Pen testing walkthroughs, compliance field notes, cloud attack chains and thought leadership from the CyberFortify offensive security team. Written by practitioners, for practitioners.
California's drivers are commercial — the enterprise deal that won't close without a test, the SOC 2 the customer demands, and the CCPA/CPRA reasonable-security duty. What it covers, cost, and remote delivery across the state.
Testing is the category where "compare on price" backfires — two identical-looking quotes can be a real engagement and a scanner with a cover page. How procurement should buy it: quality first, red flags, and a scorecard.
Gaming mixes real money, valuable virtual economies and huge user bases — the combination attackers love. In-game economy abuse, account takeover, and why the server must enforce every rule the client can't be trusted with.
A container feels like a VM but isn't — it shares the host kernel, so isolation is weaker. Get the privileges wrong and one compromise escapes to the host and every other container. The attack surface, testing, and hardening.
WordPress runs a huge share of the web — one plugin flaw hits thousands of sites automatically. The key insight: the core is solid; the risk lives in the plugins and themes. Where a test looks, and how to harden it.
What stops your staff when they hear their CEO's actual voice — cloned from a conference talk — urgently instructing a payment? Why email training fails, how to test resilience, and the process controls that stop it.
Almost every JavaScript object inherits from one shared parent — so if an attacker adds a property there, they've changed every object at once. From security-check bypass to DOM XSS and Node.js RCE.
Some apps hand user input to the OS shell to do their work — and if it isn't handled carefully, an attacker slips in their own commands. One of the shortest paths from a text box to full server compromise.
A JSON Web Token says who you are and what you can do — and the only thing between an attacker and forging an admin token is the server checking the signature. alg:none, algorithm confusion, and how to use JWTs safely.
The honest answer to the most-Googled SOC 2 question: not named, but effectively expected. Which Trust Services Criteria drive it, what auditors and customers want, Type I vs Type II timing, and making one test serve the audit.
A thick client runs on the attacker's machine — they own the device, binary and memory, so any client-side control can be defeated. The real question is whether your backend still holds the line.
Oman layers the CBO for finance, the PDPL for personal data, and national cyber security expectations. What a Muscat engagement covers, what it costs, and why local fluency gets your report accepted first time.
Kuwait layers the CBK for finance, CITRA's data privacy regulation, and national cyber security expectations. What a Kuwait City engagement covers, what it costs, and why local fluency matters at deadline.
GDPR never says "penetration test" — but Article 32 requires you to "regularly test the effectiveness" of your security measures, and testing is how. It reaches GCC firms with EU customers or data, too.
A university holds huge volumes of student data and research, yet runs one of the most open networks anywhere — often on a tight budget. Why the sector gets ransomwared, and what a test must cover.
A property deal moves an enormous sum in one transaction — and attackers know it. Why real estate is a magnet for payment-diversion fraud and data theft, and what a test must cover across portals, CRM and payments.
CORS relaxes the browser's same-origin policy — relax it too far and an attacker's site can read your logged-in users' data. The dangerous configs, what an attacker steals, and how to lock it down.
A cache serves one stored response to many users — so if an attacker gets it to store a malicious one, every visitor after them is compromised. The cache-key theory, cache deception, and how to close the gap.
"Upload your profile picture" lets a stranger place a file of their choosing on your server — and if it's a script in an executable spot, that's a web shell. The bypasses, the other damage, and the one fix that matters most.
Salesforce holds your customers, pipeline and contracts — and its security depends far more on how you configured it than on Salesforce's platform. The misconfigurations that expose data, and why it needs specialist testing.
"What's the ROI?" is a fair question and a slightly wrong one — the main return is a loss that never happens. An honest framework: where value really comes from, why the maths is fragile, and how to persuade finance.
Qatar layers the QCB for finance, the NIA framework for government and critical sectors, and the PDPPL for personal data. What a Doha engagement covers, what it costs, and why local fluency gets your report accepted first time.
One test is an event; a programme is a capability. How to set a risk-based calendar, choose engagement types, drive remediation, and report posture to the board as a trend line, not a pass/fail.
You don't need a pentest because a calendar says so — you need one because an enterprise deal, a SOC 2 audit or an investor demands it. The pragmatic founder's guide: when, what to test, and how much.
Your app checks the balance, then makes the withdrawal — and 50 requests at once can pass the check before any updates it. How a single-use coupon gets used a hundred times, the single-packet attack, and the atomic fix.
When a proxy and the server behind it disagree on where one request ends, an attacker slips a hidden request across the seam — onto the next user's traffic. The desync, the CL.TE/TE.CL variants, and how to shut it down.
You didn't build most of your AI system — you assembled it from downloaded models, datasets and ML libraries, and some can execute code the moment you load them. The risk map, how to test it, and how to defend it.
The same handful of flaw classes come up again and again — and they're rarely exotic. A field view aligned to the OWASP Top 10: broken access control leads, business logic follows, and almost none of it is anything a scanner flags.
The GCC isn't a discount region for cyber incidents — it's one of the most expensive in the world. IBM puts a Middle East breach at ~SAR 27M (~$7.3M). What it includes, why the region ranks so high, and how testing cuts it.
The numbers that make the case — breach cost, the weaknesses attackers actually exploit, testing adoption, remediation speed — every figure cited to IBM, Verizon and the regulators, with a GCC and global focus.
Was it a test — or a scanner's output with your logo on it? The ten red flags in the report and process that tell you the test was shallow, and what a good one looks like instead.
Scope is the most important decision you make about a test — and it happens before anyone touches a keyboard. What to include, what to gather, which box-colour to pick, and the two classic mistakes.
Stop a logistics operator and you stop the movement of goods. Why ransomware loves the sector, the sprawling EDI/API partner surface, and testing port and warehouse OT safely.
A hotel holds your card and your passport, across a PMS, POS, booking engine, guest Wi-Fi, loyalty and door locks. Why hotels get breached, what PCI and PDPL require, and what a test must cover.
SSO sits in front of everything, so a login-flow flaw is account takeover for the whole app. The common OAuth, OIDC and SAML flaws — and why using Google or Okta doesn't fix an insecure integration.
A single {{7*7}} that returns 49 is the tell — and from there it's often a short climb to running commands on your server. How SSTI works, the detect-then-escalate method, and how to design it out.
It turns a routine "rebuild this object from bytes" into running the attacker's code on your server — from one crafted input, no credentials. How serialized data becomes RCE, and what a gadget chain is.
Hand an XML parser a booby-trapped document and it will fetch a file off the server or fire a request at an internal system. How XXE works, and where it hides — SOAP, SAML, and every DOCX or SVG upload.
HIPAA never says "penetration test" — but the risk analysis and evaluation standards require you to find and evaluate technical risks to ePHI, and testing is how. Who's in scope, how often, and what OCR expects.
The Saudi and UAE PDPLs don't say "you must pentest" — but both demand you secure personal data and prove it works. How testing evidences the duty, and the cross-border data trap that catches GCC firms.
APIs broke the old rulebook — the top threats are authorisation flaws, not injection. Each risk from BOLA to unsafe third-party consumption, how it's exploited, and how to test and fix it.
If you send payments over SWIFT, the CSP is mandatory. The CSCF controls, the secure zone, the annual attestation, and where pentesting fits — alongside your SAMA or CBB obligations.
Your pipeline holds the keys to everything and runs code on every push — the highest-value asset most pentests skip. Poisoned execution, secret sprawl, supply-chain integrity, and how to test it.
Every quote looks similar on paper — and some hide a scanner with a cover page. The 15 questions that separate a real provider from a scan-and-invoice shop, with ideal answers and red flags.
Abu Dhabi runs its own regimes — ADHICS for healthcare, the FSRA for ADGM — over the federal UAE IA and PDPL. What an engagement covers, what it costs, and why local fluency gets your report accepted first time.
Downtime is money per minute — which is why factories are a ransomware favourite. The IT/OT convergence risk, what to test across ERP, MES and SCADA, and how to test live production without breaking it.
Retail spreads card data and customer records across the widest attack surface in business. Why retailers get hit, the PCI/PDPL drivers, and the business-logic flaws that hit the P&L directly.
ISO 27001 never says "pentest must be performed" — but Annex A A.8.8 and A.8.29 require it in practice, and auditors expect it. How testing maps to the standard, how often, and what evidence closes the loop.
If you touch card data, Requirement 11.4 is non-negotiable: internal and external tests every year and after change, plus segmentation testing. Exactly what PCI v4.0 asks, the cadence, and who can test.
A mobile app ships your code to a device the attacker controls. The OWASP MASVS checklist across storage, crypto, cert pinning, platform IPC and code protection — plus the backend API, where the real risk lives.
Scoping, kickoff, testing, live critical alerts, reporting, readout, remediation, retest — every stage of an engagement and exactly what's needed from you at each one.
Insurers concentrate health, identity and payment data and move money. Why they're a prime target, the CBB/NCA/PDPL/PCI drivers, and the business-logic flaws that expose one policyholder to another.
Two EU regimes, two testing bars — DORA's TLPT threat-led red teaming vs NIS2's risk-based testing. Who each applies to, what it mandates, and how GCC firms with EU footprints get reached.
SAP runs your finance and supply chain on its own protocols. Why it needs specialist testing — Gateway, RFC, ABAP, roles and SoD, plus the Fiori/OData surface — without breaking production.
A stolen token lets an attacker be your user. Cookie flags, token entropy, session fixation, timeout, logout invalidation, concurrent sessions and JWT pitfalls — OWASP-mapped, with how-to-test notes.
Offer pentesting under your own brand without hiring a red team. How the partner model works, what gets branded to you, the margins, and keeping quality when the delivery isn't yours.
A prospect sent a 200-row security questionnaire. What each pentest question really asks, how to answer honestly without over-committing, and exactly what evidence to attach.
Your compliance platform flagged a pentest evidence gap. The tool doesn't run the test — here's exactly what it needs from a third-party report, and how to time it to your audit window.
Offshore wins on day rate; local often wins on total cost once you count rework, data residency and regulatory mapping. An honest decision framework — and when offshore genuinely wins.
Dubai layers DESC ISR, DFSA/DIFC data law, UAE IA and PDPL. What a Dubai engagement covers, what it costs, and why regional fluency decides whether your report is accepted first time.
Ten providers with a genuine Bahrain presence — the Beyon, CTM360 and telco players — with a comparison table, the exact CBB reporting cycle, cited stats, and a scored method.
Eleven providers a Saudi buyer should know — NCA-licensed SOC operators, Aramco- and stc-backed players, and the Big 4 — with a comparison table, NCA/SAMA regulator map, cited stats, and a scored method.
Eleven providers a UAE buyer should know — with HQ, focus and accreditations, a comparison table, a DESC/NESA regulator map, cited breach stats, and the scored method we used to rank them.
The price is a count of tester-days — driven by app size, roles, business logic and depth. The six cost drivers, and how to scope for value without paying pentest rates for a scan.
A platform-delivered model adds real continuity — or hides automated scanning behind a dashboard. The delivery model doesn't answer the only question that matters: how much is manual?
A dangling DNS record pointing at a deprovisioned service lets anyone claim a subdomain of your domain — inheriting your brand's trust for phishing and worse. How to find and fix it.
The one-line binding that saves a form is the same one that lets an attacker set isAdmin by adding a field. Why it's in the OWASP API Top 10, and the allow-list fix.
Once your branded assistant is producing harmful output, it's your incident — whoever typed the prompt. How jailbreaks defeat guardrails, and how to test and defend in layers.
Bahrain's financial sector runs on the CBB's twice-yearly clock. What a Kingdom engagement involves, what it costs, and why a report mapped to CBB reporting matters at deadline.
The dangerous flaw is a checkout that lets someone buy a $1,000 item for $1, or a script quietly skimming cards. Testing the money and the logic, mapped to PCI DSS.
"We should be more secure" doesn't win budget. The four arguments leadership responds to — revenue, risk, compliance, due diligence — and how to tie them to a trigger.
One misconfigured permission or over-privileged container turns a single pod into cluster control. The real attack surface — RBAC, container escape, secrets — and how to harden it.
Auditors want findings managed, not just fixed. The fields each finding needs, how to prioritise, how to document accepted risk, and the retest that closes it out.
Any domain user can crack service-account passwords offline, with no exploit and no lockouts. How the attack works step by step, why it succeeds, and the fixes that stop it.
Introspection, nested-query DoS, BOLA, batching abuse and injection — the GraphQL-specific flaws a tester who treats it like REST will miss, and how to secure them.
The model isn't the weak point — the retrieval layer is. How missing access control, indirect prompt injection and knowledge-base poisoning turn AI assistants into leak channels.
Give a model tools and prompt injection stops being a text problem and becomes a real one. Excessive agency, tool poisoning, and how to verify a compromised model can't compromise the system.
DORA's threat-led penetration testing — who's in scope, how often, the TIBER-EU basis, and why it's a red-team-style step change from a standard pentest.
The shareable proof that testing happened — what it contains, how it differs from the full report, and why it's often the artefact that unblocks an enterprise deal or audit.
Nine sections and the questions that separate real, human-led testing from a scan in a nicer PDF — so you get comparable proposals and buy the right thing.
Not a cost decision but a choice between independence and intimacy — why an internal team and an external provider solve different problems, and why most need both.
The NCA, SAMA and PDPL drivers, what a KSA engagement covers, timelines and cost drivers — and why a report not mapped to your control set gets sent back.
A pentest isn't pass/fail — a report full of criticals did its job. The calm, structured response: triage, remediate, retest, communicate, and fix the root causes.
What SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR, CMMC, FedRAMP, NIST and the GCC regulators each require — explicit vs expected, cadence, and how one test can satisfy several.
A goal-based, adversarial simulation that tests detection and response — how it differs from a pentest, and the honest signs a purple team is your smarter first step.
How much the tester knows changes everything — realism, coverage, cost. Why gray box is the pragmatic default for application testing.
External tests whether the front door holds; internal tests what happens once someone's in. Why real breaches need both — and PCI DSS requires them.
Breadth, depth-on-a-schedule, or continuous crowd coverage — what each is for, why a bounty can't replace a pentest, and how to layer them.
Abusing legitimate features without breaking a single technical rule — why automated tools are structurally blind to them, and how manual testing finds them.
Turning "we fixed it" into "it's proven fixed" — how a retest verifies closure, catches failed fixes, and produces the attestation auditors and customers want.
One secures the whole LLM application against the OWASP LLM Top 10; the other stress-tests the model's behaviour. When you need which — and where they overlap.
The penetration testing cycles for CBB, NCA, SAMA, the UAE, Qatar, Kuwait and Oman — and the buying windows to book testing before each deadline.
The market's three tiers and the six criteria that actually decide quality — a framework to judge any provider (us included) on the merits, with disclosure.
The cornerstone definition: an authorised, simulated cyberattack that finds and safely exploits vulnerabilities before real attackers do — its purpose, seven phases, types and who needs one.
One finds and ranks weaknesses at breadth; the other exploits them to prove impact at depth. The full comparison, why compliance treats them separately, and what VAPT means.
At least annually and after any significant change — with cadence driven by compliance (PCI 11.4), risk and rate of change. Where continuous testing fits.
The main methodologies explained and compared — and how a rigorous test combines a process standard with OWASP's technical checklists, mapped to MITRE ATT&CK.
Rank by real risk, not raw CVSS. Separate quick wins from strategic fixes, set severity-based SLAs, handle accepted risk, and close the loop with a retest.
What each cloud allows — AWS permitted services, Azure's dropped notification (2017), GCP's no-contact rule — and the prohibitions common to all three.
Poisoning and relay, Kerberoasting, ADCS ESC, delegation abuse — the recurring path to Domain Admin, why it exploits defaults not bugs, and how to close it.
Twenty questions across credentials, methodology, scope, reporting and commercials — so you buy real, human-led testing and not a rebranded scan.
Satisfy SOC 2, pass enterprise security reviews, and prove multi-tenant isolation — testing scoped and timed for a SaaS startup and its budget.
Payment and transaction logic, API-first architectures, wallets and open-banking integrations — mapped to PCI DSS, SAMA and CBB. Why business logic is the crown jewel.
All ten 2025 risks — from prompt injection to unbounded consumption — what each means, the two new entries, and how an AI penetration test assesses them.
Direct vs indirect injection, the real-world variants, why it's considered unsolved, how an AI pentest finds it, and the mitigations that genuinely reduce the risk.
A plain-English reference — from BOLA and SSRF to CVSS, red teaming and prompt injection — grouped by category, each defined in a sentence or two.
What directors actually want to hear, how a penetration test gives you the independent evidence to answer, and how to present results at board level.
When a pre-launch test is essential, when you can defer, what to test, and how to fit it into your release timeline without slipping the date.
Contain, preserve evidence, meet GCC notification deadlines, and where penetration testing fits once the fire is out. A calm, practical guide.
QCB requires semi-annual VAPT and two penetration tests a year for banks; the NIA Policy sets an annual security assurance plan for government. The Gulf's most specific mandate, in its own words.
The CBK Cyber & Operational Resilience Framework (Dec 2025) replaced the 2020 CSF and added mandatory annual red teaming, plus IoT/OT testing. Control-by-control.
The CBO CS&RF mandates VAPT for financial institutions; MTCIT accredits providers for government testing. An honest guide — including where the public control text runs out.
Why insurers ask, what actually satisfies them, how a pentest affects your premium and coverage, and the claim-denial trap of misrepresenting your security on the application.
Why a scan doesn't satisfy SOC 2, PCI DSS or ISO 27001, the real difference between the two, and how to fix it fast with an audit-ready penetration test.
What a test is, whether you need one, what to expect, how to scope your first engagement, what you'll receive, and the first-timer mistakes to avoid.
What cybersecurity due diligence covers, why a penetration test moves valuation and deal risk, and how to prepare whether you're buying or being bought.
Tests are categorised three ways — by target, by tester knowledge (black/grey/white box), and by perspective (external/internal). Understand the axes to scope the right test.
What a qualified opinion really means, why a missing penetration test is a common cause (CC4.1 names it), and the exact path back to a clean report.
One to three weeks of testing plus reporting — but scope decides. Timelines by test type, what drives duration, the full engagement timeline, and how to speed it up.
The difference between a smooth, high-value test and a slow one is decided before day one. Scope, access, environment and stakeholders — plus a ready-to-use checklist.
What the UAE Information Assurance Regulation — the standard most still call NESA — requires of security testing, its priority-P1 control, who complies, and how it links to ADHICS and DESC.
Abu Dhabi's healthcare standard names penetration testing, vulnerability assessment and web security assessment on a yearly schedule. What OM 7.1 requires, the tiers, and how it maps to UAE IA.
What Dubai's DESC ISR expects of security testing, who it binds, and what can honestly be said about cadence given the control catalogue is access-restricted.
Scanners are fast; humans find the access-control and business-logic flaws behind real breaches. What each does well, why "automated pentest" misleads, and how to use both.
Executive summary, scope, findings, CVSS severity, proof of concept, remediation — what every part means, and exactly what to do with the report once you have it.
An enterprise customer made a penetration test report a condition of the deal. What they actually want, what counts as acceptable, what to send, and how to get one without stalling the contract.
An honest comparison — where each genuinely wins on depth, price, procurement and tester seniority, and the one question that matters more than firm size: who actually holds the keyboard?
Select your framework — CBB, SAMA, NCA ECC, PCI DSS, SOC 2, HIPAA, ISO 27001, FedRAMP, DORA — and get the exact testing frequency, scope, mandatory status and control reference.
The honest answer is a range: $4,000 to $150,000+, most engagements $10,000-$30,000. Real 2026 prices by test type, methodology, pricing model and compliance framework, plus a GCC note.
Control 3.2.4 requires annual penetration testing; the separate FEER framework requires red teaming every three years. The maturity model, who must comply, and how SAMA sits alongside the NCA ECC.
The verified control text, what "periodically" really means, who must comply, ECC-2:2024 changes, and how CSCC, OTCC and SAMA relate to the base ECC.
Testing twice a year in June and December, reports due 30 September and 31 March, two-year tester rotation, and the exact CBB Rulebook reference for banks, insurers, investment firms and payment providers.
Five years of OWASP data, mapped against hundreds of actual pen test findings. Broken Access Control still leads - but SSRF, injection, and insecure design have shifted in ways the updated list doesn't fully capture. Here's what we're actually finding in 2026.
Rootless jailbreaks, TrustKit, Network.framework, and custom pinning implementations. A full walkthrough of every technique we use in mobile pen tests today - and what to do when Objection doesn't work.
The full attack chain: SSRF entry point to AWS metadata service to IAM credential theft to STS AssumeRole privilege escalation. With real request examples, Azure/GCP equivalents, and remediation that actually works.
Object-level authorization failures are OWASP API Top 10 #1 for a reason - and automated scanners are structurally incapable of finding them. Here's how we test for BOLA manually, including GraphQL variants and compound key patterns.
Requirement 11.4.5 tightened significantly in PCI DSS v4.0. QSAs now expect evidence that your segmentation controls actively prevent CDE-scope expansion. Here's what the test must cover, what auditors reject, and what a passing deliverable looks like.
The most expensive mistake in security procurement is buying the wrong engagement type. Pen tests that should have been red teams, red teams that should have been pen tests - and the questions that tell you which you actually need.
Clickjacking (UI redressing) requires no malware and no XSS - just a transparent iframe and an authenticated session. Attack anatomy, six real variants, X-Frame-Options vs CSP frame-ancestors, frame busting bypasses, and a six-point prevention checklist.
SPAs, GraphQL, edge functions, AI-powered apps - the attack surface has changed. So has the toolchain. A practitioner's guide to the proxy tools, recon utilities, API testing rigs, and specialized scanners we use in 2026 engagements.
Compliance gives you a documented security posture. Protection gives you an actual one. Most organisations discover the gap between them during a breach. Here's how consulting bridges it - and what a mature programme looks like when both are working.
SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, FTC Safeguards, CMMC - the regulatory landscape compounds every year. What compliance consulting actually delivers, common mistakes that derail audits, and how to right-size the engagement for your maturity level.
Koop's automated compliance intelligence combined with CyberFortify's manual offensive security practice. Why automated GRC and manual pen testing aren't alternatives - they're a force multiplier when used together.
156 test cases across pre-engagement, recon, authentication, authorization, injection, cryptography, API, business logic and reporting phases. Download the full PDF or browse the interactive version.
Every post here is drawn from real pen test findings. When you're ready to test your own systems, our offensive security team will find what your scanners and automated tools miss.