Escape DAST - Application Security Blog

Dive into the world of application security, API security and GraphQL security. Explore performance optimization, testing strategies, and best practices for building secure APIs & SPA.

[Webinar] From Business Logic Vulnerabilities to Actionable Insights: AI-powered Pentesting + ASM in Action
Application Security

[Webinar] From Business Logic Vulnerabilities to Actionable Insights: AI-powered Pentesting + ASM in Action

For years, security teams have relied on human penetration testers to uncover critical vulnerabilities hidden in complex business logic. These flaws are subtle, context-dependent, and unique to every system’s workflow. Even modern scanners struggle to capture them, focusing only on a limited range of vulnerabilities displayed in their UI.

More Support for Complex Authentication Flows: TOTP MFA and Text-Based CAPTCHA
Product updates

More Support for Complex Authentication Flows: TOTP MFA and Text-Based CAPTCHA

This June, we’re making it easier to test real-world applications with complex authentication flows without sacrificing automation. Security teams need to test applications exactly as they exist in production, including MFA and CAPTCHA-protected flows. Historically, these protections aren’t "scanner-friendly" and often introduce friction into DAST workflows.

How Escape Enabled Deeper Business Logic Testing for Arkose Labs
Case Study

How Escape Enabled Deeper Business Logic Testing for Arkose Labs

Arkose Labs is a global cybersecurity company that specializes in account security, including bot management, device ID, anti-phishing and email intelligence. Its unified platform helps the world’s biggest enterprises across industries, including banking, gaming, e-commerce and social media, protect user accounts and digital ecosystems from malicious automation, credential stuffing