Security Research
Real-world security research covering DAST, AI-assisted vulnerability analysis, attack chain modeling, and engineering benchmarks.

We tested Llama 4 Scout, Gemma 4, and Kimi K2.7 Code on the same screenshot-to-structured-JSON task. Llama was the only model to pass every schema check — and it also delivered the best latency and observed cost in our test set.

How DeepTraQ went from "the scanner found 6 critical IDORs!" to "the scanner found 6 critical IDORs, and here's cryptographic-grade proof each one is real."

Three failure modes in multi-user BAC testing with custom ZAP — crawl loops, non-comparable runs, and capture-time session bleed — and why each one is invisible until you go looking.

An LLM generated ZAP automation YAML that looked perfect and referenced job types that don't exist. A case study in plausible-but-nonexistent APIs, and what it cost to catch it five days late.

ZAP's fuzz and accessControl add-ons are GUI-only, so IDOR, input validation, and broken access control testing silently fail in headless pipelines. Here's the standalone-script workaround that fills the gap.

An overview of the security posture of the Django DefectDojo repository, highlighting key findings, risk distribution, and recommended remediation strategies.
Discover how Corefix helps security teams identify, prioritize, and remediate vulnerabilities across cloud, web, code, and infrastructure environments.
Visit Website →Setup guides, scanner integrations, workflows, remediation automation, API references, and complete product documentation.
View Documentation →See upcoming releases, planned features, product improvements, and the future direction of Corefix.
View Roadmap →