Security InsightsApplication Security
Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.
Organizations that run formal API discovery exercises consistently find considerably more live APIs than their official documented inventory suggested. It is a well-documented pattern, and it reveals security blind spots that most organizations do not realize they have until they look carefully. Why Official API Inventories Undercount Actual Live APIs Organizations accumulate undocumented APIs through … Read more
Cross-site request forgery, commonly abbreviated CSRF, remains a persistent web application vulnerability, despite being a well-documented, long-understood attack technique. Understanding why CSRF continues succeeding against real applications helps explain why this vulnerability class still deserves serious security attention in 2026. How CSRF Attacks Work CSRF attacks exploit the fact that browsers automatically include a user’s … Read more
Business logic vulnerabilities – flaws in an application’s actual intended workflow and rules, rather than in its underlying technical implementation – represent a significant application security blind spot, since automated vulnerability scanners are honestly fundamentally poorly suited to detecting this distinct vulnerability category. What Distinguishes Business Logic Vulnerabilities From Technical Vulnerabilities Technical vulnerabilities involve flaws … Read more
Insecure direct object references, commonly abbreviated IDOR, represent a common but often overlooked application security vulnerability class, where an application exposes internal object references – database IDs, file paths – without adequately verifying that the actual requesting user has authorization to access that specific referenced object. How IDOR Vulnerabilities Work IDOR vulnerabilities occur when an … Read more
Server-side request forgery vulnerabilities have become more significant as applications increasingly integrate with cloud services and internal microservices, creating opportunity for attackers to exploit a server’s own network position rather than attacking through a more traditional, direct external path. What SSRF Allows an Attacker to Do SSRF vulnerabilities occur when an application accepts an user-influenced … Read more
Web application firewalls provide a valuable layer of defense for web applications, but organizations sometimes deploy them with an overly optimistic understanding of what they protect against, leading to genuine, real gaps in overall security posture when a WAF is treated as a comprehensive solution rather than one specific, valuable layer within a broader defense … Read more
The OWASP Top 10 gets referenced constantly in security conversations, but for developers and product teams outside dedicated security roles, the list often reads like a wall of jargon – injection, broken access control, cryptographic failures – without much sense of what these categories mean for the code they write every day. Here is a … Read more
APIs have quietly become the primary way most modern applications communicate, both internally between services and externally with partners and customers. That shift has made API security a critical concern, yet a surprising number of organizations still treat API security as an afterthought relative to the more traditional web application security practices they have had … Read more
A security review of a genuinely well-maintained web application finds that its Content Security Policy header, present and correctly configured for years, has actually been silently non-functional for the past several months – a routine infrastructure change quietly stripped the header before it ever reached real browsers, and nobody noticed, because nobody had actually been … Read more