Blog
Security insights
& research
Deep dives into vulnerability research, AI-driven security testing, and best practices for modern application security.
Introducing RedStrike DAST: Autonomous AI Security Testing
A deep dive into our autonomous AI-powered DAST platform. How we combine Playwright, OWASP ZAP, and AI reasoning for comprehensive security scanning.
Emerging Security Trends for 2026: What Teams Need to Know
AI-powered attacks vs defense, supply chain security, API vulnerabilities, regulatory changes, and the rise of autonomous security platforms.
CVE Discovery at Scale: Multi-Source Intelligence Gathering
How our CVE discovery engine uses NVD, CIRCL, Vulners, and Sploitus to systematically discover and classify vulnerabilities for detected software.
Greybox Testing: Why Authentication Changes Everything
Blackbox scanning only scratches the surface. Learn how authenticated testing reveals IDOR, privilege escalation, and business logic vulnerabilities.
Writing Effective Pentest Reports: A Guide for Professionals
Why report quality matters, how to structure findings, write actionable remediation guidance, and common mistakes to avoid.
OWASP API Top 10: Automated Testing Strategies
A practical guide to testing for OWASP API Security Top 10 vulnerabilities. Authorization matrix testing, JWT attacks, and GraphQL-specific vectors.
STRIDE in Practice: A Hands-On Threat Modelling Workshop Guide
Step-by-step guide to running effective STRIDE threat modelling workshops with your development team. Templates and exercises included.
Red Teaming vs. Penetration Testing: Understanding the Difference
Definitions, scope differences, objectives, and when to choose which. Plus how purple teaming bridges the gap between both approaches.
AI Agents for Security Testing: Challenges and Approaches
How we built AI agents that reason about security vulnerabilities. Loop detection, context management, and adaptive testing strategies.
Redis Security: Common Misconfigurations and Exploitation
Real-world findings from testing Redis instances. Unauthenticated access, CONFIG SET file write, and module loading attacks.
Shift-Left Security: Integrating DAST into Your CI/CD Pipeline
A practical guide to adding DAST scanning to GitHub Actions. Baseline diffing, auto-fail policies, and cost optimization.
Autonomous Pentesting: Should Humans Stay in the Loop?
What AI does well, what humans do better, and the hybrid approach that combines both. Our philosophy on autonomous security testing.
WebLogic Exploitation: From CVE to Webshell in 16 Findings
Case study of our WebLogic 12.2.1.3.0 assessment. 178 CVEs processed, 4 critical findings, and real-world webshell uploads from external attackers.