REPORT
The 25x Remediation Gap: See how elite security teams resolve risks in 10 days vs. 249
REPORT
The 25x Remediation Gap: See how elite security teams resolve risks in 10 days vs. 249

Blogs

Thoughts, perspectives, and industry commentary from the Cobalt team.

Hacking Web Cache - Deep Dive in Web Cache Poisoning Attacks

January 31, 2023
Est Read Time: 9 min
Web cache poisoning is an attack where an attacker takes advantage of flaws in the caching mechanism. They attempt to store an altered and malicious response in the cache entry, forcing the website to serve malicious information to its users.  Core Pentester Harsh Bothra deep dives into these attacks and remediations.
Cobalt Core Web Application Pentesting Vulnerabilities

Cobalt Achieved Record Pentests in 2022, Expanded PtaaS Adoption

January 26, 2023
Est Read Time: 5 min
Notable industry recognition from analysts and high-value awards proves Cobalt is the leader in PtaaS, and sparks the hiring of Chief Sales Officer Jerri Allan
NEWS

Man-In-The-Middle Attacks: How to Detect and Prevent

January 24, 2023
Est Read Time: 5 min
This article covers the steps cybercriminals commonly take to execute different MITM attacks, and how security teams can detect and prevent them.
Cybersecurity Insights

OAuth Vulnerabilites Pt. 1

January 23, 2023
Est Read Time: 10 min
Welcome to part one of OAuth Vulnerabilities. Core Pentester Shubham Chaskar overviews Oauth, commonly used grant types, entities, misconfiguration, and more.
Vulnerabilities

Then & Now: Harsh Bothra

January 19, 2023
Est Read Time: 3 min
Core Pentester Harsh Bothra joined Cobalt a little over two years ago. Since then, he has become a Pentest Lead and worked on endless engagements. He takes this time to reflect on how things have changed since his first test.
Cobalt Core

A Dive into Client-Side Desync Attacks

January 16, 2023
Est Read Time: 7 min
A client-side desync, a.k.a CSD, is an attack in which the victim's web browser is tricked into desynchronizing its connection to the vulnerable website. Core Pentester Harsh Bothra takes a look at how attackers can find these vulnerabilities in the wild.
Cobalt Core Vulnerabilities

2023 Cobalt Partnerships: Expanding to MSP & MSSP Partners

January 12, 2023
Est Read Time: 2 min
When companies work together to provide better solutions for their clients, everyone wins.
Modernizing Pentesting Partners

Deep Dive into GraphQL Pt. 2

January 9, 2023
Est Read Time: 8 min
Welcome to part two of GraphQL! Core Pentester Michael Adcock tackles our newest deep dive into the open-source data query.
API Pentesting Vulnerabilities

2023 Q1 Pentester of the Quarter: Sanyam Chawla

January 6, 2023
Est Read Time: 3 min
Congratulations to Sanyam Chawla for winning the Pentester of the Quarter Award for Q1. Sanyam was nominated by his peers due to being a great teammate and leader in the Core.
Cobalt Core

    Always get the latest

    Sign up to get Cobalt insights delivered right to your inbox so you never miss a story.

    More resources

    Learn pentesting best practices, read answers to our most common questions
    and get our technical docs.