Our Blog
Resources and insights
The latest industry news, interviews, technologies, and resources.
How I Almost Got Phished: Advanced Phishing Example
Investigation of real phishing email that used background and interest targeting and an advanced tactic for bypassing spam filters and appearing legitimate.
TCM Pentester Certification Roadmap
How can you become a pentester? Follow TCM’s learning path and go from no IT experience to a professional penetration tester.
How Often Should You Have A Pentest?
Most organizations will need at least one pentest annually, but some more frequent pentesting can be beneficial for finding vulnerabilities and reducing risk.
ID Tokens vs Access Tokens: What’s the Difference?
In the realm of secure authentication, two key elements often come to the fore: ID tokens and access tokens. Though these elements might seem similar, understanding their differences, common pitfalls, and best practices is crucial in ensuring the security of your...
Save Time During your Next Pentest
Pentesting is inherently time-consuming. Here are some ways that we can increase the speed and efficiency of penetration testing.
Clickjacking 101: What is Clickjacking and How Does it Work?
Clickjacking, also known as UI Redressing, is a technique that tricks users into clicking on unintended elements on a website. Learn more about how it works.
Learn WebApp Pentesting: 2023 Edition
This article reviews how you can become become a web application penetration tester or application security engineer with updated advice for 2023.
OWASP API Top10 2023 Candidate List, So What’s New?
Review the top threats to APIs identified in the OWASP 2023 Candidate List. Top threats include Broken Object Level Authorization, SSRF, and more!
BOLA: Broken Object Level Authorization
Broken Object Level Authorization is a vulnerability that impacts API security. It occurs when an application fails to enforce access controls.
Stay Ahead of Cyber Threats
Get expert insights on the latest penetration testing strategies, emerging vulnerabilities, and cybersecurity best practices—straight to your inbox.
Loading form...
We care about your data in our privacy policy.








