Skip to content

Sanket Kakde

Nine Programs, Nine Organizations, One Forgotten DNS Record: How FireCompass’s Agentic AI Penetration Testing Found Subdomain Takeover Risk Across Five Cloud and CDN Providers

Introduction A subdomain takeover starts with a decommissioning step nobody remembered to do. A team points a company subdomain at a third-party resource, a CDN edge, a cloud app, a storage bucket, a static-site build, and later deletes or renames that resource without ever removing the DNS record that pointed to it. The subdomain keeps… Read More »Nine Programs, Nine Organizations, One Forgotten DNS Record: How FireCompass’s Agentic AI Penetration Testing Found Subdomain Takeover Risk Across Five Cloud and CDN Providers

Shipped to the Browser: How FireCompass’s Agentic AI Penetration Testing Found API Keys and Signing Secrets Hardcoded Into Client-Side Code Across Ten Independent Programs

Every browser tab runs code the vendor chose to send to it, and everything in that code is visible to whoever opens developer tools, reads a source map, or decompiles the bundle. A recurring and often underestimated class of exposure is what happens when that shipped code, or a config response it calls, carries something… Read More »Shipped to the Browser: How FireCompass’s Agentic AI Penetration Testing Found API Keys and Signing Secrets Hardcoded Into Client-Side Code Across Ten Independent Programs

How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

As organizations continue to expose authentication and account-recovery flows directly to the public internet, these flows remain some of the highest-value, least-forgiving attack surfaces on the web. A single unparameterized query can turn a login form into a full database read primitive. During a recent bug bounty assessment, this finding was surfaced by FireCompass’s Agentic… Read More »How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Modern web applications often expose numerous server-side components that invoke operating system utilities to process user requests. While these utilities simplify functionality, they also expand the attack surface when user-controlled input is passed into shell commands or embedded scripting engines without proper validation. During a recent private bug bounty engagement, FireCompass AI Agent autonomously identified… Read More »From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Forest-Root-Golden-Ticket-SID

Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

Most stakeholders treat a domain as a security boundary. It is not. The forest is. This walkthrough traces a single attack chain that started with domain-admin access already held in a child domain and ended with every credential in the environment dumped from the forest root. The pivot that made it possible was one forged… Read More »Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

Firecompass ranked #1 AI on HackerOne. Read more →