Blog posts
Deep dives into vulnerabilities we discover, offensive security techniques we develop, and insights from the front lines of enterprise security research.

To Allow or Not to get-task-allow: macOS Security Analysis
This article examines how the misconfigured get-task-allow entitlement in macOS apps enables code injection and TCC bypass. It builds on large-scale testing of notarized applications and highlights the risks of weakened security boundaries.
Apple
Binary exploitation
MacOS
Vulnerability research
Karol Mazurek
February 13, 2026
5
min read
•
Sep 2, 2025

Phrack Magazine: Forty Years of Hacking
From phreaking roots to cutting-edge research, Phrack has always been a space where hackers teach hackers. Forty years on, the mission hasn’t changed—it’s only grown stronger. This article dives into Phrack Magazine’s remarkable journey and its milestone 40th anniversary. From its beginnings in the 80s underground to its global presence today, we’ll look at how Phrack shaped hacker culture, what the latest issue means for the community, and how contributors—past and present—continue to keep the signal alive.
IOS
MacOS
Vulnerability research
Web
Karol Mazurek
February 12, 2026
3
min read
•
Sep 22, 2025

Desktop Application Security Standard: Introducing DASVS
Desktop application security lacked unified standards—until now. DASVS provides a structured approach to securing Windows, macOS, and Linux applications with clear verification levels and technical security controls.
Our roadmap includes the Desktop Application Security Testing Guide (DASTG) and an automated security assessment tool. Join the community and help shape the future of desktop security!
Linux
MacOS
Vulnerability research
Windows
Paweł Woyke
February 13, 2026
5
min read
•
Oct 14, 2025

Desktop Application Security Testing Checklist 2025
Are you testing desktop app security and need to know what process to follow? That’s what this desktop application security testing checklist is for. Desktop applications are fundamentally different from web and mobile apps – and those differences create unique security challenges. Web applications run mostly server-side, behind your firewalls and security controls. The browser […]
Linux
MacOS
Vulnerability research
Windows
Paweł Woyke
February 13, 2026
8
min read
•
Nov 21, 2025

Thick Client Penetration Testing Guide 2025
Thick-client penetration testing is a critical gap in most enterprise security programs. Banking software, trading platforms, healthcare systems, and manufacturing tools – these desktop applications handle your organization’s most sensitive data and critical operations. But when was the last time you actually tested their security? If you’re relying on the same penetration testing approach you […]
Linux
MacOS
Vulnerability research
Windows
Paweł Woyke
February 13, 2026
10
min read
•
Nov 23, 2025

SAP GUI Scripting with Python: Automating Security Tests Using Windows API
SAP GUI scripting automation guide: Python + Windows API for security testing. Includes practical examples of transaction validation and control extraction for penetration testers.
SAP
Vulnerability research
Windows
Michał Majchrowicz
February 12, 2026
6
min read
•
Mar 20, 2025

Invoker – Automating Pentesting Tools in Burp Suite (Example with dosfiner)
Invoker is a Burp Suite extension that automates external tools like dosfiner, sqlmap, nuclei, or ffuf, bridging the gap between captured requests and CLI commands.
Infrastructure
Linux
Vulnerability research
Web
Paweł Zdunek
February 13, 2026
7
min read
•
Mar 27, 2025

VoIP Penetration Tests
VoIP is transforming business communication with flexibility and cost savings. However, its reliance on the internet brings cybersecurity risks. Discover how VoIP works, common threats, and the role of penetration testers in protecting organizations.
Infrastructure
VOIP
Zbigniew Piotrak
February 13, 2026
5
min read
•
Apr 14, 2025

Case Study: IOMobileFramebuffer NULL Pointer Dereference
How broken access and Null Pointer Dereference was found in macOS IOMobileFramebuffer (AppleCLCD2) service.
MacOS
Reverse engineering
Vulnerability research
Karol Mazurek
February 12, 2026
8
min read
•
Apr 22, 2025

Threat of TCC Bypasses on macOS
TCC on macOS isn’t just an annoying prompt—it’s the last line of defense between malware and your private data. This article breaks down how TCC works, why third-party developers must take bypass vulnerabilities seriously, and how seemingly minor flaws can open the door to real-world attacks. Written from the perspective of both attacker and defender, it’s a must-read for app developers and security researchers alike.
Apple
MacOS
Red teaming
Vulnerability research
Karol Mazurek
February 12, 2026
6
min read
•
May 26, 2025
Sort by Categories
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Monthly Security Report
Subscribe to our Enterprise Security Report. Every month, we share what we're discovering in enterprise software, what vulnerabilities you should watch for, and the security trends we're seeing from our offensive security work.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Cookie Settings
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you.
See our Privacy PolicyThank you! Your submission has been received!
Oops! Something went wrong while submitting the form.