Outpost24 logo
Exploiting trust: Weaponizing permissive CORS configurations
Application Security
If you’re a pentester, or a consumer of application security pentest reports, you’ll probably have come across Cross-Origin Resource Sharing...
CSRF simplified: A no-nonsense guide to Cross-Site Request Forgery
Application Security
Cross-Site Request Forgery (CSRF) is a serious web security vulnerability that allows attackers to exploit active sessions of targeted users...
Cross-site scripting vulnerability found in Oracle Integration Cloud 
Application Security
In November 2023, while conducting a security assessment on a client’s instance of the Oracle Integration Cloud Platform, I discovered...
Outpost24 logo
PTaaS guide | Choosing the right test environment 
Application Security
A major challenge for developing modern applications is ensuring their security. Penetration Testing as a Service (PTaaS) is a cloud-enabled...
checklist-pentest
Security auditing web apps? Here’s your checklist for a...
Application Security
A penetration test is a sanctioned assault on your organization’s electronic assets and data. If the attack is repelled, you...