Blog · Security Research · Field Notes

Offensive security deep-dives from the field.

Pen testing walkthroughs, compliance field notes, cloud attack chains and thought leadership from the CyberFortify offensive security team. Written by practitioners, for practitioners.

Topics: Pen Testing · Compliance · Cloud Security · API · Red Team Format: Technical deep-dives + strategic guides
Topics: OWASP Top 10 · PCI DSS v4.0 · SSRF Chains · BOLA · iOS Pinning Bypass · Red Team vs Pen Test · SOC 2 · ISO 27001 · HIPAA · Cloud IAM Escalation · API Security · Frida · Certificate Pinning · Compliance Consulting Topics: OWASP Top 10 · PCI DSS v4.0 · SSRF Chains · BOLA · iOS Pinning Bypass · Red Team vs Pen Test · SOC 2 · ISO 27001 · HIPAA · Cloud IAM Escalation · API Security · Frida · Certificate Pinning · Compliance Consulting
CA
New
Local Hub

Penetration testing services in California

California's drivers are commercial — the enterprise deal that won't close without a test, the SOC 2 the customer demands, and the CCPA/CPRA reasonable-security duty. What it covers, cost, and remote delivery across the state.

August 2026 7 min read Usama Gul Read post →
PR
New
Buyer's Guide

Penetration testing procurement: a guide for procurement teams

Testing is the category where "compare on price" backfires — two identical-looking quotes can be a real engagement and a scanner with a cover page. How procurement should buy it: quality first, red flags, and a scorecard.

August 2026 8 min read Usama Gul Read post →
GM
New
Industry

Penetration testing for gaming & online gambling

Gaming mixes real money, valuable virtual economies and huge user bases — the combination attackers love. In-game economy abuse, account takeover, and why the server must enforce every rule the client can't be trusted with.

August 2026 8 min read Usama Gul Read post →
DK
New
Platform

Docker & container security

A container feels like a VM but isn't — it shares the host kernel, so isolation is weaker. Get the privileges wrong and one compromise escapes to the host and every other container. The attack surface, testing, and hardening.

August 2026 8 min read Usama Gul Read post →
WP
New
Platform

WordPress security & penetration testing

WordPress runs a huge share of the web — one plugin flaw hits thousands of sites automatically. The key insight: the core is solid; the risk lives in the plugins and themes. Where a test looks, and how to harden it.

August 2026 7 min read Usama Gul Read post →
DF
New
AI Security

Deepfake & voice phishing: the AI social engineering threat

What stops your staff when they hear their CEO's actual voice — cloned from a conference talk — urgently instructing a payment? Why email training fails, how to test resilience, and the process controls that stop it.

August 2026 8 min read Usama Gul Read post →
PP
New
Technical

Prototype pollution explained

Almost every JavaScript object inherits from one shared parent — so if an attacker adds a property there, they've changed every object at once. From security-check bypass to DOM XSS and Node.js RCE.

August 2026 8 min read Usama Gul Read post →
CI
New
Technical

Command injection explained

Some apps hand user input to the OS shell to do their work — and if it isn't handled carefully, an attacker slips in their own commands. One of the shortest paths from a text box to full server compromise.

August 2026 8 min read Usama Gul Read post →
JWT
New
Technical

JWT attacks explained

A JSON Web Token says who you are and what you can do — and the only thing between an attacker and forging an admin token is the server checking the signature. alg:none, algorithm confusion, and how to use JWTs safely.

August 2026 8 min read Usama Gul Read post →
SO2
New
Compliance

Do you need a penetration test for SOC 2?

The honest answer to the most-Googled SOC 2 question: not named, but effectively expected. Which Trust Services Criteria drive it, what auditors and customers want, Type I vs Type II timing, and making one test serve the audit.

August 2026 7 min read Usama Gul Read post →
TC
New
Platform

Thick client & desktop application penetration testing

A thick client runs on the attacker's machine — they own the device, binary and memory, so any client-side control can be defeated. The real question is whether your backend still holds the line.

August 2026 8 min read Usama Gul Read post →
OM
New
Local Hub

Penetration testing services in Oman

Oman layers the CBO for finance, the PDPL for personal data, and national cyber security expectations. What a Muscat engagement covers, what it costs, and why local fluency gets your report accepted first time.

August 2026 7 min read Usama Gul Read post →
KW
New
Local Hub

Penetration testing services in Kuwait

Kuwait layers the CBK for finance, CITRA's data privacy regulation, and national cyber security expectations. What a Kuwait City engagement covers, what it costs, and why local fluency matters at deadline.

August 2026 7 min read Usama Gul Read post →
GDP
New
Compliance

GDPR penetration testing requirements explained

GDPR never says "penetration test" — but Article 32 requires you to "regularly test the effectiveness" of your security measures, and testing is how. It reaches GCC firms with EU customers or data, too.

August 2026 7 min read Usama Gul Read post →
ED
New
Industry

Penetration testing for education

A university holds huge volumes of student data and research, yet runs one of the most open networks anywhere — often on a tight budget. Why the sector gets ransomwared, and what a test must cover.

August 2026 8 min read Usama Gul Read post →
RE
New
Industry

Penetration testing for real estate & proptech

A property deal moves an enormous sum in one transaction — and attackers know it. Why real estate is a magnet for payment-diversion fraud and data theft, and what a test must cover across portals, CRM and payments.

August 2026 8 min read Usama Gul Read post →
COR
New
Technical

CORS misconfiguration explained

CORS relaxes the browser's same-origin policy — relax it too far and an attacker's site can read your logged-in users' data. The dangerous configs, what an attacker steals, and how to lock it down.

August 2026 7 min read Usama Gul Read post →
WCP
New
Technical

Web cache poisoning explained

A cache serves one stored response to many users — so if an attacker gets it to store a malicious one, every visitor after them is compromised. The cache-key theory, cache deception, and how to close the gap.

August 2026 8 min read Usama Gul Read post →
FU
New
Technical

File upload vulnerabilities explained

"Upload your profile picture" lets a stranger place a file of their choosing on your server — and if it's a script in an executable spot, that's a web shell. The bypasses, the other damage, and the one fix that matters most.

August 2026 8 min read Usama Gul Read post →
SF
New
Platform

Salesforce security assessment & testing

Salesforce holds your customers, pipeline and contracts — and its security depends far more on how you configured it than on Salesforce's platform. The misconfigurations that expose data, and why it needs specialist testing.

August 2026 8 min read Usama Gul Read post →
ROI
New
Commercial

Penetration testing ROI: making the financial case

"What's the ROI?" is a fair question and a slightly wrong one — the main return is a loss that never happens. An honest framework: where value really comes from, why the maths is fragile, and how to persuade finance.

August 2026 8 min read Usama Gul Read post →
QA
New
Local Hub

Penetration testing services in Qatar

Qatar layers the QCB for finance, the NIA framework for government and critical sectors, and the PDPPL for personal data. What a Doha engagement covers, what it costs, and why local fluency gets your report accepted first time.

August 2026 7 min read Usama Gul Read post →
CIS
New
Commercial

The CISO's guide to a penetration testing programme

One test is an event; a programme is a capability. How to set a risk-based calendar, choose engagement types, drive remediation, and report posture to the board as a trend line, not a pass/fail.

August 2026 9 min read Usama Gul Read post →
ST
New
Commercial

Penetration testing for startups

You don't need a pentest because a calendar says so — you need one because an enterprise deal, a SOC 2 audit or an investor demands it. The pragmatic founder's guide: when, what to test, and how much.

August 2026 8 min read Usama Gul Read post →
RC
New
Technical

Race condition & TOCTOU testing

Your app checks the balance, then makes the withdrawal — and 50 requests at once can pass the check before any updates it. How a single-use coupon gets used a hundred times, the single-packet attack, and the atomic fix.

August 2026 8 min read Usama Gul Read post →
HRS
New
Technical

HTTP request smuggling explained

When a proxy and the server behind it disagree on where one request ends, an attacker slips a hidden request across the seam — onto the next user's traffic. The desync, the CL.TE/TE.CL variants, and how to shut it down.

August 2026 8 min read Usama Gul Read post →
AIS
New
AI Security

AI supply chain & model security

You didn't build most of your AI system — you assembled it from downloaded models, datasets and ML libraries, and some can execute code the moment you load them. The risk map, how to test it, and how to defend it.

August 2026 9 min read Usama Gul Read post →
TOP
New
Statistics

The most common vulnerabilities we find

The same handful of flaw classes come up again and again — and they're rarely exotic. A field view aligned to the OWASP Top 10: broken access control leads, business logic follows, and almost none of it is anything a scanner flags.

August 2026 8 min read Usama Gul Read post →
$$
New
Statistics

The cost of a data breach in the GCC (2026)

The GCC isn't a discount region for cyber incidents — it's one of the most expensive in the world. IBM puts a Middle East breach at ~SAR 27M (~$7.3M). What it includes, why the region ranks so high, and how testing cuts it.

August 2026 7 min read Usama Gul Read post →
STA
New
Statistics

Penetration testing statistics 2026

The numbers that make the case — breach cost, the weaknesses attackers actually exploit, testing adoption, remediation speed — every figure cited to IBM, Verizon and the regulators, with a GCC and global focus.

August 2026 8 min read Usama Gul Read post →
RF
New
Buyer's Guide

10 signs of a bad penetration test (red flags)

Was it a test — or a scanner's output with your logo on it? The ten red flags in the report and process that tell you the test was shallow, and what a good one looks like instead.

August 2026 9 min read Usama Gul Read post →
SC
New
Buyer's Guide

How to define penetration testing scope

Scope is the most important decision you make about a test — and it happens before anyone touches a keyboard. What to include, what to gather, which box-colour to pick, and the two classic mistakes.

August 2026 9 min read Usama Gul Read post →
LG
New
Industry

Penetration testing for logistics & supply chain

Stop a logistics operator and you stop the movement of goods. Why ransomware loves the sector, the sprawling EDI/API partner surface, and testing port and warehouse OT safely.

August 2026 8 min read Usama Gul Read post →
HT
New
Industry

Penetration testing for hospitality & hotels

A hotel holds your card and your passport, across a PMS, POS, booking engine, guest Wi-Fi, loyalty and door locks. Why hotels get breached, what PCI and PDPL require, and what a test must cover.

August 2026 8 min read Usama Gul Read post →
SSO
New
Technical

OAuth & SSO security testing

SSO sits in front of everything, so a login-flow flaw is account takeover for the whole app. The common OAuth, OIDC and SAML flaws — and why using Google or Okta doesn't fix an insecure integration.

August 2026 9 min read Usama Gul Read post →
STI
New
Technical

Server-side template injection (SSTI) explained

A single {{7*7}} that returns 49 is the tell — and from there it's often a short climb to running commands on your server. How SSTI works, the detect-then-escalate method, and how to design it out.

August 2026 8 min read Usama Gul Read post →
DS
New
Technical

Insecure deserialization explained

It turns a routine "rebuild this object from bytes" into running the attacker's code on your server — from one crafted input, no credentials. How serialized data becomes RCE, and what a gadget chain is.

August 2026 8 min read Usama Gul Read post →
XXE
New
Technical

XXE injection explained

Hand an XML parser a booby-trapped document and it will fetch a file off the server or fire a request at an internal system. How XXE works, and where it hides — SOAP, SAML, and every DOCX or SVG upload.

August 2026 8 min read Usama Gul Read post →
HIP
New
Compliance

HIPAA penetration testing requirements explained

HIPAA never says "penetration test" — but the risk analysis and evaluation standards require you to find and evaluate technical risks to ePHI, and testing is how. Who's in scope, how often, and what OCR expects.

August 2026 8 min read Usama Gul Read post →
PDL
New
Compliance

PDPL penetration testing requirements (Saudi & UAE)

The Saudi and UAE PDPLs don't say "you must pentest" — but both demand you secure personal data and prove it works. How testing evidences the duty, and the cross-border data trap that catches GCC firms.

August 2026 8 min read Usama Gul Read post →
API
New
Technical

OWASP API Security Top 10 explained (2023)

APIs broke the old rulebook — the top threats are authorisation flaws, not injection. Each risk from BOLA to unsafe third-party consumption, how it's exploited, and how to test and fix it.

August 2026 10 min read Usama Gul Read post →
SW
New
Compliance

SWIFT CSP assessment & penetration testing explained

If you send payments over SWIFT, the CSP is mandatory. The CSCF controls, the secure zone, the annual attestation, and where pentesting fits — alongside your SAMA or CBB obligations.

August 2026 8 min read Usama Gul Read post →
CI
New
Technical

CI/CD pipeline security testing: attacks & defences

Your pipeline holds the keys to everything and runs code on every push — the highest-value asset most pentests skip. Poisoned execution, secret sprawl, supply-chain integrity, and how to test it.

August 2026 9 min read Usama Gul Read post →
Q15
New
Buyer's Guide

15 questions to ask a penetration testing vendor

Every quote looks similar on paper — and some hide a scanner with a cover page. The 15 questions that separate a real provider from a scan-and-invoice shop, with ideal answers and red flags.

August 2026 9 min read Usama Gul Read post →
AUH
New
Local Hub

Penetration testing services in Abu Dhabi

Abu Dhabi runs its own regimes — ADHICS for healthcare, the FSRA for ADGM — over the federal UAE IA and PDPL. What an engagement covers, what it costs, and why local fluency gets your report accepted first time.

August 2026 8 min read Usama Gul Read post →
MF
New
Industry

Penetration testing for manufacturing (IT/OT)

Downtime is money per minute — which is why factories are a ransomware favourite. The IT/OT convergence risk, what to test across ERP, MES and SCADA, and how to test live production without breaking it.

August 2026 8 min read Usama Gul Read post →
RT
New
Industry

Penetration testing for retail & POS

Retail spreads card data and customer records across the widest attack surface in business. Why retailers get hit, the PCI/PDPL drivers, and the business-logic flaws that hit the P&L directly.

August 2026 8 min read Usama Gul Read post →
ISO
New
Compliance

ISO 27001 penetration testing requirements explained

ISO 27001 never says "pentest must be performed" — but Annex A A.8.8 and A.8.29 require it in practice, and auditors expect it. How testing maps to the standard, how often, and what evidence closes the loop.

August 2026 8 min read Usama Gul Read post →
PCI
New
Compliance

PCI DSS 4.0 penetration testing requirements

If you touch card data, Requirement 11.4 is non-negotiable: internal and external tests every year and after change, plus segmentation testing. Exactly what PCI v4.0 asks, the cadence, and who can test.

August 2026 9 min read Usama Gul Read post →
MOB
New
Technical

Mobile app security testing checklist (iOS & Android)

A mobile app ships your code to a device the attacker controls. The OWASP MASVS checklist across storage, crypto, cert pinning, platform IPC and code protection — plus the backend API, where the real risk lives.

August 2026 9 min read Usama Gul Read post →
EN
New
Buyer's Guide

What happens after you book a pentest: the engagement timeline

Scoping, kickoff, testing, live critical alerts, reporting, readout, remediation, retest — every stage of an engagement and exactly what's needed from you at each one.

August 2026 8 min read Usama Gul Read post →
IN
New
Industry

Penetration testing for insurance companies

Insurers concentrate health, identity and payment data and move money. Why they're a prime target, the CBB/NCA/PDPL/PCI drivers, and the business-logic flaws that expose one policyholder to another.

August 2026 8 min read Usama Gul Read post →
ND
New
Compliance

NIS2 vs DORA: penetration testing requirements compared

Two EU regimes, two testing bars — DORA's TLPT threat-led red teaming vs NIS2's risk-based testing. Who each applies to, what it mandates, and how GCC firms with EU footprints get reached.

August 2026 9 min read Usama Gul Read post →
SA
New
Platform

SAP security assessment & penetration testing

SAP runs your finance and supply chain on its own protocols. Why it needs specialist testing — Gateway, RFC, ABAP, roles and SoD, plus the Fiori/OData surface — without breaking production.

August 2026 9 min read Usama Gul Read post →
SM
New
Technical

Session management testing checklist (web apps)

A stolen token lets an attacker be your user. Cookie flags, token entropy, session fixation, timeout, logout invalidation, concurrent sessions and JWT pitfalls — OWASP-mapped, with how-to-test notes.

August 2026 9 min read Usama Gul Read post →
WL
New
Partner

White-label penetration testing for MSPs & agencies

Offer pentesting under your own brand without hiring a red team. How the partner model works, what gets branded to you, the margins, and keeping quality when the delivery isn't yours.

August 2026 8 min read Usama Gul Read post →
VQ
New
Trigger

Vendor security questionnaires: the pentest questions decoded

A prospect sent a 200-row security questionnaire. What each pentest question really asks, how to answer honestly without over-committing, and exactly what evidence to attach.

August 2026 9 min read Usama Gul Read post →
VD
New
Compliance

Pentest requirements for Vanta, Drata & Secureframe users

Your compliance platform flagged a pentest evidence gap. The tool doesn't run the test — here's exactly what it needs from a third-party report, and how to time it to your audit window.

August 2026 8 min read Usama Gul Read post →
LO
New
Commercial

Local vs offshore penetration testing: which is right for you?

Offshore wins on day rate; local often wins on total cost once you count rework, data residency and regulatory mapping. An honest decision framework — and when offshore genuinely wins.

August 2026 9 min read Usama Gul Read post →
DXB
New
Local Hub

Penetration testing services in Dubai

Dubai layers DESC ISR, DFSA/DIFC data law, UAE IA and PDPL. What a Dubai engagement covers, what it costs, and why regional fluency decides whether your report is accepted first time.

August 2026 8 min read Usama Gul Read post →
BHR
New
Buyer's Guide

Best penetration testing companies in Bahrain (2026)

Ten providers with a genuine Bahrain presence — the Beyon, CTM360 and telco players — with a comparison table, the exact CBB reporting cycle, cited stats, and a scored method.

July 2026 12 min read Usama Gul Read post →
KSA
New
Buyer's Guide

Best penetration testing companies in Saudi Arabia (2026)

Eleven providers a Saudi buyer should know — NCA-licensed SOC operators, Aramco- and stc-backed players, and the Big 4 — with a comparison table, NCA/SAMA regulator map, cited stats, and a scored method.

July 2026 13 min read Usama Gul Read post →
UAE
New
Buyer's Guide

Best penetration testing companies in the UAE (2026)

Eleven providers a UAE buyer should know — with HQ, focus and accreditations, a comparison table, a DESC/NESA regulator map, cited breach stats, and the scored method we used to rank them.

July 2026 13 min read Usama Gul Read post →
WC
New
Buyer's Guide

Web application penetration testing cost: what drives the price

The price is a count of tester-days — driven by app size, roles, business logic and depth. The six cost drivers, and how to scope for value without paying pentest rates for a scan.

July 2026 8 min read Usama Gul Read post →
PT
New
Comparison

PTaaS vs traditional penetration testing

A platform-delivered model adds real continuity — or hides automated scanning behind a dashboard. The delivery model doesn't answer the only question that matters: how much is manual?

July 2026 8 min read Usama Gul Read post →
ST
New
Technical

Subdomain takeover: detection and prevention

A dangling DNS record pointing at a deprovisioned service lets anyone claim a subdomain of your domain — inheriting your brand's trust for phishing and worse. How to find and fix it.

July 2026 7 min read Usama Gul Read post →
MA
New
Technical

Mass assignment vulnerabilities in modern frameworks

The one-line binding that saves a form is the same one that lets an attacker set isAdmin by adding a field. Why it's in the OWASP API Top 10, and the allow-list fix.

July 2026 7 min read Usama Gul Read post →
JB
New
AI Security

LLM jailbreak testing for production applications

Once your branded assistant is producing harmful output, it's your incident — whoever typed the prompt. How jailbreaks defeat guardrails, and how to test and defend in layers.

July 2026 8 min read Usama Gul Read post →
BH
New
Local

Penetration testing services in Bahrain

Bahrain's financial sector runs on the CBB's twice-yearly clock. What a Kingdom engagement involves, what it costs, and why a report mapped to CBB reporting matters at deadline.

July 2026 8 min read Usama Gul Read post →
EC
New
Industry

Penetration testing for e-commerce & retail

The dangerous flaw is a checkout that lets someone buy a $1,000 item for $1, or a script quietly skimming cards. Testing the money and the logic, mapped to PCI DSS.

July 2026 9 min read Usama Gul Read post →
BC
New
Buyer's Guide

Building the business case for a penetration test

"We should be more secure" doesn't win budget. The four arguments leadership responds to — revenue, risk, compliance, due diligence — and how to tie them to a trigger.

July 2026 8 min read Usama Gul Read post →
K8
New
Technical

Kubernetes & container security testing

One misconfigured permission or over-privileged container turns a single pod into cluster control. The real attack surface — RBAC, container escape, secrets — and how to harden it.

July 2026 9 min read Usama Gul Read post →
RM
New
Post-purchase

Writing a remediation plan your auditor will accept

Auditors want findings managed, not just fixed. The fields each finding needs, how to prioritise, how to document accepted risk, and the retest that closes it out.

July 2026 8 min read Usama Gul Read post →
KB
New
Technical

Kerberoasting: how it works and how to stop it

Any domain user can crack service-account passwords offline, with no exploit and no lockouts. How the attack works step by step, why it succeeds, and the fixes that stop it.

July 2026 8 min read Usama Gul Read post →
GQ
New
Technical

GraphQL penetration testing: attack surface and method

Introspection, nested-query DoS, BOLA, batching abuse and injection — the GraphQL-specific flaws a tester who treats it like REST will miss, and how to secure them.

July 2026 8 min read Usama Gul Read post →
RG
New
AI Security

RAG security: how retrieval pipelines leak data

The model isn't the weak point — the retrieval layer is. How missing access control, indirect prompt injection and knowledge-base poisoning turn AI assistants into leak channels.

July 2026 9 min read Usama Gul Read post →
MC
New
AI Security

MCP & AI agent security testing

Give a model tools and prompt injection stops being a text problem and becomes a real one. Excessive agency, tool poisoning, and how to verify a compromised model can't compromise the system.

July 2026 9 min read Usama Gul Read post →
DR
New
Compliance

DORA TLPT requirements for EU financial entities

DORA's threat-led penetration testing — who's in scope, how often, the TIBER-EU basis, and why it's a red-team-style step change from a standard pentest.

July 2026 9 min read Usama Gul Read post →
AL
New
Post-purchase

The penetration test attestation letter, explained

The shareable proof that testing happened — what it contains, how it differs from the full report, and why it's often the artefact that unblocks an enterprise deal or audit.

July 2026 7 min read Usama Gul Read post →
RP
New
Buying Asset

Penetration testing RFP template: what to ask and include

Nine sections and the questions that separate real, human-led testing from a scan in a nicer PDF — so you get comparable proposals and buy the right thing.

July 2026 9 min read Usama Gul Read post →
IO
New
Comparison

In-house vs outsourced penetration testing

Not a cost decision but a choice between independence and intimacy — why an internal team and an external provider solve different problems, and why most need both.

July 2026 8 min read Usama Gul Read post →
SA
New
Local

VAPT services in Saudi Arabia: engagements, costs, timelines

The NCA, SAMA and PDPL drivers, what a KSA engagement covers, timelines and cost drivers — and why a report not mapped to your control set gets sent back.

July 2026 9 min read Usama Gul Read post →
FP
New
Post-purchase

What to do when you "fail" a penetration test

A pentest isn't pass/fail — a report full of criticals did its job. The calm, structured response: triage, remediate, retest, communicate, and fix the root causes.

July 2026 8 min read Usama Gul Read post →
RF
New
Compliance

Penetration testing requirements by framework: a master comparison

What SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR, CMMC, FedRAMP, NIST and the GCC regulators each require — explicit vs expected, cadence, and how one test can satisfy several.

July 2026 10 min read Usama Gul Read post →
RT
New
Guide

What is red teaming? And when you're not ready for it

A goal-based, adversarial simulation that tests detection and response — how it differs from a pentest, and the honest signs a purple team is your smarter first step.

July 2026 9 min read Usama Gul Read post →
BW
New
Comparison

Black box vs gray box vs white box penetration testing

How much the tester knows changes everything — realism, coverage, cost. Why gray box is the pragmatic default for application testing.

July 2026 8 min read Usama Gul Read post →
IE
New
Comparison

Internal vs external penetration testing

External tests whether the front door holds; internal tests what happens once someone's in. Why real breaches need both — and PCI DSS requires them.

July 2026 8 min read Usama Gul Read post →
SB
New
Comparison

Vulnerability scanning vs penetration testing vs bug bounty

Breadth, depth-on-a-schedule, or continuous crowd coverage — what each is for, why a bounty can't replace a pentest, and how to layer them.

July 2026 9 min read Usama Gul Read post →
BL
New
Technical

Business logic vulnerabilities and why scanners miss them

Abusing legitimate features without breaking a single technical rule — why automated tools are structurally blind to them, and how manual testing finds them.

July 2026 9 min read Usama Gul Read post →
RT
New
Post-purchase

Retesting after remediation: how it works and what it proves

Turning "we fixed it" into "it's proven fixed" — how a retest verifies closure, catches failed fixes, and produces the attestation auditors and customers want.

July 2026 7 min read Usama Gul Read post →
AR
New
AI Security

AI red teaming vs AI penetration testing

One secures the whole LLM application against the OWASP LLM Top 10; the other stress-tests the model's behaviour. When you need which — and where they overlap.

July 2026 9 min read Usama Gul Read post →
CC
New
Local

GCC cybersecurity compliance calendar: testing deadlines by regulator

The penetration testing cycles for CBB, NCA, SAMA, the UAE, Qatar, Kuwait and Oman — and the buying windows to book testing before each deadline.

July 2026 9 min read Usama Gul Read post →
BG
New
Buyer's Guide

Best penetration testing companies in the GCC: how to evaluate them

The market's three tiers and the six criteria that actually decide quality — a framework to judge any provider (us included) on the merits, with disclosure.

July 2026 9 min read Usama Gul Read post →
WP
New
Guide

What is penetration testing? A practitioner's guide

The cornerstone definition: an authorised, simulated cyberattack that finds and safely exploits vulnerabilities before real attackers do — its purpose, seven phases, types and who needs one.

July 2026 10 min read Usama Gul Read post →
VA
New
Comparison

Penetration testing vs vulnerability assessment: a complete comparison

One finds and ranks weaknesses at breadth; the other exploits them to prove impact at depth. The full comparison, why compliance treats them separately, and what VAPT means.

July 2026 9 min read Usama Gul Read post →
HO
New
Guide

How often should you run a penetration test?

At least annually and after any significant change — with cadence driven by compliance (PCI 11.4), risk and rate of change. Where continuous testing fits.

July 2026 8 min read Usama Gul Read post →
ME
New
Guide

Penetration testing methodology: PTES, OWASP & NIST SP 800-115

The main methodologies explained and compared — and how a rigorous test combines a process standard with OWASP's technical checklists, mapped to MITRE ATT&CK.

July 2026 9 min read Usama Gul Read post →
TR
New
Post-purchase

How to prioritise and triage penetration test findings

Rank by real risk, not raw CVSS. Separate quick wins from strategic fixes, set severity-based SLAs, handle accepted risk, and close the loop with a retest.

July 2026 9 min read Usama Gul Read post →
CL
New
Technical

AWS vs Azure vs GCP: penetration testing rules of engagement

What each cloud allows — AWS permitted services, Azure's dropped notification (2017), GCP's no-contact rule — and the prohibitions common to all three.

July 2026 10 min read Usama Gul Read post →
AD
New
Technical

Active Directory attack paths found in most internal tests

Poisoning and relay, Kerberoasting, ADCS ESC, delegation abuse — the recurring path to Domain Admin, why it exploits defaults not bugs, and how to close it.

July 2026 10 min read Usama Gul Read post →
CH
New
Buyer's Guide

How to choose a penetration testing company: 20 questions to ask

Twenty questions across credentials, methodology, scope, reporting and commercials — so you buy real, human-led testing and not a rebranded scan.

July 2026 9 min read Usama Gul Read post →
SA
New
Industry

Penetration testing for SaaS startups: SOC 2 ready

Satisfy SOC 2, pass enterprise security reviews, and prove multi-tenant isolation — testing scoped and timed for a SaaS startup and its budget.

July 2026 9 min read Usama Gul Read post →
FT
New
Industry

Penetration testing for fintech: where the real risk is the logic

Payment and transaction logic, API-first architectures, wallets and open-banking integrations — mapped to PCI DSS, SAMA and CBB. Why business logic is the crown jewel.

July 2026 9 min read Usama Gul Read post →
AI
New
AI Security

The OWASP LLM Top 10 (2025) explained, with how each is tested

All ten 2025 risks — from prompt injection to unbounded consumption — what each means, the two new entries, and how an AI penetration test assesses them.

July 2026 11 min read Usama Gul Read post →
PI
New
AI Security

Prompt injection testing: the #1 LLM risk, and how we find it

Direct vs indirect injection, the real-world variants, why it's considered unsolved, how an AI pentest finds it, and the mitigations that genuinely reduce the risk.

July 2026 9 min read Usama Gul Read post →
GL
Reference
Glossary

Penetration testing glossary: 55 terms defined

A plain-English reference — from BOLA and SSRF to CVSS, red teaming and prompt injection — grouped by category, each defined in a sentence or two.

July 2026 55 terms Usama Gul Read post →
BD
New
Buyer Trigger

The board is asking about security posture — how to answer with evidence

What directors actually want to hear, how a penetration test gives you the independent evidence to answer, and how to present results at board level.

July 2026 7 min read Usama Gul Read post →
LN
New
Guide

Do you need a penetration test before launch?

When a pre-launch test is essential, when you can defer, what to test, and how to fit it into your release timeline without slipping the date.

July 2026 7 min read Usama Gul Read post →
72
New
Incident

We've been breached — what to do in the first 72 hours

Contain, preserve evidence, meet GCC notification deadlines, and where penetration testing fits once the fire is out. A calm, practical guide.

July 2026 8 min read Usama Gul Read post →
QA
New
Compliance Guide

Qatar penetration testing requirements: QCB & the NIA Policy

QCB requires semi-annual VAPT and two penetration tests a year for banks; the NIA Policy sets an annual security assurance plan for government. The Gulf's most specific mandate, in its own words.

July 2026 10 min read Ankur H. Read post →
KW
New
Compliance Guide

Kuwait penetration testing requirements: the new CBK CORF

The CBK Cyber & Operational Resilience Framework (Dec 2025) replaced the 2020 CSF and added mandatory annual red teaming, plus IoT/OT testing. Control-by-control.

July 2026 10 min read Ankur H. Read post →
OM
New
Compliance Guide

Oman penetration testing requirements: CBO & MTCIT

The CBO CS&RF mandates VAPT for financial institutions; MTCIT accredits providers for government testing. An honest guide — including where the public control text runs out.

July 2026 9 min read Ankur H. Read post →
CI
New
Buyer Trigger

Your cyber insurance requires a penetration test — what to do

Why insurers ask, what actually satisfies them, how a pentest affects your premium and coverage, and the claim-denial trap of misrepresenting your security on the application.

July 2026 7 min read Usama Gul Read post →
AR
New
Compliance

Your auditor rejected your vulnerability scan — why a scan isn't a pentest

Why a scan doesn't satisfy SOC 2, PCI DSS or ISO 27001, the real difference between the two, and how to fix it fast with an audit-ready penetration test.

July 2026 7 min read Ankur H. Read post →
1T
New
Guide

Your first penetration test: a guide for first-time buyers

What a test is, whether you need one, what to expect, how to scope your first engagement, what you'll receive, and the first-timer mistakes to avoid.

July 2026 8 min read Usama Gul Read post →
MA
New
Buyer Trigger

Security due diligence in M&A: what acquirers actually check

What cybersecurity due diligence covers, why a penetration test moves valuation and deal risk, and how to prepare whether you're buying or being bought.

July 2026 8 min read Usama Gul Read post →
TY
New
Guide

The types of penetration testing (and which one you need)

Tests are categorised three ways — by target, by tester knowledge (black/grey/white box), and by perspective (external/internal). Understand the axes to scope the right test.

July 2026 8 min read Usama Gul Read post →
S2
New
Compliance

We failed our SOC 2 audit — what happens next?

What a qualified opinion really means, why a missing penetration test is a common cause (CC4.1 names it), and the exact path back to a clean report.

July 2026 8 min read Ankur H. Read post →
HL
New
Guide

How long does a penetration test take? Real timelines

One to three weeks of testing plus reporting — but scope decides. Timelines by test type, what drives duration, the full engagement timeline, and how to speed it up.

July 2026 6 min read Usama Gul Read post →
PR
New
Guide

How to prepare for a penetration test: a pre-engagement checklist

The difference between a smooth, high-value test and a slow one is decided before day one. Scope, access, environment and stakeholders — plus a ready-to-use checklist.

July 2026 7 min read Usama Gul Read post →
AE
New
Compliance Guide

UAE IA Regulation (NESA) penetration testing requirements: control T7.7.1

What the UAE Information Assurance Regulation — the standard most still call NESA — requires of security testing, its priority-P1 control, who complies, and how it links to ADHICS and DESC.

July 2026 10 min read Ankur H. Read post →
AD
New
Compliance Guide

ADHICS penetration testing requirements: control OM 7.1 for Abu Dhabi healthcare

Abu Dhabi's healthcare standard names penetration testing, vulnerability assessment and web security assessment on a yearly schedule. What OM 7.1 requires, the tiers, and how it maps to UAE IA.

July 2026 10 min read Ankur H. Read post →
DB
New
Compliance Guide

DESC ISR penetration testing requirements: Dubai's information security regulation

What Dubai's DESC ISR expects of security testing, who it binds, and what can honestly be said about cadence given the control catalogue is access-restricted.

July 2026 9 min read Ankur H. Read post →
MA
New
Comparison

Manual vs automated penetration testing: what each actually finds

Scanners are fast; humans find the access-control and business-logic flaws behind real breaches. What each does well, why "automated pentest" misleads, and how to use both.

July 2026 8 min read Usama Gul Read post →
RD
New
Guide

How to read a penetration test report, section by section

Executive summary, scope, findings, CVSS severity, proof of concept, remediation — what every part means, and exactly what to do with the report once you have it.

July 2026 8 min read Usama Gul Read post →
RQ
New
Buyer Trigger

Your customer wants a pentest report: what they actually need

An enterprise customer made a penetration test report a condition of the deal. What they actually want, what counts as acceptable, what to send, and how to get one without stalling the contract.

July 2026 7 min read Usama Gul Read post →
VS
New
Comparison

Boutique vs Big 4 penetration testing: which fits a regulated buyer?

An honest comparison — where each genuinely wins on depth, price, procurement and tester seniority, and the one question that matters more than firm size: who actually holds the keyboard?

July 2026 9 min read Usama Gul Read post →
RF
Tool
Interactive Tool

Penetration testing requirements by framework: the 2026 finder

Select your framework — CBB, SAMA, NCA ECC, PCI DSS, SOC 2, HIPAA, ISO 27001, FedRAMP, DORA — and get the exact testing frequency, scope, mandatory status and control reference.

July 2026 Interactive Ankur H. Open tool →
$$
Featured
Buyer's Guide

How much does penetration testing cost in 2026?

The honest answer is a range: $4,000 to $150,000+, most engagements $10,000-$30,000. Real 2026 prices by test type, methodology, pricing model and compliance framework, plus a GCC note.

July 2026 11 min read Usama Gul Read post →
SA
New
Compliance Guide

SAMA CSF penetration testing & red teaming: the 2026 guide for Saudi financial institutions

Control 3.2.4 requires annual penetration testing; the separate FEER framework requires red teaming every three years. The maturity model, who must comply, and how SAMA sits alongside the NCA ECC.

July 2026 12 min read Ankur H. Read post →
EC
New
Compliance Guide

NCA ECC penetration testing requirements: control 2-11 explained for Saudi organizations

The verified control text, what "periodically" really means, who must comply, ECC-2:2024 changes, and how CSCC, OTCC and SAMA relate to the base ECC.

July 2026 12 min read Ankur H. Read post →
CB
New
Compliance Guide

CBB penetration testing requirements: the 2026 guide for Bahrain financial institutions

Testing twice a year in June and December, reports due 30 September and 31 March, two-year tester rotation, and the exact CBB Rulebook reference for banks, insurers, investment firms and payment providers.

July 2026 11 min read Usama Gul Read post →
OW
Featured
Pen Testing Deep-Dive

OWASP Top 10 2021 → 2026: what actually changed in real engagements

Five years of OWASP data, mapped against hundreds of actual pen test findings. Broken Access Control still leads - but SSRF, injection, and insecure design have shifted in ways the updated list doesn't fully capture. Here's what we're actually finding in 2026.

April 2026 14 min read CyberFortify Research Read post →
Mobile Security

Bypassing certificate pinning on iOS in 2026 - Frida, Objection, KeychainItem

Rootless jailbreaks, TrustKit, Network.framework, and custom pinning implementations. A full walkthrough of every technique we use in mobile pen tests today - and what to do when Objection doesn't work.

April 2026 16 min read Read →
Cloud Security

SSRF → IMDSv2 → STS: the cloud privilege-escalation chain we still see weekly

The full attack chain: SSRF entry point to AWS metadata service to IAM credential theft to STS AssumeRole privilege escalation. With real request examples, Azure/GCP equivalents, and remediation that actually works.

April 2026 12 min read Read →
API Security

BOLA in REST APIs: why scanners miss the most common API1 finding

Object-level authorization failures are OWASP API Top 10 #1 for a reason - and automated scanners are structurally incapable of finding them. Here's how we test for BOLA manually, including GraphQL variants and compound key patterns.

April 2026 11 min read Read →
Compliance

PCI DSS v4.0 segmentation testing - what auditors now expect under 11.4.5

Requirement 11.4.5 tightened significantly in PCI DSS v4.0. QSAs now expect evidence that your segmentation controls actively prevent CDE-scope expansion. Here's what the test must cover, what auditors reject, and what a passing deliverable looks like.

April 2026 10 min read Read →
Strategy

Red team vs pen test: when each is wrong

The most expensive mistake in security procurement is buying the wrong engagement type. Pen tests that should have been red teams, red teams that should have been pen tests - and the questions that tell you which you actually need.

April 2026 9 min read Read →
Web App Security

Clickjacking attacks: how invisible iframes hijack user clicks - and how to stop them

Clickjacking (UI redressing) requires no malware and no XSS - just a transparent iframe and an authenticated session. Attack anatomy, six real variants, X-Frame-Options vs CSP frame-ancestors, frame busting bypasses, and a six-point prevention checklist.

April 2026 10 min read Read →
Pen Testing

Web application pen testing tools for evolving attack surfaces

SPAs, GraphQL, edge functions, AI-powered apps - the attack surface has changed. So has the toolchain. A practitioner's guide to the proxy tools, recon utilities, API testing rigs, and specialized scanners we use in 2026 engagements.

Nov 2025 13 min read Read →
Compliance

The link between compliance and protection: how cybersecurity consulting bridges the gap

Compliance gives you a documented security posture. Protection gives you an actual one. Most organisations discover the gap between them during a breach. Here's how consulting bridges it - and what a mature programme looks like when both are working.

Nov 2025 11 min read Read →
Compliance

How regulatory compliance consulting services can help your organisation

SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, FTC Safeguards, CMMC - the regulatory landscape compounds every year. What compliance consulting actually delivers, common mistakes that derail audits, and how to right-size the engagement for your maturity level.

Oct 2025 10 min read Read →
Partnership

Koop × CyberFortify: when compliance gets smart and security gets strong

Koop's automated compliance intelligence combined with CyberFortify's manual offensive security practice. Why automated GRC and manual pen testing aren't alternatives - they're a force multiplier when used together.

Nov 2025 8 min read Read →
Free Resource

Web Application Pentest Checklist - 2026 edition

156 test cases across pre-engagement, recon, authentication, authorization, injection, cryptography, API, business logic and reporting phases. Download the full PDF or browse the interactive version.

Always updated Free download Get checklist →

Ready for a real engagement?

Every post here is drawn from real pen test findings. When you're ready to test your own systems, our offensive security team will find what your scanners and automated tools miss.

Schedule scoping call →