Secureaks Blog

Secureaks Blog - Pentest and cybersecurity

Articles on penetration testing, cybersecurity, and ethical hacking. Stay informed about the latest trends in the field of cybersecurity.

Why whitelist a pentester on a WAF?
Cybersecurity

Why whitelist a pentester on a WAF?

Romain Garcia · 02/16/2026

When a company carries out an application penetration test, the main objective is to assess the actual security level of the web application, its functionalities, its code and its exposure to attacks. However, one element can quickly distort the results: the presence of a WAF (Web Application Firewall). In this context, whitelisting a pentester on a WAF is common practice and often necessary to guarantee the relevance of tests. This approach is not intended to reduce security, but to enable reliable assessment of application vulnerabilities.

Read more
React2Shell: full analysis (CVE-2025-55182)
Cybersecurity

React2Shell: full analysis (CVE-2025-55182)

Romain Garcia · 12/18/2025

The React2Shell flaw affects React Server Components (RSC) and allows, under certain conditions, remote code execution (RCE) on the server hosting the application. It requires no authentication, is very easy to exploit, and logically achieves the maximum score of 10/10 on the CVSS scale.

In this article, we'll look at what exactly React2Shell is, which versions are affected, how the vulnerability works, how to detect and exploit it, and above all, how to protect against it effectively.

Read more
Pentest vs Bug Bounty: what are the differences and what's in it for you?
Ethical Hacking

Pentest vs Bug Bounty: what are the differences and what's in it for you?

Romain Garcia · 05/13/2025

Faced with the constant growth of online threats, companies are looking to strengthen the security of their information systems. Two complementary approaches are often mentioned: penetration testing (or pentests) and Bug Bounty programs. While their common objective is to identify vulnerabilities, their methods, frameworks and benefits differ considerably. Understanding these differences is essential to choosing the solution best suited to your needs.

Read more
Exploit SQL Injections with SQLMap : Complete Guide
Ethical Hacking

Exploit SQL Injections with SQLMap : Complete Guide

Romain Garcia · 04/28/2025

SQL injections represent one of the most critical vulnerabilities in cybersecurity. Exploiting these flaws often requires advanced skills, but tools like SQLMap make the task much more efficient. This guide covers the basics of SQL injections, how to use SQLMap to detect and exploit them, and tips on how to protect against them.

Read more
How often should I run a penetration test on my website?
Cybersecurity

How often should I run a penetration test on my website?

Romain Garcia · 04/22/2025

Web application security is a major challenge for all companies with an online presence. Cyber-attacks are constantly evolving, exploiting the slightest vulnerability to gain access to sensitive data or compromise service availability. In this context, penetration testing (pentesting) is essential to identify and correct security vulnerabilities before they are exploited. But how often should such tests be carried out?

Read more
5 cybersecurity mistakes that small businesses still make too often
Cybersecurity

5 cybersecurity mistakes that small businesses still make too often

Romain Garcia · 04/18/2025

Cybersecurity has become a crucial issue for companies of all sizes. Yet many small and medium-sized businesses continue to make fundamental mistakes that expose them to significant risks. These mistakes are all the more problematic in that they are often avoidable with a minimum of good practice and awareness. This article looks at five of them and explains why they need to be corrected quickly.

Read more
Matomo