Recently Posted
CredShields Blog
Latest articles
What MAS Auditors Look for in Your Identity and Access Architecture
Monetary Authority of Singapore (MAS) examiners assess identity and access against the access control requirements of the MAS...
Shai Hulud npm Supply Chain Attack: How To Check If The keyv Compromise Reached You
On August 4, 2026, a poisoned release of the npm package keyv spread the Shai Hulud credential-stealing worm...
Mobile Application Penetration Testing: What to Expect
A mobile application can function normally while still exposing sensitive data or privileged actions. Its security depends on...
AI Penetration Testing: What You Should Know Before Choosing A Vendor
AI has made its way into security testing, much like other industries. It is now used in penetration...
SOC 2 Penetration Testing: What You Should Expect Before An Audit
A SOC 2 report makes one guarantee to your customers: The data they give you is secure, and...
The wp2shell Crisis: Why This WordPress Core RCE Changes the Timeline for Enterprise Defense
The WordPress ecosystem is in the midst of its worst security crisis in almost a decade. wp2shell, a...
CVE-2026-10753: A Broken Access Control Flaw CredShields Found in Google’s Site Kit
An editor level user with dashboard sharing access could change a sitewide setting through a REST API endpoint...
What Makes Daml Different: A Security Perspective
If you work in web3 security, your mental model of smart contract risk was almost certainly built on...
Incident Report: Kelp DAO rsETH Bridge Exploit
Incident: Kelp DAO rsETH bridge, April 18 2026, 17:35 UTC An attacker pulled 116,500 rsETH roughly $292M, about...
5 Common Daml Authorization Mistakes
Daml’s authorization model is genuinely one of the better things about it. Solidity makes you bolt onaccess control...