Results for "Security tooling"
- Article
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover
Gecko’s AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
- Article
RCE in Your Test Suite: AI Agent Skills and the Attack Vector Skill Scanners Miss
When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs dur…
- Article
What Is SSRF (Server-Side Request Forgery)? A Complete Guide
Learn what SSRF (Server-Side Request Forgery) is, how attackers exploit it in cloud environments, and proven defense strategies. A complete guide.
Showing 11 - 14 of 14 results