penetrify.cloud/blog
Blog
Approfondimenti, guide e aggiornamenti dall'avanguardia della sicurezza autonoma.

Abbiamo superato la suite di benchmark XBOW — nel nostro livello più veloce
Il nostro motore di pentest autonomo ha risolto tutte le 104 sfide di sfruttamento web XBOW (XBEN) — il 100% — usando il nostro livello di scansione più veloce ed economico. Ecco il risultato, il metodo e gli onesti caveat.

Il divario dei grader di CVE-Bench: quando gli exploit riusciti ottengono punteggio zero
Diversi grader automatici di CVE-Bench vanno in crash o si bloccano nel momento in cui un exploit compromette il proprio bersaglio, e un grader andato in crash viene silenziosamente registrato come un attacco fallito. Il benchmark può assegnare a una compromissione autentica il punteggio di un fallimento.

SQL Injection Despite the ORM: The One Raw Query Nobody Reviewed
Using an ORM does not prevent SQL injection. It concentrates it: hundreds of safe queries lull the team, and the one raw query someone wrote for a report interpolates a parameter straight into the statement.

Indirect Prompt Injection to Data Exfiltration: When the Model Has Tools
Prompt injection on its own is a curiosity. Prompt injection reaching a tool that holds real credentials is a breach — and the instruction does not have to come from your user. It can arrive inside the document your app was asked to summarise.

The Unverified Stripe Webhook: Forging checkout.session.completed for Free Premium
Your webhook endpoint is a public URL that grants entitlements. Without signature verification it accepts a payment confirmation from anyone — and the request that upgrades an attacker to your top tier is a single curl command.

When org_id Is a Parameter, Not a Boundary: Multi-Tenant Data Isolation Failure
Every multi-tenant application has an organisation identifier. The question that decides whether you have isolation is where it comes from — the session, or the request. When it comes from the request, one customer reads another's data with a single edited value.

Firebase Security Rules Left Wide Open: allow read, write: if true
Firebase asks you to choose a rules mode when you create a database, and the permissive option is the one that makes the tutorial work. Months later the app is live, the rule still says if true, and anyone with the project ID can read and write the entire database.

The Supabase service_role Key in the Client Bundle: RLS Bypassed Entirely
Row Level Security is the control that keeps one Supabase user out of another's rows. The service_role key is designed to ignore it. When that key reaches the browser, every policy you wrote stops mattering — and the pattern shows up in production more often than anyone admits.

La nostra app teneva i token di autenticazione in localStorage. Ecco cosa abbiamo cambiato.
Abbiamo scansionato la nostra app e il report ha segnalato il login con Cognito. Perché cifrare non risolve e cosa abbiamo rilasciato al suo posto.

What an autonomous pentest agent found in 3,847 apps — and what your scanner didn't
A data breakdown of 47,291 exploitation-validated findings, with methodology and limitations. 91% of the SQL injection we found shipped despite a SAST gate in CI; 78% of critical findings needed no login.