# SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management > Time & again securing you SecureLayer7 is an offensive security company. This blog publishes original security research, vulnerability advisories, penetration-testing guides, and CVE analyses. ## Recent articles - [Insecure Deserialization: Security Risks And Best Practices For Prevention ](https://blog.securelayer7.net/insecure-deserialization/): Modern applications rely on the continuous exchange of data between servers, APIs, and other systems through a process of serialization - [CVE-2026-55255: IDOR in Langflow’s Flow Execution API Enables Cross-User Workflow Hijacking and Credential Theft](https://blog.securelayer7.net/cve-2026-55255-langflow-idor/): Langflow is the dominant no-code, low-code visual builder for LangChain-based AI agents and workflows. With north of twenty-five thousand GitHub - [A Guide to OWASP Top 10 Proactive Controls](https://blog.securelayer7.net/owasp-top-10-proactive-controls/): OWASP Proactive Controls are a set of checklists for developers to help them prevent vulnerabilities that might be created in - [REMOTE-003 Path Traversal in Configuration Subsystem of Apache Dubbo 3.3.x](https://blog.securelayer7.net/apache-dubbo-remote-003-path-traversal/): Responsible Disclosure This vulnerability was identified by SecureLayer7 as part of our security research and was reported to the affected - [AI Security: A Complete Guide to Securing Enterprise AI Systems](https://blog.securelayer7.net/ai-security/): AI is rapidly becoming a core part of modern business, but it also introduces new security risks that traditional application - [CVE-2026-16723: The Class-Loader-as-Primitive Bug Pattern Returns — Fastison 1.x Pre-Auth RCE via @JSONType + jar:http](https://blog.securelayer7.net/cve-2026-16723-fastjson-1x-rce-analysis/): Fastjson is Alibaba's high-performance Java JSON library, and it is quietly one of the most consequential pieces of infrastructure in - [OWASP Web Security Testing Guide (WSTG) Explained](https://blog.securelayer7.net/owasp-web-security-testing-guide-wstg/): Automated vulnerability scanners love to report that an application is perfectly secure. Yet, every day, applications with "clean" scan reports - [Server-Side Template Injection: Attacks & Prevention](https://blog.securelayer7.net/server-side-template-injection/): Server-Side Template Injection (SSTI) is a critical web vulnerability that occurs when user input is embedded into server-side templates without - [Life at SecureLayer7: An Honest Review From the AI Team](https://blog.securelayer7.net/life-at-securelayer7-rohit-hatagale/): If you are reading reviews about working at SecureLayer7 before an interview or an offer, this one is written for - [Remote File Inclusion Explained: Attacks and Prevention ](https://blog.securelayer7.net/remote-file-inclusion/): Remote File Inclusion (RFI) is a critical web application vulnerability that allows attackers to execute malicious code by forcing an - [Penetration Testing Report: Key Sections And How to Use](https://blog.securelayer7.net/penetration-testing-report/): A penetration testing report shows the outcome of the pentesting exercise including key findings, testing scope, what methodologies were used, - [Penetration Testing Execution Standard (PTES): A Complete Guide](https://blog.securelayer7.net/penetration-testing-execution-standard/): The Penetration Testing Execution Standard (PTES) is a widely recognized framework that defines a structured, consistent, and realistic approach to - [Inside the HuggingFace AI Agent Intrusion (Part 2)](https://blog.securelayer7.net/huggingface-ai-agent-intrusion-technical-anatomy/): HuggingFace has published its official technical timeline of the July 2026 agent intrusion, and it is far more detailed than - [Runtime Application Self-Protection (RASP) Explained](https://blog.securelayer7.net/runtime-application-self-protection-rasp/): Runtime Application Self-Protection (RASP) is a vital security technology designed to protect modern applications in real-time. Unlike traditional tools like - [How OpenAI’s AI Agent Broke Into Hugging Face](https://blog.securelayer7.net/openai-hugging-face-exploitgym-incident-analysis/): What actually happened On July 21, 2026, OpenAI publicly disclosed that a routine internal capability evaluation had turned into a - [AI-Assisted Penetration Testing: Guide & Tools](https://blog.securelayer7.net/ai-assisted-penetration-testing/): As cyber threats grow increasingly sophisticated, traditional penetration testing alone is no longer enough to secure complex IT environments. AI-assisted - [Life at SecureLayer7: Notes From the 2026 Employee of the Year](https://blog.securelayer7.net/life-at-securelayer7-pranav-khune/): Once a year, all of us at SecureLayer7 step away from the terminals, the client calls, and the report deadlines, - [Januscape: A 16-Year-Old Field-Comparison Bug in the Linux KVM Shadow MMU](https://blog.securelayer7.net/januscape-linux-kvm-vulnerability/): The Linux KVM subsystem is the hypervisor behind most of the world’s non-hyperscaler public cloud and virtually every private-cloud, VPS, - [Container Vulnerability Scanning: A Practical Guide](https://blog.securelayer7.net/container-vulnerability-scanning/): Container vulnerability scanning delivers security value to DevOps, SecOps, SREs, and platform teams. In practice, that means images are scanned - [Black Hat USA 2026 Parties & Events: The Complete Guide (with DEF CON 34)](https://blog.securelayer7.net/black-hat-usa-2026-parties-events-guide/): Looking for the best Black Hat USA 2026 parties and events? You are in the right place. Every August, Mandalay - [CVE-2026-63030 & CVE-2026-60137: wp2shell Pre-Auth RCE in WordPress Core via REST Batch-Route Confusion and SQL Injection](https://blog.securelayer7.net/cve-2026-63030-cve-2026-60137-wp2shell-pre-auth-rce-in-wordpress-core-via-rest-batch-route-confusion-and-sql-injection/): CVE-2026-63030 & CVE-2026-60137: wp2shell: Pre-Authentication RCE in WordPress Core via REST Batch-Route Confusion and SQL Injection A pre-authentication RCE in - [Network Vulnerability Assessment: Securing Cloud Network](https://blog.securelayer7.net/network-vulnerability-assessment/): Networks form the foundation of your business. Everything and everyone connected to your business goes through this same network. Your - [CVE-2026-8037: Progress Kemp LoadMaster – Pre-Auth Root RCE](https://blog.securelayer7.net/cve-2026-8037-progress-loadmaster-rce/): CVE-2026-8037: Progress Kemp LoadMaster — Pre-Auth Root RCE via Uninitialized Heap and Missing Null Terminator Progress Kemp LoadMaster is a - [The Vulnerability Management Lifecycle: A Complete Guide](https://blog.securelayer7.net/vulnerability-management-lifecycle/): The Vulnerability Management Lifecycle is a comprehensive, structured approach to identifying, assessing, and addressing security vulnerabilities within an organization’s IT - [Application Penetration Testing: Complete Guide](https://blog.securelayer7.net/application-penetration-testing/): Application penetration testing is a controlled offensive security assessment that determines whether weaknesses in an application can be exploited under - [Continuous Threat Exposure Management (CTEM) Explained](https://blog.securelayer7.net/continuous-threat-exposure-management-ctem/): Organisations today monitor thousands of vulnerabilities across cloud systems, SaaS apps, endpoints, APIs, and third-party software. The challenge is deciding - [Cisco Unified CM Pre-Auth RCE — When the Phone System Becomes the Attacker’s Foothold](https://blog.securelayer7.net/cve-2026-20230-cisco-unified-cm-rce/): CVE-2026-20230 CVSS v3.1 8.6 (Cisco Critical) Pre-Auth CISA KEV (added 2026-06-25, active exploitation since 2026-06-21) Cisco Unified Communications Manager — - [External Attack Surface Management (EASM): A Practical Guide](https://blog.securelayer7.net/external-attack-surface-management-easm/): Your attack surface is whatever the internet can find. That’s a reality. To manage that risk effectively, organizations need continuous - [Prompt Injection Attacks: Risks, Examples & Prevention](https://blog.securelayer7.net/prompt-injection-attacks/): The rise of AI and Large Language Models (LLMs) has transformed modern applications, but it has also introduced new security - [CVE-2026-44963: Veeam Backup – Authenticated Domain User to RCE via BinaryFormatter Blacklist Bypass](https://blog.securelayer7.net/cve-2026-44963-veeam-backup-authenticated-rce-binaryformatter-bypass/): Veeam Backup & Replication is the dominant enterprise backup and disaster-recovery platform for virtualized, physical, and cloud workloads. A vulnerability - [Cloud Security Posture Management: How CSPM Protects Your Cloud](https://blog.securelayer7.net/cloud-security-posture-management/): Misconfigured cloud resources, excessive permissions, unsecured storage buckets, and compliance gaps remain some of the leading causes of cloud security - [Data Security Posture Management (DSPM) Explained](https://blog.securelayer7.net/data-security-posture-management/): Data security posture management (DSPM) helps organizations find and assess the exposure of sensitive data across cloud environments. DSPM provides - [CVE-2026-20253: Splunk Enterprise Pre-Auth RCE Analysis](https://blog.securelayer7.net/cve-2026-20253-splunk-enterprise-pre-auth-rce/): Splunk is the dominant commercial platform for log ingestion, search, and security analytics — most enterprise SOCs operate at least - [LiteLLM RCE Chain: Three CVEs Enable AI Supply Chain Attack](https://blog.securelayer7.net/litellm-three-cve-rce-ai-supply-chain-attack/): LiteLLM is one of the most widely deployed open-source proxies for Large Language Model traffic. It sits in front of - [CVE-2026-25874: Hugging Face LeRobot – Unauthenticated Pickle RCE in the AsyncInference PolicyServer](https://blog.securelayer7.net/cve-2026-25874-lerobot-pickle-deserialization-rce/): LeRobot is Hugging Face’s open-source robotics framework — the same project that ships Stable-Baselines-style RL primitives, real-robot data loaders, and - [CVE-2026-42779: Apache MINA-Deserialization Allowlist Bypass to RCE](https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce/): Apache MINA is the network-I/O framework that backs a long list of well-known Apache subprojects — ActiveMQ Artemis, Vysper, FtpServer, - [Top 10 AI Pentesting Companies in 2026: An Expert Overview](https://blog.securelayer7.net/ai-pentesting-companies/): The rapid growth of cloud environments, APIs, and GenAI applications has created attack surfaces that traditional security testing methods struggle - [CVE-2026-7304: SGLang-Unauthenticated RCE via dill.loads](https://blog.securelayer7.net/cve-2026-7304-sglang-unauthenticated-rce/): LLM inference servers are the new high-value target. They run with GPU access, hold proprietary model weights in memory, and - [CVE-2025-27817: Apache Kafka Connect Arbitrary File Read](https://blog.securelayer7.net/cve-2025-27817-apache-kafka-connect-arbitrary-file-read/): Apache Kafka Connect, the integration framework used by thousands of organisations to stream data between systems, harbours a vulnerability that - [Introducing PromptPurify: An Open-Source Prompt-Injection Firewall](https://blog.securelayer7.net/promptpurify-an-prompt-injection-firewall/): Attackers commonly use prompt injection to target AI applications. To address this challenge, SecureLayer7 has released Promptpurify, which is an - [OWASP ASVS: A Framework for Building Secure Applications](https://blog.securelayer7.net/owasp-asvs/): How can you determine if an application is secure? Most organizations don’t have a clear answer. Some depend on annual - [CVE-2025-61622: PyFory – Insecure Pickle Deserialization to Remote Code Execution](https://blog.securelayer7.net/cve-2025-61622-pyfory-deserialization-rce-exploit/): Python’s pickle module has long been recognized as one of the most dangerous serialization interfaces in the language, its own - [CVE-2025-48459: Apache IoTDB – Unsafe Deserialization via Class.forName() to RCE](https://blog.securelayer7.net/cve-2025-48459-apache-iotdb-unsafe-deserialization/): A single TCP packet. No credentials. No handshake. That is all it takes (in principle) to achieve root-level remote code - [CVE-2024-52577 Apache Ignite RCE via Deserialization Exploit](https://blog.securelayer7.net/cve-2024-52577-apache-ignite-rce-deserialization/): Enterprise distributed computing platforms are high-value targets. When a framework trusted to manage terabytes of in-memory data across hundreds of - [SaaS Penetration Testing: Complete Guide for 2026 ](https://blog.securelayer7.net/saas-penetration-testing/): Software-as-a-Service (SaaS) applications continue to dominate the digital landscape, securing them has become more critical than ever. SaaS platforms host - [AI Red Teaming: How It Works, Examples, And Best Practices](https://blog.securelayer7.net/ai-red-teaming/): We’ve integrated models like GPT and Claude into our critical business infrastructure without fully understanding how secure they are. Since - [CVE-2025-54539: Apache ActiveMQ NMS AMQP Deserialization Policy Bypass to RCE](https://blog.securelayer7.net/cve-2025-54539-apache-nms-amqp-rce/): A deserialization filter is only as good as its checks. CVE-2025-54539 is a logic bug in Apache.NMS.AMQP's NmsDefaultDeserializationPolicy where the - [Manual vs Autonomous Penetration Testing: Key Differences ](https://blog.securelayer7.net/manual-vs-autonomous-penetration-testing/): Penetration testing is a critical component of modern cybersecurity, helping organizations identify and address vulnerabilities before attackers can exploit them. - [Electron app security risks – Part 2: Real-world RCE chains in Discord and Element](https://blog.securelayer7.net/electron-app-security-risks-part-2/): Part 1 covered the basics: main process vs renderer, what nodeIntegration, contextIsolation, and sandbox actually do, and how a misconfigured - [Smart Contract Security: Risks, Audits, and Best Practices](https://blog.securelayer7.net/smart-contract-security-risks/): Smart contracts have become a core building block of modern blockchain ecosystems, powering decentralized applications, DeFi platforms, and digital asset ## Categories - [Vulnerability Research](https://blog.securelayer7.net/category/vulnerability-research/) - [Knowledge-base](https://blog.securelayer7.net/category/knowledge-base/) - [Web Application Security](https://blog.securelayer7.net/category/penetration-testing/web-application-security/) - [Penetration Testing](https://blog.securelayer7.net/category/penetration-testing/) - [Mobile & IoT Security](https://blog.securelayer7.net/category/mobile-iot-security/) - [Offensive security](https://blog.securelayer7.net/category/offensive-security/) - [News](https://blog.securelayer7.net/category/securelayer7-news/) - [API Security](https://blog.securelayer7.net/category/api-security/) - [Cloud Security](https://blog.securelayer7.net/category/cloud-security/) - [Compliance](https://blog.securelayer7.net/category/compliance/) - [Life at SecureLayer7](https://blog.securelayer7.net/category/life-at-securelayer7/) - [AI Pentesting](https://blog.securelayer7.net/category/ai-pentesting/) - [Network Security](https://blog.securelayer7.net/category/network-security/) - [Vulnerability Assessment](https://blog.securelayer7.net/category/vulnerability-assessment/)