Blog · 228 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

DAST & Scanning
11 min read
AI Slop Cut Bug Bounty Payouts in Half. The Talent Pipeline Gets the Bill

Supply Chain
12 min read
Your Coding Agent Installed 23 Packages in a Minute. Your SBOM Saw Zero.

API Auth
13 min read
Check the Socket, Not the Installer: An Audit and Lockdown Playbook for the NemoClaw Ollama Flaw

Supply Chain
11 min read
An AI Found a 20-Year-Old RCE in One Evening, and the Game Is the Least Interesting Part
Keep reading
More articles

Your SOC 2 Pentest Proves a Week. The Report Implies a Year.
soc2

An AI Built a Working Avada Exploit in Two Hours. Your Patch Window Just Got Shorter
api auth

Prove Tenant Isolation Without a Pentest: Mint as Tenant A, Replay as Tenant B
api auth

We Aimed Five Prompt Attacks at Our Own Agent. The Tool Wrapper Chose What Leaked.
api auth

The Four-Hour GraphQL Security Review: A Schedule, Not a Checklist
graphql

AliExpress Didn't Beam Ultrasonic Sound at Shoppers. What It Actually Did Is Harder to Block
supply chain
