SECURITY CIPHER · BLOG

web application security

Posts from Security Cipher.

PIYUSH KUMAWAT · July 27, 2026

How I Would Hack Your Startup in 24 Hours (Real-World Pentest Guide)

Give me your company name and 24 hours. That is usually all it takes to go from knowing nothing about a startup…

PIYUSH KUMAWAT · July 19, 2026

Web Cache Poisoning in 2026: A Practical Playbook (One Request, Every Victim)

Most web bugs hit one victim at a time. Web cache poisoning is different, and that is exactly why it is worth…

PIYUSH KUMAWAT · July 13, 2026

Hacking GraphQL APIs in 2026: Introspection, BOLA, and Batching Attacks

GraphQL is a gift to attackers. One endpoint, usually /graphql, that speaks a typed, self-describing language and will happily tell you every…

PIYUSH KUMAWAT · July 10, 2026

IDOR Hunting in 2026: A Practical Playbook for Finding Broken Access Control

IDOR is the bug that pays rent for a lot of bug bounty hunters, and it is still the one developers ship…

PIYUSH KUMAWAT · August 14, 2024

🛠️ Reconnaissance and Vulnerability Scanning Script🛡️

In the fast-paced world of cybersecurity, staying ahead of potential threats requires thorough reconnaissance and vulnerability assessments. This blog post introduces you…

PIYUSH KUMAWAT · March 11, 2023

Threat Modeling : Everything You Need to Know for Web Application Security

Web applications are a crucial part of today’s online landscape, with businesses relying on them to provide services to their customers. However,…

PIYUSH KUMAWAT · January 30, 2023

OSV-Scanner: Protecting Your Open-Source Dependencies

In today’s digital age, cyber security threats are becoming increasingly prevalent and sophisticated. As a result, organizations need to have robust security…