Awareness
-

Sponsored Malware: When the Bad Guys Pay for Views
By Jason Taylor When a Raxis pentester Jason Taylor found a suspicious sponsored search result, he broke down the code it would have run and discovered it was malware. March 13, 2026 -

SpamGPT: Protecting Your Company From Large-Scale Phishing
By Nathan Anderson SpamGPT, a complex phishing and social engineering suite has made the news recently. Learn what it is and how organizations can protect their employees. October 9, 2025 -

Hackers See Opportunity Where You See Only a Button
By Brad Herring In this post, Raxis VP Brad Herring explains how web proxy tools can turn even simple buttons and check-boxes into avenues for an attack. April 1, 2022 -

2021 OWASP Top 10 Focus: Injection Attacks for Penetration Testing
By Raxis Research Team The latest draft of the OWASP Top 10 has been released. Though injection is #3, Raxis’ Matt Dun explains why that doesn’t mean the threat is any less severe. September 24, 2021 -

Realistically Assessing the Threat of Clickjacking Today: A Penetration Tester Perspective
By Adam Fernandez Raxis’ Lead Developer Adam Fernandez discusses clickjacking, explaining what it is and why it represents less of a threat now than it once did. Adam also talks about how clickjacking differs from similar attacks. May 28, 2021 -

NSA, FBI, CISA Statement on Russian SVR Activity
By Raxis Research Team The US government is warning businesses to beware of vulnerabilities being exploited by the Russian Foreign Intelligence Service (SVR RF). But that’s not the only group taking advantage. Here’s what you should do. April 21, 2021