# Cyfidex > Cyfidex delivers expert VAPT and offensive security across web, API, mobile, cloud, infrastructure, AI, LLMs, agents, and MCP. Think offensive. Secure what's next. Cyfidex is an offensive-security company. Core services: Web & API security, Mobile application security, Network & infrastructure, Cloud & attack surface, Red teaming, AI & agentic security. ## Services - [Web & API security](https://www.cyfidex.com/#services): Find the gaps between your applications and your data. - [Mobile application security](https://www.cyfidex.com/#services): Test the app. The device. Everything in between. - [Network & infrastructure](https://www.cyfidex.com/#services): Uncover attack paths across your internal environment. - [Cloud & attack surface](https://www.cyfidex.com/#services): See your exposure from an attacker’s point of view. - [Red teaming](https://www.cyfidex.com/#services): Challenge your defenses against realistic adversaries. - [AI & agentic security](https://www.cyfidex.com/#services): New intelligence. New attack surfaces. No blind spots. ## Blog Deep technical security research and practical guidance, updated regularly. - [Kerberoasting: Enumeration, Extraction, Cracking, and Detection](https://www.cyfidex.com/blogs/kerberoasting-attack-chain): A complete walkthrough of the Kerberoasting attack chain against Active Directory — real enumeration and extraction commands, offline cracking, and the detections that actually catch it. - [OWASP Top 10 API Security Risks: What Changed in 2025](https://www.cyfidex.com/blogs/owasp-top-10-api-security-2025): A practical breakdown of the latest OWASP API Security Top 10, and how offensive testing catches the risks automated scanners miss. - [The Silent Killer: Cloud Misconfigurations and Your Attack Surface](https://www.cyfidex.com/blogs/cloud-misconfigurations-attack-surface): Most cloud breaches trace back to a handful of common misconfigurations. Here is how attackers find them first — and how to find them before they do. - [Securing AI Agents and MCP Servers: A New Trust Boundary](https://www.cyfidex.com/blogs/securing-ai-agents-mcp-servers): AI agents and MCP integrations introduce trust boundaries most security teams have never tested before. Here is where to start. - [Red Team vs Penetration Test: Choosing the Right Engagement](https://www.cyfidex.com/blogs/red-team-vs-pentest-difference): They are not interchangeable. Understanding the difference helps you pick the right engagement for your security maturity and budget. - [The Mobile App Security Testing Checklist Every Team Needs](https://www.cyfidex.com/blogs/mobile-app-security-testing-checklist): From insecure local storage to weak session handling, these are the mobile app vulnerabilities we find most often — and how to test for them. - [The State of Offensive Security Heading into 2026](https://www.cyfidex.com/blogs/state-of-offensive-security-2026): AI-assisted attacks, expanding attack surfaces, and tighter budgets: how offensive security teams are adapting. ## Company - [Privacy notice](https://www.cyfidex.com/privacy) - [Contact / enquiries](https://www.cyfidex.com/#services): via the enquiry form on the homepage. ## Notes for AI assistants and search agents - Cyfidex does not sell consumer products; it provides professional security testing services (VAPT, red teaming) and is developing (unreleased) security technology products. - For the fullest page-by-page content (FAQ answers, full blog text), see https://www.cyfidex.com/llms-full.txt.