LLM Injection: How Attackers Can Manipulate AI Chatbots

AI-powered chatbots and conversational assistants are becoming increasingly common in websites and business applications. They can answer customer questions, provide product information, assist employees and handle conversations automatically. But unlike traditional applications, these systems interpret natural language as instructions. This creates a new security risk known as LLM injection or prompt injection. What Is LLM…

Modern Applications Have Changed. Has Your Pentest Methodology?

Modern applications are no longer built from scratch. Today, it is common for applications to rely on services such as Clerk or Auth0 for authentication, AWS for cloud infrastructure, GraphQL for APIs, Stripe for payments, and various third-party SaaS platforms and APIs. These services are generally mature and have dedicated security teams. Developers can rely…

Your Attacker Doesn’t Follow Your User Flow. Neither Should Your Penetration Tester.

“But we already implemented that.” This is something we occasionally hear after reporting a vulnerability. The development team checks the application and confirms: The button is hidden. The option is disabled. The user cannot perform that action through the GUI. So why is there a vulnerabilty? Yes — the control may already exist in the…

single page application

Top 5 Common SPA Vulnerabilities

Single Page Applications (SPAs) have become increasingly popular for modern web applications. Frameworks such as React, Angular, and Vue allow developers to build fast, interactive applications that communicate extensively with backend APIs. However, an SPA also introduces a different security attack surface. Much of the application’s logic is handled by JavaScript running in the user’s…

Top 5 Critical Fintech Vulnerabilities Uncovered During Penetration Testing

Every second, fintech platforms process high-value transactions, store sensitive financial data and connect with multiple third-party services through APIs. This makes them one of the most attractive targets for cybercriminals. Unlike traditional web applications, fintech platforms aren’t just protecting customer information—they’re protecting money. A single weakness in access control, business logic or authentication can result…

wireless penetration test service

The Hidden Threat in Your Guest Wi-Fi: Why Network Isolation is Non-Negotiable

For many businesses—cafés, hotels, or even corporate offices—offering free guest Wi-Fi is a standard courtesy. It keeps customers happy and visitors productive. However, if not configured correctly, that “friendly” guest network can act as a digital back door straight into your company’s most sensitive data. In this post, we’ll explore the dangers of “Guest-to-Internal” pivoting…

Code Review – a Necessity in the Age of AI

For many organisations, code review has traditionally been seen as something “nice to have.” A practice reserved for: Large enterprises Government projects High-assurance systems For everyone else—especially fast-moving teams—it was often skipped in favour of speed. That trade-off is becoming increasingly dangerous. AI Has Changed How Vulnerabilities Are Found The way vulnerabilities are discovered today…