Results for "Security research"
- Article
Automated Pentest: Complete Guide to Tools and Best Practices
A complete guide to automated pentest tools and best practices. Learn what works, what doesn’t, and how to implement continuous security testing.
- Article
Claude Code Review: What Code Scanners Cannot Tell You About Real Risk
Claude Code Review brought five parallel agents and sub-1% false positives, changing how AI development teams ship production code.
- Article
Gecko Security vs ZeroPath: Which Is Better?
Gecko Security vs ZeroPath, compared. See which SAST tool finds authorization bugs, handles microservices, and reduces false positives better.
- Article
What Is Static Code Analysis? A Complete Guide
Learn what static code analysis is, how it works, and why it catches vulnerabilities before deployment. A complete guide with best practices.
- Article
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover
Gecko’s AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
- Article
SQLi CVE Database: A Complete List of SQL Injection Vulnerabilities
A complete SQLi CVE database. Track SQL injection vulnerabilities, CVSS scores, and bypass methods including CVE-2026-34612 and CVE-2026-34717.
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
- Article
RCE in Your Test Suite: AI Agent Skills and the Attack Vector Skill Scanners Miss
When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs dur…
- Article
What Is SSRF (Server-Side Request Forgery)? A Complete Guide
Learn what SSRF (Server-Side Request Forgery) is, how attackers exploit it in cloud environments, and proven defense strategies. A complete guide.
- Article
CVE-2025-51463: Aim Path Traversal in Server Backup Restoration
A path traversal vulnerability was found in AIM server. This vulnerability allows remote attackers to write arbitrary files on the server’s filesystem via a mal…
Showing 11 - 20 of 22 results