Blog
Security articles on application code, Salesforce orgs and AI coding agents.
How orgs and applications actually get attacked, how attack paths are built, and how to get more security analysis done with fewer tokens. RSS
AgentExchange Security Review5 Oct 20267 min readAgentExchange Security Review: what fails, and how to pass the first timeCRUD and FLS, sharing, guest access, XSS, secrets and insecure endpoints: what fails AgentExchange (formerly AppExchange) Security Review, and how to find it.Read the post →Attack paths5 Oct 20263 min readWhy attack paths matter more than lists of findingsA list of 400 Salesforce findings does not say which one matters most. An attack path does. How identity, permissions, code and data connect into one path an attacker can follow.Read the post →Application security5 Oct 20268 min readBroken access control is still number one, and 2025 showed whyChange one number in a request, get someone else's record. The IDOR breaches behind the 2025 headlines, and how Vulkro finds them in code and in Apex.Read the post →Salesforce5 Oct 20269 min readConnected apps and OAuth tokens: the integration attack surfaceStolen and phished OAuth tokens drove the 2025 and 2026 Salesforce data thefts. What decides a token's reach, and a practical connected app review checklist.Read the post →AI coding agents5 Oct 20267 min readDeterministic analysis vs asking a modelWhy asking a language model to find the vulnerabilities is the wrong approach, and where a model genuinely helps once a detector has done its part.Read the post →Application security5 Oct 20268 min readThe EU Cyber Resilience Act is live: what software teams must do nowSince 11 September 2026 the CRA reporting deadlines apply: 24 hours, 72 hours, then a final report. What to have ready, from the SBOM to the VEX.Read the post →Salesforce5 Oct 202610 min readHow Salesforce orgs get breached, shown as attack pathsThe large Salesforce data thefts of 2025 and 2026 needed no platform flaw. Three identity-based attack paths were enough. Each one hop by hop, and where to stop it.Read the post →Salesforce5 Oct 20263 min readIntroducing Vulkro Cloud for SalesforceA hosted workspace that keeps every Salesforce org under continuous security review, with attack paths, a Fix first list and the changes between scans.Read the post →AI coding agents5 Oct 20268 min readMCP servers are the new attack surfaceA backdoored MCP server, a command injection in a popular proxy, a prompt-injected agent leaking private repos. What went wrong in 2025, and what to check.Read the post →Salesforce5 Oct 20268 min readNIS2 and DORA reach your Salesforce org: the evidence you now needSalesforce runs the platform. Under NIS2 and DORA, the access, integrations and code inside your org are your responsibility. The evidence that shows it.Read the post →Application security5 Oct 20266 min readOne engine for Salesforce and the rest of your stackThe Node, Python, Go and Java services around a Salesforce org are part of the same attack path and need the same analysis: routes, ownership and proof.Read the post →