20 May 2026

Over Half of Companies’ IT Projects Contain Serious Vulnerabilities, Citadelo Report Finds

In 2025, we tested 34% more projects than the previous year. Of the 628 IT projects assessed, more than half contained a critical or high-severity vulnerability.

4 May 2026

Cloud Security Audit vs. Cloud Penetration Test: Which Approach Should You Choose?

Imagine your team has just deployed a new cloud environment. The security manager asks: "Should we run an audit or a pentest?" The answer depends on one key question — what exactly do you need to know. And choosing the wrong approach can cost you months of false confidence.

11 March 2024

Ethical Hacking Report 2023: Web, Cloud, and Infrastructure Top the Risk Chart

Citadelo’s Ethical Hacking Report 2023 reveals 2,795 vulnerabilities found in 384 simulated attacks. Web, Cloud, and Infrastructure remain the most exposed areas — highlighting the urgent need for proactive security testing to close critical gaps.

1 March 2024

CVE Alert: Python API Library Allowed Remote Code Execution

A small configuration slip. A rarely used content type. One well-placed payload — and your Python app is under someone else’s control. This CVE proves it.

12 February 2024

CI/CD Misconfigurations That Could Break Your Production

What happens when your CI/CD pipeline skips one too many security checks? In our latest assessment, we chained multiple vulnerabilities—from GitHub misconfigurations to OpenShift exposure—and landed a webshell in production.

29 January 2024

CVE Hat-trick: 3 Major Vulnerabilities Found by Our Hacker

At Citadelo, discovering CVEs isn’t just a badge of honor — it’s how we keep systems safe. Here’s the story behind a triple find: one hacker, three vulnerabilities, and critical insights for anyone serious about cybersecurity.