penetration Testing Companies (2026): How to Verify and Who to Shortlist

Exactly 510 companies worldwide hold CREST's firm-level Penetration Testing accreditation. How to verify a provider on the CREST Marketplace, the traps that mislead buyers, where CREST matters by market, and which accredited firms to shortlist.

Advisories

Arafat Afzalzada · 2026-08-09 | 17 min read

5 views

0

PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)

PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)

A requirement-level guide to PCI DSS penetration testing under v4.0.1: what Requirement 11.4 mandates, internal vs external vs segmentation testing, who may perform it, scoping, QSA evidence, timing, and cost.

Network SecurityWeb App Security

Arafat Afzalzada · 2026-08-09 | 14 min read

3 views

0

Supabase: Powerful, but One Misconfiguration Away From Disaster

Supabase: Powerful, but One Misconfiguration Away From Disaster

A deep dive into Supabase's critical security flaw: how exposed Anon keys can lead to data disaster. Learn why Row Level Security (RLS) is essential to protect your PostgreSQL database.

Network SecurityWeb App Security

Omar Hamdy · 2026-08-08 | 11 min read

449 views

25

StingAD: From One Low-Priv Account to Domain Admin

StingAD: From One Low-Priv Account to Domain Admin

Stingrai Security Research and Development Labs walks a single low-privileged Active Directory credential to Domain Admin using StingAD: Kerberoasting, Shadow Credentials, AD CS ESC1, DCSync, and a golden ticket.

Network Security

Arafat Afzalzada · 2026-07-31 | 15 min read

48 views

10

Continuous Red Teaming vs the Annual Pentest: Why 32% Coverage Fails (2026)

Continuous Red Teaming vs the Annual Pentest: Why 32% Coverage Fails (2026)

The average organization tests only 32% of its attack surface. Here is why annual point-in-time pentests leave dangerous drift gaps in 2026, what continuous testing and PTaaS deliver, and a clear buyer decision framework.

Network Security

Arafat Afzalzada · 2026-07-01 | 16 min read

18 views

0

Continuous Red Teaming vs the Annual Pentest: Why 32% Coverage Fails (2026)

Continuous Red Teaming vs the Annual Pentest: Why 32% Coverage Fails (2026)

The average organization tests only 32% of its attack surface. Here is why annual point-in-time pentests leave dangerous drift gaps in 2026, what continuous testing and PTaaS deliver, and a clear buyer decision framework.

Network Security

Arafat Afzalzada · 2026-07-01 | 16 min read

18 views

0

Living Off the Land: Why LOLBins Beat Blocklists, and How to Detect Them (2026)

Living Off the Land: Why LOLBins Beat Blocklists, and How to Detect Them (2026)

Living off the land explained for defenders: why LOLBins abuse signed OS binaries you cannot blocklist, why signatures fail, and how to detect LOTL with baselining, behavior and lineage analytics, and purple teaming mapped to MITRE ATT&CK.

Network Security

Ivan Spiridonov · 2026-07-01 | 16 min read

19 views

0

Non-Human Identity Attacks: When Leaked API Keys Become Your Perimeter (2026)

Non-Human Identity Attacks: When Leaked API Keys Become Your Perimeter (2026)

18.1M exposed API keys and tokens and 28.65M new hardcoded secrets made non-human identities the fastest-growing attack surface in 2025. Here is how exposure happens and how to defend it.

Network Security

Ivan Spiridonov · 2026-07-01 | 16 min read

35 views

0

Inside Agentic Red Teaming: The 24/7 AI Attacker, and What It Still Cannot Do

Inside Agentic Red Teaming: The 24/7 AI Attacker, and What It Still Cannot Do

Agentic red teaming put an autonomous AI at the top of HackerOne's US leaderboard in 2025. Here is what the 24/7 AI attacker does well, where humans stay essential, and why AI-led-plus-human-validated wins in 2026.

LLM Security

Ivan Spiridonov · 2026-07-01 | 16 min read

99 views

0