Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
GraphQL Security: Beyond REST Vulnerabilities
GraphQL's single endpoint and introspection feature create unique risks — batching abuse, IDOR through aliases, and schema enumeration need dedicated testing methodology.
Read MoreJWT Security: Common Mistakes and How to Exploit Them
Algorithm confusion, none-bypass, weak HMAC secrets, and key injection attacks make JWT one of the most exploitable auth mechanisms I test. Here's the full breakdown.
Read MoreSSRF Attacks: Making Servers Attack Themselves
Server-Side Request Forgery hits differently in cloud-native stacks — IMDS credential theft, internal port scanning, and blind SSRF via DNS callbacks explained.
Read MoreOAuth Vulnerabilities: When Authentication Goes Wrong
From redirect_uri manipulation to subdomain takeover chains, OAuth misconfigurations are among the highest-impact findings in modern web pen tests.
Read MoreAPI Security Testing: A Practical Guide
APIs expose raw business logic — learn how to map endpoints, bypass auth, and exploit BOLA, mass assignment, and rate-limit flaws in real engagements.
Read MoreYour EDR Did Not Stop Me: Why Endpoint Detection Fails Against AD Attacks
EDR catches malware. It doesn't catch Kerberoasting, NTLM relay, or Pass-the-Hash — all legitimate protocol abuse. Here's what fills the gap.
Read MoreWhy MFA Fails Inside the Network: AD Authentication Gaps Attackers Exploit
100% MFA coverage on the dashboard, zero MFA prompts during my internal pentest. Pass-the-Hash and Kerberoasting bypass it entirely — here's why.
Read MoreThe Active Directory Kill Chain: How Attackers Move from Foothold to Domain Admin
Reconnaissance to DCSync follows a predictable path. I walk through each stage of the AD kill chain and exactly which controls would have stopped me.
Read MoreLAPS, gMSAs, and Tiered Administration: The Three Pillars of AD Defense
Most orgs implement LAPS or gMSAs partially and miss critical ACL details. Here's how to deploy all three AD hardening pillars the right way.
Read MoreKerberos Abuse: The Attacks Your Kerberos Infrastructure Enables
Kerberoasting, unconstrained delegation, and Golden Ticket attacks exploit how your Kerberos infrastructure is configured — not flaws in the protocol itself.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.