Security Insights

Application Security

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

API Discovery: Why You Probably Have More APIs Than You Think

API Discovery: Why You Probably Have More APIs Than You Think

Organizations that run formal API discovery exercises consistently find considerably more live APIs than their official documented inventory suggested. It is a well-documented pattern, and it reveals security blind spots that most organizations do not realize they have until they look carefully. Why Official API Inventories Undercount Actual Live APIs Organizations accumulate undocumented APIs through … Read more

CSRF Attacks Explained: Why They Still Work in 2026

CSRF Attacks Explained: Why They Still Work in 2026

Cross-site request forgery, commonly abbreviated CSRF, remains a persistent web application vulnerability, despite being a well-documented, long-understood attack technique. Understanding why CSRF continues succeeding against real applications helps explain why this vulnerability class still deserves serious security attention in 2026. How CSRF Attacks Work CSRF attacks exploit the fact that browsers automatically include a user’s … Read more

Business Logic Vulnerabilities: The Flaws Scanners Cannot Find

OWASP Top 10 Explained for Non-Security Teams

Business logic vulnerabilities – flaws in an application’s actual intended workflow and rules, rather than in its underlying technical implementation – represent a significant application security blind spot, since automated vulnerability scanners are honestly fundamentally poorly suited to detecting this distinct vulnerability category. What Distinguishes Business Logic Vulnerabilities From Technical Vulnerabilities Technical vulnerabilities involve flaws … Read more

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure direct object references, commonly abbreviated IDOR, represent a common but often overlooked application security vulnerability class, where an application exposes internal object references – database IDs, file paths – without adequately verifying that the actual requesting user has authorization to access that specific referenced object. How IDOR Vulnerabilities Work IDOR vulnerabilities occur when an … Read more

Understanding SSRF Vulnerabilities in Modern Applications

CSRF Attacks Explained: Why They Still Work in 2026

Server-side request forgery vulnerabilities have become more significant as applications increasingly integrate with cloud services and internal microservices, creating opportunity for attackers to exploit a server’s own network position rather than attacking through a more traditional, direct external path. What SSRF Allows an Attacker to Do SSRF vulnerabilities occur when an application accepts an user-influenced … Read more

Web Application Firewalls: What They Catch and What They Miss

Insecure Direct Object References: A Common but Overlooked Flaw

Web application firewalls provide a valuable layer of defense for web applications, but organizations sometimes deploy them with an overly optimistic understanding of what they protect against, leading to genuine, real gaps in overall security posture when a WAF is treated as a comprehensive solution rather than one specific, valuable layer within a broader defense … Read more

OWASP Top 10 Explained for Non-Security Teams

CSRF Attacks Explained: Why They Still Work in 2026

The OWASP Top 10 gets referenced constantly in security conversations, but for developers and product teams outside dedicated security roles, the list often reads like a wall of jargon – injection, broken access control, cryptographic failures – without much sense of what these categories mean for the code they write every day. Here is a … Read more

API Security: What Most Companies Get Wrong

API Discovery: Why You Probably Have More APIs Than You Think

APIs have quietly become the primary way most modern applications communicate, both internally between services and externally with partners and customers. That shift has made API security a critical concern, yet a surprising number of organizations still treat API security as an afterthought relative to the more traditional web application security practices they have had … Read more

Why a Correctly Configured Security Header Can Still Silently Stop Working

API Discovery: Why You Probably Have More APIs Than You Think

A security review of a genuinely well-maintained web application finds that its Content Security Policy header, present and correctly configured for years, has actually been silently non-functional for the past several months – a routine infrastructure change quietly stripped the header before it ever reached real browsers, and nobody noticed, because nobody had actually been … Read more