Blog

Analysis and takeaways from our offensive engagements and vulnerability research.

Tech Tech Tech Tech

Hacking Liferay: From XSS to RCE via CAPTCHA Bypass

AnchorSec’s research team investigate the Liferay application and find a Cross-Site Scripting vulnerability that leads to Remote Code Execution, via CAPTCHA bypass. This blog explains the vulnerability and how it was exploited.

Read More
Gareth C Gareth C

Hidden Daemons: A Telnet mystery

AnchorSec’s founder, Gareth, develops a tool to help him find and verify Regular Expression Denial of Service (ReDoS) vulnerabilities in code. This blog explores the cause of this class of vulnerability, how to find ReDoS vulnerabilities and the implications for security. The blog also describes the development of a new tool to assist in finding these vulnerabilities, and the next steps for security testers.

Read More
Gareth C Gareth C

Evil Re: An introduction to ReDoS vulnerabilities

AnchorSec’s founder, Gareth, develops a tool to help him find and verify Regular Expression Denial of Service (ReDoS) vulnerabilities in code. This blog explores the cause of this class of vulnerability, how to find ReDoS vulnerabilities and the implications for security. The blog also describes the development of a new tool to assist in finding these vulnerabilities, and the next steps for security testers.

Read More
Francesca B Francesca B

2026 trends in Cyber Security

AnchorSec explores the key themes shaping cyber security in 2026 and shares ideas to help you navigate the changes and protect your business. From accelerating use of AI to upcoming legislation, this blog contains straightforward advice to stay on top of the trends.

Read More
Francesca B Francesca B

The Rising Stakes of Operational Technology Security  

OT environments were not initially designed with security as a priority. As OT environments become increasingly connected to IT infrastructure, and our daily lives become ever more dependent on the smooth, safe running of this technology, ensuring it is deployed, maintained and operated securely is increasingly important.

Read More
Francesca B Francesca B

Another Kind of Technical Debt

As organisations embrace the cost benefits and technical capabilities of automated tools and AI supported security testing, AnchorSec asks what the implications are for the offensive security industry, and the real world security of your IT systems.

Read More
Tech Tech Tech Tech

A Real-World Take on SANS SEC760

I recently embarked upon a journey through time and space to learn some new things, challenge myself technically and wipe off the rust of a near dead skill I once used to cultivate when cybersec was still a little more space cowboy.

Read More