ATTACK
INTELLIGENCE.
Real findings from real assessments. Every post covers a vulnerability class we've confirmed in production systems — with code, commands, and fixes.
SSRF Attacks: How a Simple Image Proxy Can Expose Your Entire Internal Network
Server-Side Request Forgery lets attackers use your server as a proxy to reach internal services, AWS metadata endpoints, and internal databases. We found an exploitable SSRF on a major PR platform's unauthenticated image proxy.
Vibe Coding Is Creating a Security Disaster: What Claude and GPT-4 Don't Tell You
AI coding assistants ship features fast. They also introduce hardcoded secrets, missing auth checks, and SQL injection vulnerabilities at scale. We analyzed AI-generated apps and found critical security issues in the majority of them.
IDOR Vulnerability: Real Examples From Sites With 100K+ Users
Insecure Direct Object References (IDOR) let attackers access any user's data by changing a number in a URL. We've found IDOR exposing 700,000+ records on live platforms. This is how it works and how to find it on your own site.
Exposed API Endpoints: How Hackers Find Your Data in Under 60 Seconds
Your API returns 702,651 user records. No authentication required. This isn't hypothetical — we've found this exact issue on real production sites. Here's how attackers locate these endpoints and what you can do right now.
WordPress Security Vulnerabilities: The 2026 Checklist for Site Owners
WordPress powers 43% of the web and is the most-attacked CMS. XML-RPC, user enumeration, exposed wp-admin, and outdated plugins create a textbook attack surface. Here's exactly what to check and fix.
SEEN ENOUGH?
SCAN YOUR DOMAIN.
Pedro runs 99+ security checks automatically. Find what's exposed before the attackers do.
Start Free Assessment →