Practical knowledge on pentest, compliance & AI security.
No marketing, no superficial whitepapers. What a tester with hands in the code encounters every day — written for people who genuinely want to understand their systems.
Is a penetration test report genuine? Verify it yourself in the browser
A PDF report can be altered or faked in a couple of minutes, and is rarely checked en route. That is why every Resync report is digitally signed. Here is how you, as an auditor, CISO or client, check yourself whether a report is authentic and unaltered, entirely in your own browser, with no upload.
The Dutch Cybersecurity Act has passed: your action list to 15 August
On 7 July 2026 the Dutch Senate adopted the Cybersecurity Act; it takes effect on 15 August, with no transition period. That leaves you around five weeks. A concrete step-by-step action list: from "am I in scope?" and NCSC registration to the evidence that your measures work.
Zip Slip in xslweb: a missing path check in a built-in unzip function
The built-in unzip function in the Java XSLT framework xslweb extracted ZIP files without path validation. That flaw rode along in every release since 2015. The technical anatomy of the bug, the fix, and why this pattern keeps coming back.
The 2 minutes where SameSite=Lax doesn't stop CSRF
Chrome's "Lax+POST" mitigation still sends cookies without an explicit SameSite attribute on cross-site POST requests for the first 2 minutes. And that window is easier to keep open than you'd think.
How often should you run a penetration test?
The rule of thumb is at least annually and after every significant change. But where does that rule come from, what counts as "significant", and what do PCI DSS and NIS2 actually require? A practical explainer, including when once a year is too little.
The Dutch Cybersecurity Act (NIS2): are you in scope, and what changes?
The Senate adopted the law on 7 July 2026; it takes effect on 15 August 2026, with no transition period. Is your organisation in scope, what do the duty of care, reporting and registration obligations involve, and where does a penetration test fit in? A current, practical explainer.
What is a penetration test and when do you need one?
The difference between a pentest, a vulnerability scan and an audit — written for the IT manager, CISO or executive considering a penetration test for the first time. Includes a practical decision tree for "should I test now or not?"
NIS2 and municipalities: what does the regulator expect from you?
The Dutch Cybersecurity Act has passed and takes effect on 15 August 2026. Executives will face personal liability. What does your municipality need to do concretely — and what's the difference between "paperwork in order" and "demonstrably secure"? Compact explanation of what the regulator expects in practice.
Why vibe-coded apps are more vulnerable
Apps built with Cursor, Bolt, Lovable or v0 consistently contain the same vulnerability patterns. Not because AI is "bad" — but because AI optimises for "working", not "secure". The anatomy of the problem, with examples.
Ready for a real pentest?
Theory is good, proof is better. Request a free intake — fixed price, retest included, response within 1 business day.
Schedule free intake →