Blog
Security insights
& research
Deep dives into vulnerability research, AI-driven security testing, and best practices for modern application security.
CVE-2026-69836: When Entra ID Tokens Remember Too Much
Technical breakdown of an Entra ID token issuance flaw that let stale authentication context claims bypass Conditional Access. PoC walkthrough, detection queries, and remediation.
Introducing RedStrike DAST: Autonomous AI Security Testing
A deep dive into our autonomous AI-powered DAST platform. How we combine Playwright, ZAP / Burp Suite, and AI reasoning for comprehensive security scanning.
Emerging Security Trends for 2026: What Teams Need to Know
AI-powered attacks vs defense, supply chain security, API vulnerabilities, regulatory changes, and the rise of autonomous security platforms.
CVE Discovery at Scale: Multi-Source Intelligence Gathering
How our CVE discovery engine uses NVD, CIRCL, Vulners, and Sploitus to systematically discover and classify vulnerabilities for detected software.
Greybox Testing: Why Authentication Changes Everything
Blackbox scanning only scratches the surface. Learn how authenticated testing reveals IDOR, privilege escalation, and business logic vulnerabilities.
Writing Effective Pentest Reports: A Guide for Professionals
Why report quality matters, how to structure findings, write actionable remediation guidance, and common mistakes to avoid.
OWASP API Top 10: Automated Testing Strategies
A practical guide to testing for OWASP API Security Top 10 vulnerabilities. Authorization matrix testing, JWT attacks, and GraphQL-specific vectors.
STRIDE in Practice: A Hands-On Threat Modelling Workshop Guide
Step-by-step guide to running effective STRIDE threat modelling workshops with your development team. Templates and exercises included.
Red Teaming vs. Penetration Testing: Understanding the Difference
Definitions, scope differences, objectives, and when to choose which. Plus how purple teaming bridges the gap between both approaches.
AI Agents for Security Testing: Challenges and Approaches
How we built AI agents that reason about security vulnerabilities. Loop detection, context management, and adaptive testing strategies.
Redis Security: Common Misconfigurations and Exploitation
Real-world findings from testing Redis instances. Unauthenticated access, CONFIG SET file write, and module loading attacks.
Shift-Left Security: Integrating DAST into Your CI/CD Pipeline
A practical guide to adding DAST scanning to GitHub Actions. Baseline diffing, auto-fail policies, and cost optimization.
Autonomous Pentesting: Should Humans Stay in the Loop?
What AI does well, what humans do better, and the hybrid approach that combines both. Our philosophy on autonomous security testing.
WebLogic Exploitation: From CVE to Webshell in 16 Findings
Case study of our WebLogic 12.2.1.3.0 assessment. 178 CVEs processed, 4 critical findings, and real-world webshell uploads from external attackers.