Security insights
& research

Deep dives into vulnerability research, AI-driven security testing, and best practices for modern application security.

🔑
CVE Analysis
CVE

CVE-2026-69836: When Entra ID Tokens Remember Too Much

Technical breakdown of an Entra ID token issuance flaw that let stale authentication context claims bypass Conditional Access. PoC walkthrough, detection queries, and remediation.

August 28, 2026 · 11 min read

🚀
DAST Platform
DAST

Introducing RedStrike DAST: Autonomous AI Security Testing

A deep dive into our autonomous AI-powered DAST platform. How we combine Playwright, ZAP / Burp Suite, and AI reasoning for comprehensive security scanning.

June 15, 2026 · 12 min read

📈
Security Trends
Research

Emerging Security Trends for 2026: What Teams Need to Know

AI-powered attacks vs defense, supply chain security, API vulnerabilities, regulatory changes, and the rise of autonomous security platforms.

January 30, 2026 · 10 min read

🔍
CVE Research
Research

CVE Discovery at Scale: Multi-Source Intelligence Gathering

How our CVE discovery engine uses NVD, CIRCL, Vulners, and Sploitus to systematically discover and classify vulnerabilities for detected software.

May 28, 2026 · 8 min read

🛡
Pentesting
Pentesting

Greybox Testing: Why Authentication Changes Everything

Blackbox scanning only scratches the surface. Learn how authenticated testing reveals IDOR, privilege escalation, and business logic vulnerabilities.

May 12, 2026 · 10 min read

📝
Report Writing
Pentesting

Writing Effective Pentest Reports: A Guide for Professionals

Why report quality matters, how to structure findings, write actionable remediation guidance, and common mistakes to avoid.

January 15, 2026 · 9 min read

🔌
API Security
DAST

OWASP API Top 10: Automated Testing Strategies

A practical guide to testing for OWASP API Security Top 10 vulnerabilities. Authorization matrix testing, JWT attacks, and GraphQL-specific vectors.

April 30, 2026 · 15 min read

📑
Threat Modelling
Threat Modelling

STRIDE in Practice: A Hands-On Threat Modelling Workshop Guide

Step-by-step guide to running effective STRIDE threat modelling workshops with your development team. Templates and exercises included.

April 18, 2026 · 11 min read

🤝
Red Teaming
Pentesting

Red Teaming vs. Penetration Testing: Understanding the Difference

Definitions, scope differences, objectives, and when to choose which. Plus how purple teaming bridges the gap between both approaches.

January 5, 2026 · 8 min read

🧠
AI Security
Research

AI Agents for Security Testing: Challenges and Approaches

How we built AI agents that reason about security vulnerabilities. Loop detection, context management, and adaptive testing strategies.

March 28, 2026 · 9 min read

🖥
Infrastructure
Pentesting

Redis Security: Common Misconfigurations and Exploitation

Real-world findings from testing Redis instances. Unauthenticated access, CONFIG SET file write, and module loading attacks.

March 14, 2026 · 7 min read

🚀
CI/CD Security
DAST

Shift-Left Security: Integrating DAST into Your CI/CD Pipeline

A practical guide to adding DAST scanning to GitHub Actions. Baseline diffing, auto-fail policies, and cost optimization.

March 2, 2026 · 10 min read

🧠
Autonomous Security
Research

Autonomous Pentesting: Should Humans Stay in the Loop?

What AI does well, what humans do better, and the hybrid approach that combines both. Our philosophy on autonomous security testing.

December 20, 2025 · 8 min read

💣
Vulnerability Research
Research

WebLogic Exploitation: From CVE to Webshell in 16 Findings

Case study of our WebLogic 12.2.1.3.0 assessment. 178 CVEs processed, 4 critical findings, and real-world webshell uploads from external attackers.

February 20, 2026 · 14 min read

Brochure