Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Authority
Sep 26, 2026 Vid Grosek

Can your supplier’s SBOM and VEX support patch decisions?

Supplier documents can support patch decisions when you can establish who published them, connect them to the software you run, and demonstrate how your tools use and update the resulting decision. A software bill of materials (SBOM) records software components and their relationships.…

Read More
AD Attacks
Sep 25, 2026 Vid Grosek

Entra migration review: prove client secrets are retired

A working managed identity or federated credential does not prove that the former client secret is retired. Review every deployed consumer and every customer-managed password credential within the declared scope. Record three distinct outcomes: credential retired, runtime migration complete, and…

Read More
AD Attacks
Sep 22, 2026 Vid Grosek

Microsoft Entra’s passkey transition: evidence to approve each enforcement wave

Microsoft guidance checked September 22, 2026. Approve a phishing-resistant authentication rollout only when the evidence covers the workflows entering the next wave. For each user, device, client, and resource combination, record the policy configuration, actual authentication method, enforced…

Read More
Reporting
Sep 21, 2026 Vid Grosek

Buying a CRA reporting readiness review: evidence to require

A useful Cyber Resilience Act (CRA) reporting readiness review should demonstrate how your team handles a specific case: establish product scope, assess both reporting triggers, record awareness, notify users, and complete the applicable reporting stages. Put these deliverables and their acceptance…

Read More
Web Security
Sep 20, 2026 Vid Grosek

Browser-based OAuth in 2026: choose the architecture before exposing tokens to a SPA

A backend-for-frontend (BFF) is justified when keeping OAuth tokens out of browser JavaScript provides enough protection to warrant operating a backend and proxying API traffic. The decision depends on the consequences of token theft, direct API requirements, proxy feasibility, and operating cost.…

Read More
Evasion
Sep 19, 2026 Vid Grosek

Endpoint Tamper Protection: Evidence That It Still Works

Editorial slot: September 19, 2026. Published on September 19, 2026 after review. If your endpoint dashboard is green, you know that it received a status report. You do not yet know whether a protected setting resists tampering, whether a sensor sends useful evidence, or whether an analyst will act…

Read More
Web Security
Sep 19, 2026 Vid Grosek

Secure Webhook Receiving: Verify Signatures, Stop Replays, Handle Retries

Editorial slot: September 18, 2026. Published on September 19, 2026 after review. A webhook receiver should treat every incoming request as untrusted until it has verified the provider's signature against the exact bytes received. Then it should reject stale requests, record a delivery identity…

Read More
Web Security
Sep 19, 2026 Vid Grosek

Kubernetes NetworkPolicy Isolation: Prove the Rules Work Before Relying on Them

Editorial slot: September 17, 2026. Published on September 19, 2026 after review. The direct answer: a NetworkPolicy manifest is not proof of isolation. Before relying on it, prove four things in the target cluster: the installed network plugin enforces Kubernetes NetworkPolicy, the intended Pods…

Read More
Authority
Sep 19, 2026 Vid Grosek

Scope an AI-agent security test

Editorial slot: September 13, 2026. Published on September 19, 2026 after review. A useful AI-agent security assessment follows one real business request from the initiating principal, whether a person, service, workflow, or scheduled task, through the agent, the identities it uses, every connected…

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch