Practitioner-focused security research

Helping You Build, Break, and Secure Applications Smarter

CyberSecFix publishes technical, reproducible security content covering application and API security, cloud, AI, and vulnerability research, written for people who build and break systems.

Vulnerability ResearchCritical9.1

Authentication bypass via inconsistent path normalization

A walkthrough of how mismatched path handling between a proxy and an application can bypass authentication controls, and how to prevent it.

MMohtasham9 min read

Editor's selection

Featured research

View all

Fresh from the lab

Latest articles

Deep dives

Vulnerability research

View all

Offensive security

Penetration testing

View all

Build secure

Application security

View all
Application Security

IDOR vs BOLA: are they the same thing?

IDOR and BOLA describe closely related authorization failures. This piece clarifies the terminology and when each label is the more precise one.

Interfaces & data

API security

View all

Infrastructure

Cloud security

View all

Emerging

AI security

View all

Tooling

Security tools

View all
Security Tools

Building a lightweight API testing toolkit

You do not need a heavy platform to test APIs effectively. The small set of composable tools that cover most day-to-day API testing.

The researcher

MMohtasham

Security Researcher

Primary author at CyberSecFix, focused on application security, API security, and vulnerability research.

19 articles published