The Cyfidex Blog
Offensive security thinking, shared openly.
Research, field notes, and practical guidance from our offensive security team — covering web, cloud, mobile, AI, and the attack surfaces still taking shape.
7 articles
Kerberoasting: Enumeration, Extraction, Cracking, and Detection
A complete walkthrough of the Kerberoasting attack chain against Active Directory — real enumeration and extraction commands, offline cracking, and the detections that actually catch it.
The State of Offensive Security Heading into 2026
AI-assisted attacks, expanding attack surfaces, and tighter budgets: how offensive security teams are adapting.
Securing AI Agents and MCP Servers: A New Trust Boundary
AI agents and MCP integrations introduce trust boundaries most security teams have never tested before. Here is where to start.
OWASP Top 10 API Security Risks: What Changed in 2025
A practical breakdown of the latest OWASP API Security Top 10, and how offensive testing catches the risks automated scanners miss.
The Silent Killer: Cloud Misconfigurations and Your Attack Surface
Most cloud breaches trace back to a handful of common misconfigurations. Here is how attackers find them first — and how to find them before they do.
Red Team vs Penetration Test: Choosing the Right Engagement
They are not interchangeable. Understanding the difference helps you pick the right engagement for your security maturity and budget.
The Mobile App Security Testing Checklist Every Team Needs
From insecure local storage to weak session handling, these are the mobile app vulnerabilities we find most often — and how to test for them.