[ BLOGS ]

Where Dev Teams Learn Faster

Where Dev Teams Learn Faster

Where Dev Teams Learn Faster

1000+ engineering teams have made CodeAnt AI the last line of defence before every deployment

Trusted by Startups to Fortune 100

Featured

AI PENTESTING

Claude Code Sandbox
Escape on macOS

Sonali Sood

Founding GTM, CodeAnt AI

Liquid Network Hack Explained: Inside the $320M Attack Path No Scan Would Have Caught

Code Security

The $320M Liquid Network Hack and the Attack Path Nobody Validated

How the Liquid Network hack drained 95% of a Bitcoin sidechain's reserves in 23 minutes without compromising a single key, and what attack path validation would have caught.

AI Pentesting

Auditing the Shipped Artifact. What Four macOS Desktop Clients Revealed

SAST reads the repo. SCA reads the lockfile. Nothing reads the signed artifact your users install. Four macOS desktop clients audited, the recurring bug classes, and the method.

AI Pentesting

What is an IDOR Vulnerability? Types, Examples, CVSS, and Detection Methods

IDOR vulnerabilities let attackers access any user’s data with a simple ID change. Learn every variant, real exploits, and how to prevent it in APIs and SaaS systems.

AI Pentesting

AI Penetration Testing: How It Works, Methodology, Tools, and Best Practices

Learn how AI penetration testing works, from reconnaissance and vulnerability discovery to exploitation, attack paths, reporting, and human validation.

AI Pentesting

AI Penetration Testing Methodology: Phase-by-Phase Breakdown (2026)

Two firms quote the same price. One has methodology, one has tools. Here's the complete 10-phase process that determines whether your most critical vulnerability gets found, or missed entirely.

AI Pentesting

Continuous Penetration Testing vs Annual Pentesting: Which Model Is Right for Your SaaS Company?

A deep technical breakdown of continuous vs annual pentesting, including attack surface drift, testing cadence, and ROI.

AI Pentesting

3 Types of Penetration Testing: Black Box, White Box, and Gray Box

Not all penetration tests are the same. Learn how black box, white box, and gray box testing differ, and which one your application actually needs to stay secure.

The Log4j2 Filter That Only Does Half Its Job

Code Security

Dissecting FOIS: The Log4j2 Filter That Only Does Half Its Job

Log4j2's FilteredObjectInputStream checks which classes can be rebuilt, but not how large or deep the data can be. Here's how that gap enables an RCE and two gadget-free crashes on a serialized log receiver.

Claude Code Action Bug: Security Flaw Lets Triage Roles Inject Data

Code Security

Claude Code Action Bug: Security Flaw Lets Triage Roles Inject Data

A triage-role GitHub collaborator could move a Claude Code Action run's authorized trigger boundary and inject post-authorization input into a repo-writing job.

Claude Code Security Flaw: Sandboxed Code Overwrites Host Files

Code Security

Claude Code Security Flaw: Sandboxed Code Overwrites Host Files

A filesystem identity race allowed code confined to Claude Code's macOS Bash sandbox to redirect the host-owned Edit tool and overwrite user-writable files outside the workspace.

CVE-2026-71511: Redaction Bug Exposes Password Hashes

AI Pentesting

CVE-2026-71511: Redaction Bug Exposes Password Hashes

A redaction bug (CVE-2026-71511, CVSS 6.5) left Dolibarr's members API exposing every member's password hash to any account that could read member records.

CVE-2026-71510: Blind Search Leaks Dolibarr Salaries

AI Pentesting

CVE-2026-71510: Blind Search Leaks Dolibarr Salaries Copy

A blind authorization flaw (CVE-2026-71510, CVSS 6.5) let attackers infer hidden Dolibarr salaries and password hashes through yes/no search queries.

Let AI Fix Your Code, You Build the Future

Get Pentest Report

NO CC REQUIRED