
28 September 2026
The most common critical vulnerability in web applications has remained unchanged for years. We find it in every third test, and no firewall can stop it because the attacker uses exactly what the application is permitted to do.

23 September 2026
Cloud projects have the highest vulnerability density of everything we test, averaging 10.5 vulnerabilities per project. Yet the cloud provider is almost never at fault.

17 September 2026
An audit confirms that your security, procedures and responsibilities are properly defined. But is that enough? Real resilience cannot be assessed on paper alone. Only a penetration test can verify it in practice.

16 September 2026
71% of the infrastructure projects we tested contained at least one critical vulnerability. Most of these vulnerabilities were hidden in systems that companies considered secure simply because they were “not publicly accessible.

11 September 2026
The greatest cybersecurity risk in 2026 is no longer limited to your internet-facing infrastructure. It is everything you already consider secure. In the first part of this series, we examine where critical risks are now emerging and what CISOs can do about them.

3 September 2026
In early August, OWASP released the new OWASP Top 10 for LLM Applications. The document roughly tripled in size and now takes real incident data into consideration.