Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
API Authorization: Finding and Fixing BOLA/IDOR
Test whether each API caller may act on the requested object, using authorized accounts, synthetic records and explicit permission checks.
Read MoreMicrosoft 365 and Entra ID: Reducing Account-Takeover Exposure
Review authentication, Conditional Access, sessions, recovery and privileged access together to reduce account-takeover exposure.
Read MoreActive Directory Certificate Services: Pentest Priorities and Defensive Remediation
Review AD CS certificate templates, enrollment rights and authentication paths, then assign and verify defensive changes.
Read MoreWorking with Slovenian IT Teams: A Pentester Perspective
From bilingual NIS2 reports for URSIV to in-person Ljubljana debriefs — what I've learned about effective collaboration with Slovenian IT teams during pentests.
Read MoreGDPR and Security Testing: Slovenian Perspective
How pentesting fulfils GDPR Articles 32, 25, 33, and 35 — and why Slovenian organizations under ZVOP-2 should treat it as a compliance tool, not just a technical exercise.
Read MoreCommon Vulnerabilities in Slovenian Companies
Real patterns from pentesting Slovenian organizations: Active Directory misconfigurations, Kerberoastable accounts, NTLM relay, and recurring web application flaws.
Read MoreCybersecurity Careers in Slovenia: Getting Started
From SOC analyst roles to CTF achievements and HackerOne findings — practical steps to launch a cybersecurity career in Slovenia's growing market.
Read MoreChoosing a Penetration Testing Provider in Slovenia
From OSCP and OSCE3 credentials to sample reports and pricing red flags — a practical guide to picking a trustworthy pentest provider in Slovenia.
Read MoreNIS2 in Slovenia: What Organizations Need to Know
Practical breakdown of NIS2 scope, risk management obligations, and supply-chain requirements for Slovenian essential and important entities.
Read MoreThe Cybersecurity Landscape in Slovenia
From NIS2-driven demand to a growing talent gap, here's how Slovenia's cybersecurity market is evolving — and where it's heading.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.