// RESEARCH & RESOURCES
Resources
Third-Party APIs Are Part of Your Attack Surface
Applications validate what users send and trust what vendors return. The direction of that trust is rarely justified by the direction of control.
READ ARTICLE →
OWASP Top 10:2025 for Penetration Testers — What Actually Changed?
The 2025 list promotes supply chain and adds mishandling of exceptional conditions.
READ ARTICLE →
Business Logic Vulnerabilities: The Bugs Automated Scanners Still Miss
Scanners test requests. Logic flaws live in the relationship between requests. Modelling the application as a state machine is what makes them findable.
READ ARTICLE →
BOLA in API Security: Why Broken Object Level Authorization Still Matters
BOLA persists because authentication is centralised and object-level authorization is not.
READ ARTICLE →
Why Are AI & LLM Applications Vulnerable?
An LLM application is a distributed system with a non-deterministic component in the middle.
READ ARTICLE →
Agentic AI Security: Understanding the New Attack Surface of AI Agents
Adding tools to a model changes the security question from what it might say to what it might do — and turns every integration into a…
READ ARTICLE →
