-
MCP OAuth Account Takeover: How Open Dynamic Client Registration Enables One-Click ATO on AI Integrations
How an unauthenticated POST to an MCP OAuth registration endpoint chains with arbitrary redirect URIs and absent PKCE enforcement to produce a one-click account takeover on AI integrations - with exact curl commands.
-
The FBI Jobs Portal Breach: What ShinyHunters' FBIjobs.gov Hack Actually Tells Us About Government-Facing Web Applications
What ShinyHunters' defacement and data theft claims at FBIjobs.gov reveal about application-layer security for public-facing government portals - and what any organization running a comparable application should be asking now.
-
Manual Penetration Testing vs Automated Scanners: What SaaS Teams Get Wrong in 2026
A direct comparison of manual penetration testing and automated vulnerability scanners, explaining why scanners miss business logic flaws, IDORs, and auth bypasses that real attackers exploit - and what growth-stage SaaS teams should be doing instead.
-
Penetration Testing Cost: What Drives the Price in 2026
What actually moves the price on a pentest quote - scope, manual vs automated, tester experience, engagement model - and how to tell a real test from a scanner report with a consulting markup.