DEV Community

#pentesting

Offensive security techniques and methodologies for penetration testing.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Ultimate IDOR Testing Checklist (2026 Edition)

The Ultimate IDOR Testing Checklist (2026 Edition)

Comments 2
6 min read
Private APN Pivoting: Polish Energy Grid RCE via Telecom Infrastructure

Private APN Pivoting: Polish Energy Grid RCE via Telecom Infrastructure

Comments
5 min read
OT Isolation as Attack Surface: Weaponizing CISA's Defense Guidance

OT Isolation as Attack Surface: Weaponizing CISA's Defense Guidance

Comments
6 min read
HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

Comments
4 min read
Hunting the #1 API Vulnerability (BOLA) in Your Own REST API

Hunting the #1 API Vulnerability (BOLA) in Your Own REST API

6
Comments
8 min read
Qilin Ransomware Exploits PAN-OS GlobalProtect Auth Bypass

Qilin Ransomware Exploits PAN-OS GlobalProtect Auth Bypass

Comments
5 min read
EDR Bypass in 2026: How Attackers Evade Modern Endpoint Detection

EDR Bypass in 2026: How Attackers Evade Modern Endpoint Detection

Comments
2 min read
Oracle PeopleSoft Supply Chain Compromise: Nissan & 99 Targets

Oracle PeopleSoft Supply Chain Compromise: Nissan & 99 Targets

Comments
5 min read
AWS Security Agent: Pentesting and Threat Modeling On Demand

AWS Security Agent: Pentesting and Threat Modeling On Demand

Comments
6 min read
AI Agent Security Audit: From MCP Penetration Testing to LLM Vulnerability Assessment

AI Agent Security Audit: From MCP Penetration Testing to LLM Vulnerability Assessment

Comments 3
7 min read
Dream AI Cybersecurity Unicorn: Sovereign Defense Infrastructure & Attack Surface Implications

Dream AI Cybersecurity Unicorn: Sovereign Defense Infrastructure & Attack Surface Implications

Comments
5 min read
JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration

JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration

Comments
6 min read
A Practical Web Application Reconnaissance Methodology for Penetration Testing

A Practical Web Application Reconnaissance Methodology for Penetration Testing

2
Comments
11 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.