Security Insights

Application Security

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Identity and Access Management: Why Deprovisioning Is Where Programs Actually Fail

API Discovery: Why You Probably Have More APIs Than You Think

Identity and access management programs get evaluated heavily on how well provisioning works — how quickly and correctly a new employee gets access to what they need — while deprovisioning, the reverse process of removing access when it’s no longer needed, receives disproportionately less attention despite being where most real IAM program failures actually originate. … Read more

Secrets Sprawl: Why Your Codebase Has More Credentials Than You Think

API Discovery: Why You Probably Have More APIs Than You Think

Every codebase accumulates more credentials than anyone tracking access controls believes it has, and the gap between “credentials we know about” and “credentials that actually exist and work” is what security teams call secrets sprawl — a problem that grows quietly with every API integration, every CI pipeline, and every developer who hardcodes a token … Read more

API Discovery: Why You Probably Have More APIs Than You Think

API Discovery: Why You Probably Have More APIs Than You Think

Organizations that run formal API discovery exercises consistently find considerably more live APIs than their official documented inventory suggested. It is a well-documented pattern, and it reveals security blind spots that most organizations do not realize they have until they look carefully. Why Official API Inventories Undercount Actual Live APIs Organizations accumulate undocumented APIs through … Read more

CSRF Attacks Explained: Why They Still Work in 2026

CSRF Attacks Explained: Why They Still Work in 2026

Cross-site request forgery, commonly abbreviated CSRF, remains a persistent web application vulnerability, despite being a well-documented, long-understood attack technique. Understanding why CSRF continues succeeding against real applications helps explain why this vulnerability class still deserves serious security attention in 2026. How CSRF Attacks Work CSRF attacks exploit the fact that browsers automatically include a user’s … Read more

Business Logic Vulnerabilities: The Flaws Scanners Cannot Find

OWASP Top 10 Explained for Non-Security Teams

Business logic vulnerabilities – flaws in an application’s actual intended workflow and rules, rather than in its underlying technical implementation – represent a significant application security blind spot, since automated vulnerability scanners are honestly fundamentally poorly suited to detecting this distinct vulnerability category. What Distinguishes Business Logic Vulnerabilities From Technical Vulnerabilities Technical vulnerabilities involve flaws … Read more

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure direct object references, commonly abbreviated IDOR, represent a common but often overlooked application security vulnerability class, where an application exposes internal object references – database IDs, file paths – without adequately verifying that the actual requesting user has authorization to access that specific referenced object. How IDOR Vulnerabilities Work IDOR vulnerabilities occur when an … Read more

Security Awareness Training That Employees Do Not Tune Out

Security Awareness Training That Employees Do Not Tune Out

Security awareness training has a reputation problem – many employees experience it as a boring, easily forgotten annual obligation rather than useful, actionable guidance, undermining the very real security value effective awareness training could otherwise provide across an organization. Why Traditional Awareness Training Fails to Land Annual, lengthy, generic security awareness training sessions struggle to … Read more

Understanding SSRF Vulnerabilities in Modern Applications

CSRF Attacks Explained: Why They Still Work in 2026

Server-side request forgery vulnerabilities have become more significant as applications increasingly integrate with cloud services and internal microservices, creating opportunity for attackers to exploit a server’s own network position rather than attacking through a more traditional, direct external path. What SSRF Allows an Attacker to Do SSRF vulnerabilities occur when an application accepts an user-influenced … Read more

Building an Effective Bug Bounty Program

API Discovery: Why You Probably Have More APIs Than You Think

Bug bounty programs offer organizations access to a considerably broader pool of security researchers than any internal security team alone could realistically provide, but building an effective program requires more careful, deliberate thought than simply offering a reward and waiting for reports to start arriving. Why Bug Bounty Programs Complement Internal Security Testing Internal security … Read more

Supply Chain Attacks: Securing Your Software Dependencies

OWASP Top 10 Explained for Non-Security Teams

Software supply chain attacks – where attackers compromise a widely-used dependency to indirectly reach a much larger number of downstream targets – have grown into one of the more significant security concerns in recent years, and understanding the real risk helps organizations build appropriately proportionate, effective defenses against this specific, growing threat category. Why Supply … Read more