Sprocket Security | Cybersecurity Blog
Resources Blog

Blog

Keep up to date with the latest offensive security news, knowledge, and resources.
Ahead of the Breach – Accenture's Daniel Barnes on SAML exploitation and what really matters in pentesting

Ahead of the Breach – Accenture's Daniel Barnes on SAML exploitation and what really matters in pentesting

Daniel Barnes shares stories from his pentesting career and gives advice for up-and-coming offensive security professionals.
What OCR Investigators Look for After a Breach

What OCR Investigators Look for After a Breach

Learn what HHS OCR investigators look for after a HIPAA breach and how continuous penetration testing builds the audit trail that proves your security programs works.
Vulnerability Hunting a Retired App Part 1 - Auth Bypass

Vulnerability Hunting a Retired App Part 1 - Auth Bypass

Decompiling a retired .NET application reveals how a single middleware misconfiguration leads to full authentication bypass.
How Continuous Testing Reduces Ransomware Risk in Healthcare

How Continuous Testing Reduces Ransomware Risk in Healthcare

Healthcare ransomware exploits the gap between tests. See how continuous penetration testing reduces exposure, speeds remediation, and protects patient care.
What a DORA TLPT Assessment Actually Requires

What a DORA TLPT Assessment Actually Requires

Learn what DORA’s TLPT assessment requires, why most organizations fail on preparation (not vulnerabilities), and how to build a TLPT-ready security program.
Putting the Token Before the Cart? A Guide on E-Commerce API Pentesting

Putting the Token Before the Cart? A Guide on E-Commerce API Pentesting

Why traditional API pentests miss real commerce risk and how cart tokens, checkout flows, and cross-layer auth gaps expose customer data.
4 5 6 7 8