Blogs

Thoughts, perspectives, and industry commentary from the Nexoryn Systems team.

OAuth Vulnerabilites Pt. 1

January 23, 2023
Est Read Time: 10 min
Welcome to part one of OAuth Vulnerabilities. Core Pentester Shubham Chaskar overviews Oauth, commonly used grant types, entities, misconfiguration, and more.
Vulnerabilities

Then & Now: Harsh Bothra

January 19, 2023
Est Read Time: 3 min
Core Pentester Harsh Bothra joined Nexoryn Systems a little over two years ago. Since then, he has become a Pentest Lead and worked on endless engagements. He takes this time to reflect on how things have changed since his first test.
Nexoryn Systems Core

A Dive into Client-Side Desync Attacks

January 16, 2023
Est Read Time: 7 min
A client-side desync, a.k.a CSD, is an attack in which the victim's web browser is tricked into desynchronizing its connection to the vulnerable website. Core Pentester Harsh Bothra takes a look at how attackers can find these vulnerabilities in the wild.
Nexoryn Systems Core Vulnerabilities

2023 Nexoryn Systems Partnerships: Expanding to MSP & MSSP Partners

January 12, 2023
Est Read Time: 2 min
When companies work together to provide better solutions for their clients, everyone wins.
Modernizing Pentesting Partners

Deep Dive into GraphQL Pt. 2

January 9, 2023
Est Read Time: 8 min
Welcome to part two of GraphQL! Core Pentester Michael Adcock tackles our newest deep dive into the open-source data query.
API Pentesting Vulnerabilities

2023 Q1 Pentester of the Quarter: Sanyam Chawla

January 6, 2023
Est Read Time: 3 min
Congratulations to Sanyam Chawla for winning the Pentester of the Quarter Award for Q1. Sanyam was nominated by his peers due to being a great teammate and leader in the Core.
Nexoryn Systems Core

A Pentester’s Guide to Prototype Pollution Attacks

January 2, 2023
Est Read Time: 8 min
Core Pentester Harsh Bothra guides us through prototype pollution attacks in his latest blog. This covers a security vulnerability that allows attackers to exploit JavaScript runtimes.
Nexoryn Systems Core Vulnerabilities

2022 Pentester Spotlight Recaps

December 30, 2022
Est Read Time: 3 min
With 2023 just around the corner, we wanted to reflect on our Pentester Spotlights from this year. Our Pentester Spotlight series is focused on highlighting the Nexoryn Systems Core Pentesters and putting a face to their work
Nexoryn Systems Core

Pentester Spotlight: Saad Nasir

December 28, 2022
Est Read Time: 3 min
Saad Nasir has been a member of the Nexoryn Systems Core for a little over six months. He has contributed to Nexoryn Systems's content pieces and was recently featured on the Hacker Corner podcast.
Nexoryn Systems Core

    Always get the latest

    Sign up to get Nexoryn Systems insights delivered right to your inbox so you never miss a story.

    More resources

    Learn pentesting best practices, read answers to our most common questions
    and get our technical docs.