Daniel Barnes shares stories from his pentesting career and gives advice for up-and-coming offensive security professionals.
Resources
Blog
Blog
Keep up to date with the latest offensive security news, knowledge, and resources.
Featured
Unauthenticated SQL injection in mJobTime (CVE-2026-9209) exposes construction and field services data. No vendor fix exists after 120-day disclosure.
Learn what HHS OCR investigators look for after a HIPAA breach and how continuous penetration testing builds the audit trail that proves your security programs works.
Decompiling a retired .NET application reveals how a single middleware misconfiguration leads to full authentication bypass.
Healthcare ransomware exploits the gap between tests. See how continuous penetration testing reduces exposure, speeds remediation, and protects patient care.
Learn what DORA’s TLPT assessment requires, why most organizations fail on preparation (not vulnerabilities), and how to build a TLPT-ready security program.
Why traditional API pentests miss real commerce risk and how cart tokens, checkout flows, and cross-layer auth gaps expose customer data.