
20 May 2026
In 2025, we tested 34% more projects than the previous year. Of the 628 IT projects assessed, more than half contained a critical or high-severity vulnerability.

4 May 2026
Imagine your team has just deployed a new cloud environment. The security manager asks: "Should we run an audit or a pentest?" The answer depends on one key question — what exactly do you need to know. And choosing the wrong approach can cost you months of false confidence.

11 March 2024
Citadelo’s Ethical Hacking Report 2023 reveals 2,795 vulnerabilities found in 384 simulated attacks. Web, Cloud, and Infrastructure remain the most exposed areas — highlighting the urgent need for proactive security testing to close critical gaps.

1 March 2024
A small configuration slip. A rarely used content type. One well-placed payload — and your Python app is under someone else’s control. This CVE proves it.

12 February 2024
What happens when your CI/CD pipeline skips one too many security checks? In our latest assessment, we chained multiple vulnerabilities—from GitHub misconfigurations to OpenShift exposure—and landed a webshell in production.

29 January 2024
At Citadelo, discovering CVEs isn’t just a badge of honor — it’s how we keep systems safe. Here’s the story behind a triple find: one hacker, three vulnerabilities, and critical insights for anyone serious about cybersecurity.