AnySec

Insights

Field notes from the trenches.

Engagement post-mortems, vulnerability deep-dives, and lessons learned from defending casinos, exchanges, and banks. No marketing fluff.

Scoping a penetration test for an online casino
Penetration TestingFeatured · · 8 min read

Scoping a penetration test for an online casino

How to scope penetration testing for an online casino: what's in the RoE, which assets matter, what drives cost, and what the report contains.

Read the write-up →
Managed SOC for iGaming
Managed SOC · 8 min read

Managed SOC for iGaming

Managed SOC for iGaming only works if log sources, detection coverage, and response boundaries are fixed before onboarding, not during the first incident.

Read →
Scoping DDoS stress testing for an online casino
DDoS · 8 min read

Scoping DDoS stress testing for an online casino

DDoS stress testing for an online casino only proves resilience if the RoE, provider coordination, and abort conditions are scoped correctly first.

Read →
Vulnerability assessment vs penetration testing
Penetration Testing · 9 min read

Vulnerability assessment vs penetration testing

Vulnerability assessment vs penetration testing for iGaming: what each one covers, the evidence each produces, and how a casino decides which it truly needs.

Read →
CVE-2026-32194: your SVG uploads may be next
Penetration Testing · 6 min read

CVE-2026-32194: your SVG uploads may be next

Bing Images had a CVSS 9.8 SVG-to-RCE flaw via ImageMagick delegates. If your app processes user-uploaded images server-side, check this today.

Read →
CVE-2026-54121: any AD user can seize your domain
Penetration Testing · 6 min read

CVE-2026-54121: any AD user can seize your domain

CVE-2026-54121 ("Certighost") lets a low-privileged Active Directory user impersonate a Domain Controller and compromise the domain. What to check this week.

Read →
CVE-2026-16232: auth bypass in Check Point console
Response · 6 min read

CVE-2026-16232: auth bypass in Check Point console

CVE-2026-16232 lets an unauthenticated attacker log into Check Point SmartConsole with full admin rights and rewrite firewall policy. Check this in 24 hours.

Read →
How to protect an online casino from DDoS attacks
DDoS · 8 min read

How to protect an online casino from DDoS attacks

A 2026 guide to protecting an online casino from DDoS attacks: anycast absorption, L7 filtering, origin isolation, and the runbook that keeps betting live.

Read →
Credential stuffing against casino cashiers
Casinos · 10 min read

Credential stuffing against casino cashiers

Credential stuffing rarely loses money at login — the loss lands at the cashier. The full attack chain against casino withdrawal flows, and how to break it.

Read →
When your SOC tool is the target: CVE-2026-20253
Managed SOC · 8 min read

When your SOC tool is the target: CVE-2026-20253

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise, now on CISA's KEV list. If your SOC platform is internet-reachable, it's attack surface too.

Read →
The casino cybersecurity threat landscape in 2026
Casinos · 9 min read

The casino cybersecurity threat landscape in 2026

What we've seen actually hitting licensed online casinos this year — bonus abuse, withdrawal fraud, and the slow rise of AI-assisted social engineering.

Read →
Building a SOC for a crypto exchange from scratch
Managed SOC · 10 min read

Building a SOC for a crypto exchange from scratch

Detection rules, alert thresholds, and on-call playbooks for threats unique to a regulated exchange — wallet drainers, custody compromise, address-poisoning.

Read →
NIS2 + DORA without the consultant theatre
Compliance · 11 min read

NIS2 + DORA without the consultant theatre

What EU operators actually need to do to be ready for NIS2 and DORA — control by control, with the time and effort to expect.

Read →
Anatomy of a modern L7 DDoS attack
DDoS · 9 min read

Anatomy of a modern L7 DDoS attack

What we see hitting casino and exchange edges in 2026 — and why provider defaults don't catch it.

Read →
Why we still do pure-manual penetration testing
Penetration Testing · 8 min read

Why we still do pure-manual penetration testing

Automated scanners have improved and PTaaS platforms are everywhere. Here's why our senior engineers test by hand, and what they catch that scanners don't.

Read →
What a real pentest report looks like
Penetration Testing · 8 min read

What a real pentest report looks like

If your last pentest report was a Nessus PDF export, you got scammed. Here's exactly what to demand.

Read →
Building a private Anycast edge from scratch
Infrastructure · 11 min read

Building a private Anycast edge from scratch

Why some of our clients run their own ASN, IP blocks, and edge — the trade-offs vs Cloudflare, and how the math actually works.

Read →

Facing something you'd rather not write about later?

Talk to the engineers behind these write-ups. Thirty minutes, no sales script — just a straight read on where you stand.

Book a call