Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Web Security
Sep 19, 2024 Vid Grosek

GraphQL Security: Beyond REST Vulnerabilities

GraphQL's single endpoint and introspection feature create unique risks — batching abuse, IDOR through aliases, and schema enumeration need dedicated testing methodology.

Read More
Web Security
Sep 14, 2024 Vid Grosek

JWT Security: Common Mistakes and How to Exploit Them

Algorithm confusion, none-bypass, weak HMAC secrets, and key injection attacks make JWT one of the most exploitable auth mechanisms I test. Here's the full breakdown.

Read More
Web Security
Sep 09, 2024 Vid Grosek

SSRF Attacks: Making Servers Attack Themselves

Server-Side Request Forgery hits differently in cloud-native stacks — IMDS credential theft, internal port scanning, and blind SSRF via DNS callbacks explained.

Read More
Web Security
Sep 04, 2024 Vid Grosek

OAuth Vulnerabilities: When Authentication Goes Wrong

From redirect_uri manipulation to subdomain takeover chains, OAuth misconfigurations are among the highest-impact findings in modern web pen tests.

Read More
Web Security
Aug 30, 2024 Vid Grosek

API Security Testing: A Practical Guide

APIs expose raw business logic — learn how to map endpoints, bypass auth, and exploit BOLA, mass assignment, and rate-limit flaws in real engagements.

Read More
AD Attacks
Aug 25, 2024 Vid Grosek

Your EDR Did Not Stop Me: Why Endpoint Detection Fails Against AD Attacks

EDR catches malware. It doesn't catch Kerberoasting, NTLM relay, or Pass-the-Hash — all legitimate protocol abuse. Here's what fills the gap.

Read More
AD Attacks
Aug 20, 2024 Vid Grosek

Why MFA Fails Inside the Network: AD Authentication Gaps Attackers Exploit

100% MFA coverage on the dashboard, zero MFA prompts during my internal pentest. Pass-the-Hash and Kerberoasting bypass it entirely — here's why.

Read More
AD Attacks
Aug 15, 2024 Vid Grosek

The Active Directory Kill Chain: How Attackers Move from Foothold to Domain Admin

Reconnaissance to DCSync follows a predictable path. I walk through each stage of the AD kill chain and exactly which controls would have stopped me.

Read More
AD Attacks
Aug 10, 2024 Vid Grosek

LAPS, gMSAs, and Tiered Administration: The Three Pillars of AD Defense

Most orgs implement LAPS or gMSAs partially and miss critical ACL details. Here's how to deploy all three AD hardening pillars the right way.

Read More
AD Attacks
Aug 05, 2024 Vid Grosek

Kerberos Abuse: The Attacks Your Kerberos Infrastructure Enables

Kerberoasting, unconstrained delegation, and Golden Ticket attacks exploit how your Kerberos infrastructure is configured — not flaws in the protocol itself.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch