AJAmartya Jhainsecurity-research.hashnode.dev·7h ago · 6 min readYour Perimeter Will Fail. The Real Question Is How Far an Attacker Gets After.TL;DR: External tests and scanners check your perimeter. Neither answers the question that decides how bad a breach gets: once someone is inside, how far can they go? That is what internal penetration00
AJAmartya Jhainsecurity-research.hashnode.dev·7h ago · 8 min readYour Pentest Report Says "SQL Injection on /api/search." It Won't Say Which Line.Your Pentest Report Says "SQL Injection on /api/search." It Won't Say Which Line. TL;DR: External penetration testing still matters, but the classic once-a-year model has six structural gaps that hurt00
AJAmartya Jhainsecurity-research.hashnode.dev·1d ago · 7 min readI Automated Copilot Code Review on Every Pull Request. Here's What It Still Can't DoThe setup takes twenty minutes. The limitations take longer to notice. The first time I turned on Copilot code review, I watched it comment on a pull request within ninety seconds, felt genuinely imp10
AJAmartya Jhainsecurity-research.hashnode.dev·Sep 9 · 13 min readWhy Your $6,500 Penetration Test Will Cost You More Than the $47,000 One Two penetration testing quotes land in your inbox. One says $6,500. The other says $22,000. Both vendors say they use AI. Both promise comprehensive coverage. Both have credible-looking reports, exper00
AJAmartya Jhainsecurity-research.hashnode.dev·Sep 9 · 25 min readExternal Penetration Testing in 2026: A Technical Methodology, Tool Stack, and Attack Surface GuideExternal penetration testing is often reduced to a familiar sequence: nmap → nuclei → Burp → report That workflow is useful, but it misses the hardest part of the engagement. Finding the assets worth00