Awareness
-

Sponsored Malware: When the Bad Guys Pay for Views
When a Raxis pentester Jason Taylor found a suspicious sponsored search result, he broke down the code it would have run and discovered it was malware.Jason Taylor March 13, 2026 -

SpamGPT: Protecting Your Company From Large-Scale Phishing
SpamGPT, a complex phishing and social engineering suite has made the news recently. Learn what it is and how organizations can protect their employees.Nathan Anderson October 9, 2025 -

Hackers See Opportunity Where You See Only a Button
In this post, Raxis VP Brad Herring explains how web proxy tools can turn even simple buttons and check-boxes into avenues for an attack.Brad Herring April 1, 2022 -

2021 OWASP Top 10 Focus: Injection Attacks for Penetration Testing
The latest draft of the OWASP Top 10 has been released. Though injection is #3, Raxis’ Matt Dun explains why that doesn’t mean the threat is any less severe.Raxis Research Team September 24, 2021 -

Realistically Assessing the Threat of Clickjacking Today: A Penetration Tester Perspective
Raxis’ Lead Developer Adam Fernandez discusses clickjacking, explaining what it is and why it represents less of a threat now than it once did. Adam also talks about how clickjacking differs from similar attacks.Adam Fernandez May 28, 2021 -

NSA, FBI, CISA Statement on Russian SVR Activity
The US government is warning businesses to beware of vulnerabilities being exploited by the Russian Foreign Intelligence Service (SVR RF). But that’s not the only group taking advantage. Here’s what you should do.Raxis Research Team April 21, 2021