Security research

Manual SaaS and API security research

Findings and methods from real testing. Access control, APIs, GraphQL, authentication, business logic and AI application security, written so an engineer can act on them.

18 articles8 topicsUpdated 7 October 2026

18 articles

The three parts of a JSON Web Token with the header highlightedPractitioner
Latest
Authentication13 min read

How to Tell If a JWT Is Actually Secure

Most developers meet JSON Web Tokens the same way. A library hands you a token, you store it, you send it back on every request, and the framework tells you whether the user is logged in. It works, so nobody looks inside. I look inside for a living, and tokens are one of the places…

All articles

The three parts of a JSON Web Token with the header highlightedPractitioner
Authentication13 min read

How to Tell If a JWT Is Actually Secure

Most developers meet JSON Web Tokens the same way. A library hands you a token, you store it, you send it back on every request, and the framework tells you whether the user is logged in. It works, so nobody looks inside. I look inside for a living, and tokens are one of the places…

Key takeawayA token is encoded, not encrypted. Anyone holding it can read every claim inside it without any key at all.
A probe reaching one node from outside an application boundary while a green path traces the internal structure to the underlying cause.Practitioner
Pentesting Guides12 min read

Source Code Review vs Penetration Testing: Which One Your SaaS Application Actually Needs

Most teams ask this question with a budget in front of them and room for one. The honest answer is that a source code review and a penetration test answer different questions, and the right choice depends entirely on which question is currently costing you. A penetration test tells you what an attacker can do…

Key takeawayOne proves what an attacker can do to the running system. The other explains why it is possible and where else the same mistake lives.
Many faint scanner leads narrowing down to a single confirmed finding highlighted in green.Practitioner
Pentesting Guides13 min read

What Is a Vulnerability Assessment? Scope, Process and What the Output Should Tell You

A vulnerability assessment is a structured review of an application, its APIs and its exposed infrastructure that identifies security weaknesses, confirms which of them are real, and rates each one by the risk it presents to the business. It answers a narrow question well: what is currently wrong, where, and how serious is it. That…

Key takeawayWhat the scope should cover, what manual validation adds that a scanner cannot, and how to judge the report you get back.
Five stacked standards documents with the front one highlighted in green, representing PTES, OWASP and NIST in a single engagement.Practitioner
Pentesting Guides7 min read

Penetration Testing Methodologies and Standards: What PTES, OWASP and NIST Actually Cover

A standard tells you what to test. It does not tell you where your product breaks. This is what PTES, OWASP WSTG, the OWASP API Security Top 10, OWASP ASVS and NIST SP 800-115 actually cover, which parts matter when the target is a SaaS application or an API, and which parts exist mainly so…

Key takeawayWhich parts of PTES, WSTG, ASVS and NIST earn their place in a real engagement, and which exist so a report can cite something.
A central AI agent node connected to surrounding tools, with one connection reaching beyond its boundary.Deep dive
AI Security11 min read

AI Agents Are Becoming a New Attack Surface: What SaaS Companies Need to Secure Before Giving Them Access

For years, application security teams have asked a familiar question: What can this user access? That question still matters. But as AI agents become integrated into SaaS platforms, companies increasingly need to ask another one: What can this AI agent access, and what can it do with that access? That distinction is becoming important. AI…

Key takeawayAn agent with tools is a user with credentials, so the dangerous combination is access plus autonomy rather than the model itself.
A four step process chain with a green arc bypassing the middle steps, representing a valid request that skips the rule.Practitioner
Business Logic5 min read

Business Logic Vulnerabilities: The Security Risk Automated Scanners Miss

Modern SaaS applications are built around business processes rather than simple web pages. Users create projects, invite teammates, purchase subscriptions, approve invoices, generate reports, and collaborate across organizations. Every one of these actions follows a set of business rules that determine what should and should not happen. Most security discussions focus on familiar vulnerabilities like…

Key takeawayScanners cannot find these because nothing is malformed. The request is valid and the rule behind it is wrong.
A grid of locked permission cells with one unlocked in green, representing an authorization check that should not have passed.Deep dive
Access Control12 min read

Authorization Testing in Modern SaaS Applications: A Complete Guide

Learn how modern SaaS teams evaluate authorization, role boundaries, tenant isolation, object ownership, and business logic to identify security weaknesses before they become production incidents. Modern SaaS applications are designed to handle some of an organization’s most valuable assets. Customer records, invoices, source code, financial information, healthcare data, internal documentation, AI workflows, and administrative controls…

Key takeawayHow to test role boundaries, tenant isolation and object ownership as separate problems instead of one permissions check.
A stack of locked records with one opened in green and an arrow pointing from the record above it.Fundamentals
Access Control8 min read

IDOR Vulnerabilities Explained: How Attackers Access Other Users’ Data

Understanding one of the most common and dangerous security flaws affecting modern SaaS applications. Modern SaaS applications are built around one simple idea: users should only be able to access the data and functionality they are authorized to use. Customers trust these platforms with invoices, customer records, financial information, source code, medical records, and countless…

Key takeawayWhy a 200 response to someone else's object ID is the most common serious flaw in SaaS, and how it gets found.
A wall of bricks with one missing and a green path running through the gap.Practitioner
Access Control8 min read

Broken Access Control: The Security Flaw Behind Some of the Most Serious SaaS Breaches

Most organizations spend a significant amount of time thinking about authentication. They implement strong password policies, enable multi-factor authentication, and invest in secure login systems. These are important controls and should never be ignored. However, many of the most damaging security incidents do not happen because an attacker bypasses authentication. They happen because the attacker…

Key takeawayStrong authentication tells you who someone is. It says nothing about what they should reach once they are inside.
A single query node branching into many fields, with one branch highlighted in green.Practitioner
API Security8 min read

Common GraphQL Security Risks in SaaS Applications

GraphQL has become one of the most popular technologies for building modern APIs. Many SaaS companies adopt GraphQL because it gives developers greater flexibility, reduces over-fetching, and allows applications to retrieve exactly the data they need through a single endpoint. For engineering teams, this often results in faster development cycles and a more efficient frontend…

Key takeawayIntrospection, aliasing, batching and query depth each widen the surface in ways a REST focused test never touches.
One verified checkpoint followed by a corridor of open gates receding into the distance.Practitioner
Authentication7 min read

The Most Common Authentication Vulnerabilities in SaaS Applications

Authentication is one of the most important security controls in any SaaS application. It verifies that a user is who they claim to be, and establishes the identity that every later access decision depends on. Every login page, mobile application, API, and third-party integration ultimately relies on authentication to establish trust between users and the…

Key takeawayWhere MFA, OAuth, session handling and password reset actually break, beyond credential stuffing and weak passwords.
A stack of report pages with one finding line marked in green.Fundamentals
Pentesting Guides7 min read

What Is a Penetration Test Report? What SaaS Teams Should Expect After Testing

Most companies think the penetration test is the final deliverable. It’s not. The real value often comes after the testing is complete: inside the penetration test report itself. Because a good penetration test report does more than list vulnerabilities. It explains how your application can actually be attacked, what business risk exists, how the issue…

Key takeawayWhat separates a report your developers can act on from a tool export with severity labels attached.
Concentric rings around a core with inputs arriving from outside, one of them highlighted in green.Fundamentals
AI Security4 min read

How AI Is Changing Cybersecurity (And Why It’s Creating New Attack Surfaces)

Artificial intelligence is quickly becoming a core part of modern applications. From chatbots and recommendation systems to internal automation tools and AI-powered workflows, SaaS platforms are integrating AI at an increasing pace. But while AI is improving efficiency and user experience, it is also introducing something most teams are not fully prepared for. New attack…

Key takeawayAdding AI to a product adds inputs you do not control and permissions you did not audit.
A dashed sweep across a surface compared with a green probe descending through the layers beneath it.Fundamentals
Pentesting Guides5 min read

Penetration Testing vs Vulnerability Scanning (What Actually Finds Real Risks in SaaS Applications)

If you’re building a SaaS product or managing a web application, you’ve probably come across both terms: penetration testing and vulnerability scanning. They’re often used interchangeably, but in reality, they solve very different problems. Understanding that difference is critical, because choosing the wrong approach can leave real vulnerabilities completely unnoticed. What Vulnerability Scanning Does Vulnerability…

Key takeawayDetection versus exploitation, what each one genuinely finds, and how often you actually need either.
Six parallel API channels with one highlighted in green leaking downward.Practitioner
API Security6 min read

Common API Vulnerabilities in SaaS Applications (And How They Are Exploited)

APIs are the backbone of modern SaaS applications. Every login, dashboard update, integration, or workflow is powered by API calls running in the background. But here’s the problem. Most SaaS companies focus heavily on the frontend and assume the backend APIs are “safe by default.” They’re not. In real-world security testing, APIs are often the…

Key takeawaySeven API flaw classes with how each is exploited in practice, and why the API is the largest surface you own.
A route connecting ordinary nodes into an attack path, ending at a highlighted node.Fundamentals
SaaS Security4 min read

How SaaS Applications Get Hacked (And Where Most Startups Fail in Security)

Introduction Most SaaS companies believe they are secure. They rely on cloud infrastructure, managed services, and modern frameworks. On the surface, everything looks solid. But in reality, most breaches today don’t come from complex exploits or zero-days. They happen because of something much simpler: Access. Trust. And broken logic. In many cases, attackers don’t “hack”…

Key takeawayMost breaches are not zero days. They are ordinary logic and access mistakes in software that looks well built.
A magnifier over a field of scattered points, finding the one that matters.Fundamentals
Pentesting Guides4 min read

What Is The Hidden Finds? A Cybersecurity Company for SaaS Security, Penetration Testing & Vulnerability Assessment

If you have come across The Hidden Finds and are wondering what it actually is, this article is for you. In simple words, The Hidden Finds is a cybersecurity company that helps businesses find security weaknesses before attackers do. I work with modern companies, especially SaaS platforms and online businesses, to improve their security through…

Key takeawayWhat the practice covers, how the work is done manually, and where the name comes from.
Assets inside a perimeter with one exposed asset outside it highlighted in green, representing exposed asset detection.Practitioner
Asset Monitoring11 min read

Exposed Asset Detection: How to Find What You Have on the Internet Before Someone Else Does

Exposed asset detection is the process of finding every system your organization has reachable from the public internet, including the ones nobody remembers creating. It is the first step in any serious security programme, because every control you buy afterwards quietly assumes you already know what you are protecting. Most organizations do not. The inventory…

Key takeawayDetection finds what is reachable. Visibility means knowing it is yours, who owns it, and whether it should exist at all.
Reading path

Access control, start to finish

Four articles that build on each other, from what the flaw is through to how to test for it. Read them in this order if the subject is new to you.

  1. 01 Broken access control
  2. 02 IDOR explained
  3. 03 Authorization testing guide
  4. 04 Access control checklist
SECURITY INSIGHTS

Stay Updated

Explore new security research, attack-path analysis, and practical SaaS security insights.