Industry Insights from our cybersecurity experts
News and insights on the cybersecurity industry and trending topics. Regular updates, commentary, and the point of view from Blaze’s world-class cyber experts.

SaaS Penetration Testing: What to Test Beyond the Web App
SaaS penetration testing goes beyond standard web application testing. Learn how to assess APIs, tenant isolation, cloud infrastructure, SSO, integrations, admin tooling, and business logic across a modern SaaS product.
All Articles

Common PCI DSS Penetration Testing Findings
PCI DSS pentests often uncover fewer findings than broader assessments, but the findings that remain are more likely to affect the controls protecting cardholder data. This article looks at the issues that appear most often and what they mean.

Common ISO 27001 Penetration Testing Findings
What do ISO 27001 pentests usually find? This article explains the most common findings, why they appear in scoped environments, and what they reveal about control effectiveness.
MITRE Fight Fraud Framework: How F3 Extends ATT&CK Into Financial Fraud
MITRE’s new Fight Fraud Framework (F3) helps analysts model how cyber-enabled fraud unfolds after compromise. This article explains what F3 is, how it differs from ATT&CK, and why it matters for fraud detection and investigation.

How Agentic AI Will Finally Make Shift Left Security Real
Agentic AI is making shift-left security more achievable by helping teams detect, validate, and remediate vulnerabilities earlier in the secure software development lifecycle. See why it matters, where current tools are changing developer workflows, and how organizations can adopt these capabilities in practice.

Common SOC 2 Penetration Testing Findings
What does a SOC 2 penetration test usually uncover? These are the findings that appear most often in SaaS environments.

Common Penetration Testing Findings: What Security Assessments Reveal
Which vulnerabilities do penetration tests find most often? This article breaks down the most common penetration testing findings observed in 2025, including sensitive data exposure, improper access control, input validation flaws, and other recurring security issues.
