Blog posts
Deep dives into vulnerabilities we discover, offensive security techniques we develop, and insights from the front lines of enterprise security research.

Hunting GlassWorm: Open-Source Detection for Invisible Supply Chain Payloads
GlassWorm has compromised 400+ packages across five waves - and you can't see the malicious code. It hides inside invisible Unicode characters that your editor, terminal, and linter all render as nothing. We built glassworm-hunter to fix that: a free, open-source Python scanner that detects GlassWorm payloads in your VS Code extensions, npm packages, and Python dependencies before they become your problem.
Vulnerability research
Paweł Woyke
Sławomir Zakrzewski
April 7, 2026
9
min read
•
Mar 20, 2026

USB HID Attack for $3: Brute-Forcing a Kiosk PIN with an Attiny85
A $3 microcontroller. No lockout. 10,000 PIN combinations. Here's how CVE-2024-3461 turns any KioWare kiosk into an open door - and why USB HID attacks bypass every USB security policy you have.
Vulnerability research
Hardware
Red teaming
Maksymilian Kubiak
March 27, 2026
7
min read
•
Mar 13, 2026
Stored XSS to RCE: Finding CVE-2025-4951 in Rapid7 AppSpider
How an unvalidated XML field in Rapid7 AppSpider escalates to arbitrary code execution via ActiveX. CVE-2025-4951, found during a manual audit.
Vulnerability research
Maksymilian Kubiak
April 7, 2026
9
min read
•
Mar 13, 2026

Pickle Deserialization in ML Pipelines: The RCE That Won't Go Away
Pickle deserialization in ML pipelines is a silent RCE vector hiding in plain sight - passing code review, surviving security audits, and shipping to production at companies that know better. Here's why it keeps happening.
Vulnerability research
Secure coding
Sławomir Zakrzewski
March 12, 2026
12
min read
•
Mar 6, 2026

NIS2 Penetration Testing: A Practical Guide for Security Managers
NIS2 doesn't just require documentation - it requires proof your controls hold under real attack conditions. Here's the technical and operational breakdown for security managers.
Buyer's Guide
Paweł Woyke
March 6, 2026
9
min read
•
Mar 5, 2026

Web Application Penetration Testing Services: How to Evaluate a Provider
What to look for in a web application penetration testing provider - and how to tell if you're getting a real test or a cleaned-up scanner report.
Buyer's Guide
Paweł Woyke
March 5, 2026
15
min read
•
Feb 28, 2026

Caido vs Burp Suite: A Penetration Tester's Comparison
Is Caido a serious alternative to Burp Suite Professional? We put both tools to the test so you don't have to.
Web
Vulnerability research
Rafał Wójcicki
February 28, 2026
12
min read
•
Feb 27, 2026

Content Spoofing & SSRF in F5 BIG-IP Security Assessment
Detailed technical analysis of content spoofing (CVE-2026-20732) and SSRF-style reconnaissance security exposure discovered in F5 BIG-IP version 17.1.2.2. This assessment demonstrates how authenticated attackers can exploit administrative interfaces for UI manipulation and network reconnaissance.
Infrastructure
Vulnerability research
Web
Marcin Wyczechowski
February 13, 2026
8
min read
•
Feb 4, 2026

SAP Test Automation Using Windows API in Python
This article explores advanced techniques for automating SAP GUI interactions using Python and Windows API. It demonstrates how to manage window focus, navigate dynamic fields, and simulate keystrokes at the OS level - offering a robust alternative to SAP scripting in restricted environments. Through practical examples and a detailed analysis of script execution, readers will learn how to streamline SAP login processes, improve reliability, and integrate SAP GUI automation into broader workflows.
SAP
Michał Majchrowicz
February 24, 2026
13
min read
•
Feb 13, 2026

Java RMI for pentesters part two - reconnaissance & attack against non-JMX registries
In the second part of this series, we delve into automated reconnaissance and attacks within the Java RMI framework. Leveraging the RMI interface/server introduced in Part One, we explore practical techniques for penetration testing. This installment aims to equip pentesters with essential skills for efficient RMI exploitation.
Infrastructure
Web
AFINE
February 27, 2026
14
min read
•
Oct 8, 2020
Sort by Categories
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Monthly Security Report
Subscribe to our Enterprise Security Report. Every month, we share what we're discovering in enterprise software, what vulnerabilities you should watch for, and the security trends we're seeing from our offensive security work.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Cookie Settings
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you.
See our Privacy PolicyThank you! Your submission has been received!
Oops! Something went wrong while submitting the form.