Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Web Security
Sep 13, 2026 Vid Grosek

API Authorization: Finding and Fixing BOLA/IDOR

Test whether each API caller may act on the requested object, using authorized accounts, synthetic records and explicit permission checks.

Read More
Authority
Sep 13, 2026 Vid Grosek

Microsoft 365 and Entra ID: Reducing Account-Takeover Exposure

Review authentication, Conditional Access, sessions, recovery and privileged access together to reduce account-takeover exposure.

Read More
AD Attacks
Sep 13, 2026 Vid Grosek

Active Directory Certificate Services: Pentest Priorities and Defensive Remediation

Review AD CS certificate templates, enrollment rights and authentication paths, then assign and verify defensive changes.

Read More
Slovenia
Feb 01, 2025 Vid Grosek

Working with Slovenian IT Teams: A Pentester Perspective

From bilingual NIS2 reports for URSIV to in-person Ljubljana debriefs — what I've learned about effective collaboration with Slovenian IT teams during pentests.

Read More
Slovenia
Jan 27, 2025 Vid Grosek

GDPR and Security Testing: Slovenian Perspective

How pentesting fulfils GDPR Articles 32, 25, 33, and 35 — and why Slovenian organizations under ZVOP-2 should treat it as a compliance tool, not just a technical exercise.

Read More
Slovenia
Jan 22, 2025 Vid Grosek

Common Vulnerabilities in Slovenian Companies

Real patterns from pentesting Slovenian organizations: Active Directory misconfigurations, Kerberoastable accounts, NTLM relay, and recurring web application flaws.

Read More
Slovenia
Jan 17, 2025 Vid Grosek

Cybersecurity Careers in Slovenia: Getting Started

From SOC analyst roles to CTF achievements and HackerOne findings — practical steps to launch a cybersecurity career in Slovenia's growing market.

Read More
Slovenia
Jan 12, 2025 Vid Grosek

Choosing a Penetration Testing Provider in Slovenia

From OSCP and OSCE3 credentials to sample reports and pricing red flags — a practical guide to picking a trustworthy pentest provider in Slovenia.

Read More
Slovenia
Jan 07, 2025 Vid Grosek

NIS2 in Slovenia: What Organizations Need to Know

Practical breakdown of NIS2 scope, risk management obligations, and supply-chain requirements for Slovenian essential and important entities.

Read More
Slovenia
Jan 02, 2025 Vid Grosek

The Cybersecurity Landscape in Slovenia

From NIS2-driven demand to a growing talent gap, here's how Slovenia's cybersecurity market is evolving — and where it's heading.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch