Securing session
Insights

Field notes from the offensive side

Research, teardowns, and hard-won lessons from real engagements, written by the operators who ran them. No fluff, no vendor spin.

Research

Original technical write-ups from our engagements and lab work.

Whitepapers

In-depth guidance on building durable security programmes.

Security advisories

Responsible-disclosure notes and mitigations for issues we uncover.

Research
Jul 8, 2026·9 min read

Chaining Low-Severity Bugs Into Full Account Takeover

Three findings each rated informational combined into a critical breach. A walkthrough of why severity should be measured by chains, not isolated issues.

Read article
Cloud
Jun 27, 2026·7 min read

The IAM Misconfiguration Pattern Behind Most Cloud Breaches

A recurring role-assumption path we find in the majority of AWS assessments, how it forms, why it hides, and how to shut it down for good.

Read article
AI Security
Jun 14, 2026·11 min read

Indirect Prompt Injection Is the New SSRF

When your LLM reads untrusted documents and can call tools, retrieved content becomes executable. Lessons from testing production RAG pipelines.

Read article
Red Team
May 30, 2026·8 min read

What Your SOC Actually Sees During a Real Intrusion

A detection timeline from a recent covert engagement, where alerts fired, where they didn't, and the tuning that closed the gap.

Read article
AppSec
May 18, 2026·6 min read

Business Logic: The Vulnerability Class Scanners Can't See

Why the highest-impact findings rarely map to a CVE, and how to build a testing practice that hunts for logic abuse deliberately.

Read article
Advisory
May 3, 2026·5 min read

Writing a Penetration Test Report Engineers Won't Ignore

The difference between a report that drives fixes and one that gathers dust comes down to reproduction, proof, and respect for the reader.

Read article
Work with us

Turn our research into your resilience.

Reading about attacks is useful. Facing one in a controlled test is transformative. Tell us what you are protecting and we will scope an engagement around it.