24 April 2025
Web, cloud, mobile, and infrastructure projects all revealed the same pattern: overlooked basics, repeat mistakes, and too many systems left wide open.
26 March 2024
With over 8 years of experience at Citadelo, Jakub Novák shares how offensive security has evolved in the Czech and Slovak markets. From the rise of regulations like NIS2 and DORA to the continued dominance of phishing attacks, he outlines what every CISO needs to know.
11 March 2024
Citadelo’s Ethical Hacking Report 2023 reveals 2,795 vulnerabilities found in 384 simulated attacks. Web, Cloud, and Infrastructure remain the most exposed areas — highlighting the urgent need for proactive security testing to close critical gaps.
1 March 2024
A small configuration slip. A rarely used content type. One well-placed payload — and your Python app is under someone else’s control. This CVE proves it.
20 February 2024
What does it mean that in Citadelo a hacker is hiring a hacker? Interview with our HR Manager Dita. Find more about hacker recruitment at Citadelo and how it affects the quality of the team and therefore the quality of the pentests.
12 February 2024
What happens when your CI/CD pipeline skips one too many security checks? In our latest assessment, we chained multiple vulnerabilities—from GitHub misconfigurations to OpenShift exposure—and landed a webshell in production.