Blog· 197 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

Latest9 min read
AI Code Assistants Are Writing Your Security Debt: How to Validate Before Production
By Harsh Nandanwar

10 min read
Securing Multi-Tenant SaaS: How to Test for Cross-Tenant Data Leakage at Scale
By Harsh Nandanwar

19 min read
CVE Breakdown: The SSRF-to-RCE Chain Nobody Patched in Time
By Pallavi M

17 min read
IDOR at Scale: Why One Broken Object Reference Can Mean a Full Customer Data Leak
By Pallavi M

18 min read
GraphQL's Blind Spots: Why Introspection, Batching, and Nested Queries Are an Attacker's Playground
By Pallavi M

18 min read
Business Logic Flaws Won't Show Up in Your OpenAPI Spec: Here's Where They Hide
By Pallavi M

20 min read
125 APIs, 20 Vulnerabilities, Zero Manual Setup: What API Sprawl Really Looks Like
By Pallavi M

18 min read
Password Reset Poisoning: The 15-Minute Bug That Takes Over Every Account on Your Platform
By Pallavi M

20 min read
Email Verification Isn't Authentication: The Gap Every Signup Flow Gets Wrong
By Pallavi M
