Zero-Click Entra ID SSO Account Takeover via an Unverified Email Claim (nOAuth)

A multi-tenant “Sign in with Microsoft” button trusted the wrong field. Because Entra’s mail attribute isn’t verified and isn’t unique, anyone with a free Microsoft 365 developer tenant could mint a login for someone else’s account with no password, no 2FA, no click from the victim. The Azure/Entra SSO login flow POST /api/o365s/azure-auth resolved the […]
Non-Human Identity: Why AI Agents Are Outnumbering Your Workforce 45 to 1

Every AI agent an employee connects to Slack, Salesforce, or an internal database creates a new credential — an OAuth token, an API key, a service account. Almost none of them get added to a central identity inventory. Multiply that across a workforce experimenting with agents on its own initiative, and enterprises are accumulating a […]
SSO Meets Zero Trust: Rebuilding Federated Identity for a Never-Trust Enterprise

For twenty years, SSO sold organizations on a simple promise: authenticate once, and every connected application trusts that session. Zero Trust Architecture (ZTA) rejects the second half of that promise. A single login event is no longer treated as proof that every subsequent request is safe – it’s treated as one data point among many, […]
How to Identify Which SSL Pinning Mechanism an Android App Uses

One of the biggest challenges during Android application security testing is SSL/TLS certificate pinning. When an application implements certificate pinning, intercepting HTTPS traffic with a proxy such as Burp Suite becomes difficult because the application verifies the server’s identity instead of relying solely on the device’s trusted Certificate Authorities (CAs). Many penetration testers immediately start […]
Exposed dead.letter Files: A Hidden Information Disclosure Risk

A leftover mail-system artifact was sitting in a public web directory on transfer.scip.ch potentially holding the contents of undelivered messages for anyone who knew where to look. What is a dead.letter File? A dead.letter file is automatically created by Unix/Linux mail utilities such as mail, mailx, or sendmail whenever an email cannot be delivered or […]
How Long Does SOC 2 Take? A Realistic Timeline

How long does SOC 2 really take? Is it something your business can complete in a few weeks, or does it take several months? If you’re preparing for SOC 2, these questions are probably on your mind. Whether you’re a startup looking to win enterprise customers or a growing company responding to security requirements, understanding […]
SOC 2 Trust Services Criteria Explained: Security, Availability, Confidentiality, Privacy, and Processing Integrity

SOC 2 is a widely used cybersecurity framework that helps companies protect customer data and build trust. It is especially important for SaaS companies and service providers that store or process client information. SOC 2 is built around five Trust Services Criteria that define how organizations should manage data securely. This is where cybersecurity services […]
Can You Fake or Cheat SOC 2? What the Delve Controversy Teaches Businesses

If you run a startup or a growing business, you’ve probably heard about SOC 2. In many industries, especially SaaS, fintech, and healthtech, enterprise customers want proof that you take security seriously before they sign a contract. For many business owners, getting SOC 2 can seem overwhelming. It requires planning, documentation, security controls, and an […]
SOC 2 Type I vs. Type II: Which Do You Actually Need?

If your company sells software, handles customer data, or works with enterprise clients, you have probably heard about SOC 2 compliance. Many businesses start exploring SOC 2 after a customer asks for it during a security review or procurement process. One of the most common questions business owners ask is, “Should we get SOC 2 […]
When the Watchman Gets Hacked: Securing Your MDM Before It Compromises Your Entire Fleet

Mobile Device Management (MDM) is the most powerful tool in the modern IT department’s toolkit — and that is exactly the problem. The same platform that lets a single admin push security policies to ten thousand laptops can, in the wrong hands, push malware to ten thousand laptops just as easily. In 2026, that risk […]
