top of page

BLOG
Search


We Pointed an Autonomous AI Pentester at a Deliberately Broken API. It Came Back With a Root Shell
AigentX, our autonomous web-application penetration testing agent, ran black-box against OWASP crAPI and confirmed 35 exploitable findings, 15 of them Critical, including a chain that turns a free signup account into uid=0(root) and a permanently forged admin identity. Every finding below carries a request, a response, and a reproduction. The full report is one click away. 35 Confirmed Findings 15 Critical 11 High 4 Kill Chains 0 False Positives Most “AI found N vulnerabiliti
Komodo Research
Jun 153 min read


How To Handle Security Due Diligence During The M&A Process
More often than not, we see our clients show interest in other companies. This pull can come in many different forms, but it's usually...
Komodo Research
Dec 31, 20212 min read


Can Security Red-Team Exercises Give You ROI On Your Cyber Security Expenses?
Penetration testing has always been a way for companies to test their resilience to a cyberattack and their preparedness. In recent...
Komodo Research
Nov 16, 20215 min read


Baking Security Into the Development Lifecycle
Application security is not new. It has been around since the early 2000s and in a similar environment, where Code-Red, Nimda, and other viruses were causing global havoc. Securing the software development lifecycle was initially a Microsoft initiative developed due to the growing number and impact of vulnerabilities in its products and code. The model has significantly evolved since, though the principles remain the same: catch security bugs early on in the development cyc
Komodo Research
Oct 29, 20215 min read


Prototype Pollution - The Vulnerability Impacting JavaScript Applications
Prototype pollution attack is a relatively new and slightly unfamiliar vulnerability. However, in the last few years, we have benefitted...
Komodo Research
Sep 15, 20212 min read
bottom of page