All Articles
78 guides, CVE analyses, and security research articles — page 5 of 7.
-
We Hid 10 Secrets on a Web Server. SecurityClaw Found All 10 in Under 5 Seconds.
We planted 10 sensitive paths on a web server — backup files, Git repo, live API keys, admin panel. SecurityClaw's gobuster integration found all 10 in 4.79 seconds. Here's exactly how.
Read article → -
We Gave Hashcat 6 Password Hashes. It Cracked 5 in Under a Second. The 6th Said No.
We ran Hashcat v7.1.2 against 6 password hashes — MD5, NTLM, SHA-1, SHA-256, SHA-512, and bcrypt. Five cracked in milliseconds. One didn't. The gap between them is 59,034x.
Read article → -
371 Templates. 8 Seconds. AWS Credentials Sitting Wide Open — SecurityClaw's Nuclei Scan in Practice
We built a deliberately misconfigured web app and ran SecurityClaw's nuclei scanner against it. It found AWS keys, .env files, and git config in 8 seconds. Here's the proof.
Read article → -
It Doesn't Just Find Your Leaked Secrets — It Tells You If They Still Work
SecurityClaw ran TruffleHog v3.95.2 against a controlled repo with 5 planted secrets. All 5 detected — including the Stripe key v2 missed. The real story: live verification tells you instantly if a leaked credential is still active.
Read article → -
WPScan vs WP Engine: What Happens When a Scanner Meets Real Hardening
SecurityClaw ran WPScan 3.8.28 against a hardened enterprise WordPress target. The automated scan returned 3 INFO findings. The manual analysis layer returned 7. Here's why that gap isn't a scanner failure — it's a story about what serious WordPress security looks like.
Read article → -
How SecurityClaw Finally Got Past bol.com's WAF — and What It Found
Enterprise WAFs block cloud IPs by default. How SecurityClaw bypassed bol.com's Akamai block with a residential Kali container — and what the scan found.
Read article → -
SecurityClaw Scanned bol.com With 16 AI Skills — Here's What It Found
SecurityClaw ran 16 AI skills against bol.com on EC2 and recovered 2,607 findings. Here's what they mean for bug bounty recon at scale.
Read article → -
SecurityClaw's First Real Bug Bounty Campaign: What We Found on bol.com
SecurityClaw's first EC2 batch campaign against bol.com: 2,607 findings in 5 minutes, a Google demo app on staging, and one lost finding we can't recover.
Read article → -
AI-Driven Pentesting Crossed Into Production: SecurityClaw's Bedrock Planner Works on the First Try
SecurityClaw's AI pentesting pipeline — powered by Claude Sonnet on AWS Bedrock — generated a valid, executable pentest plan on the first attempt. No retry. No human editing. Here's what that means for the future of automated security research.
Read article → -
Firefox SpiderMonkey WebAssembly GC RCE: One Typo, Full Renderer Compromise
A single & vs | typo in Firefox SpiderMonkey''s Wasm GC engine causes a type confusion leading to RCE in the renderer process — affecting 200M+ users via any malicious webpage.
Read article → -
Burp Suite Costs $449/yr Per User. Here's What a 5-Person Team Actually Spends.
Burp Suite Pro is $449/user/yr. Enterprise starts at $3,999/yr. Here's the real total cost for security teams in 2026 — and what Burp doesn't cover.
Read article → -
CVE-2026-2473: GCP Vertex AI Bucket Squatting Enables Cross-Tenant RCE and Model Theft (CVSS 9.8)
Google patched a critical Vertex AI vulnerability where predictable Cloud Storage bucket names allowed unauthenticated attackers to steal AI models, poison training pipelines, and execute code across tenant boundaries.
Read article →