AnySec

Insights

Field notes from the trenches.

Engagement post-mortems, vulnerability deep-dives, and lessons learned from defending casinos, exchanges, and banks. No marketing fluff.

Penetration Testing a DeFi Protocol: Your Signing Path Is the Scope
Penetration TestingFeatured · · 8 min read

Penetration Testing a DeFi Protocol: Your Signing Path Is the Scope

A smart-contract audit reviews code. A DeFi pentest attacks the off-chain path around it — front end, build pipeline, signer workflow, keeper infrastructure. Scope, RoE and limits.

Read the write-up →
CVE-2026-85102: pre-auth RCE on your Check Point VPN gateway
Response · 6 min read

CVE-2026-85102: pre-auth RCE on your Check Point VPN gateway

CVE-2026-85102 lets an unauthenticated attacker execute code on Check Point Security Gateway and Spark firewalls via VPN certificate handling. On CISA's KEV list. What to check in 24 hours.

Read →
DDoS Protection for a DeFi Protocol: The Front End Is Solved, the RPC Layer Isn't
DDoS · 9 min read

DDoS Protection for a DeFi Protocol: The Front End Is Solved, the RPC Layer Isn't

A DeFi protocol's front-end DDoS problem is the same one any web app has. Its RPC layer is a different problem most teams never scope, because most protocols don't own that infrastructure.

Read →
Hardening a DeFi Protocol: What Comes First
Infrastructure · 8 min read

Hardening a DeFi Protocol: What Comes First

Registrar/DNS control, admin-key custody, and timelock config — the hardening priority order for a non-custodial DeFi protocol with no server to patch.

Read →
Haruko Breach: What Its Crypto Clients Should Check in 24 Hours
Response · 8 min read

Haruko Breach: What Its Crypto Clients Should Check in 24 Hours

Haruko, a crypto trading-infrastructure vendor connecting 100+ venues, was breached — 15 institutional clients affected, some funds lost. What to do when your vendor is hacked, not you.

Read →
Managed SOC for a DeFi Protocol: Why Your Alert Has to Beat the Next Block
Managed SOC · 9 min read

Managed SOC for a DeFi Protocol: Why Your Alert Has to Beat the Next Block

A non-custodial DeFi protocol has almost no traditional SOC surface — no employee endpoints, no customer login flow. What's actually monitorable, and why detection has to outrun block time, not minutes.

Read →
Private Anycast for a Crypto Exchange: When Your Own Health Checks Take You Fully Offline
Infrastructure · 7 min read

Private Anycast for a Crypto Exchange: When Your Own Health Checks Take You Fully Offline

Meta's October 2021 outage wasn't an attack or a hijack — it was a correctly designed health check withdrawing every BGP route at once. The failure mode private Anycast owners have to design against themselves.

Read →
Identity Hardening for an Online Casino: What the MGM Help-Desk Breach Actually Changed
Infrastructure · 8 min read

Identity Hardening for an Online Casino: What the MGM Help-Desk Breach Actually Changed

MGM Resorts lost an estimated $100M to Adjusted Property EBITDAR after attackers social-engineered a help desk into resetting an admin's MFA — not a password breach, an identity-process breach.

Read →
Incident Response for a DeFi Protocol: There's No Wallet to Freeze
Response · 9 min read

Incident Response for a DeFi Protocol: There's No Wallet to Freeze

Incident response for a DeFi protocol exploit: no signing key to revoke, no custodian to call — what the $197M Euler Finance recovery actually took.

Read →
DDoS Protection for a Fintech Payment Platform: The Card-Brand Clock
DDoS · 9 min read

DDoS Protection for a Fintech Payment Platform: The Card-Brand Clock

A fintech payment platform has no fixed regulatory uptime KPI for DDoS — PCI DSS 12.10.1 defers the reporting clock to the card brands' own incident rules instead.

Read →
CVE-2026-20079: root access on your Cisco Firewall Management Center
Response · 6 min read

CVE-2026-20079: root access on your Cisco Firewall Management Center

CVE-2026-20079 is a CVSS 10.0 unauthenticated root RCE in Cisco Secure FMC, now confirmed exploited by a nation-state group and a ransomware operator. What to check in 24 hours.

Read →
DDoS Stress Testing for Web3 Infrastructure: The Failover Path Most Scopes Never Touch
DDoS · 9 min read

DDoS Stress Testing for Web3 Infrastructure: The Failover Path Most Scopes Never Touch

A DDoS stress test that only proves your RPC endpoints stay up misses the failure mode that cost KelpDAO $292M: what happens when the system fails over to a node it shouldn't trust.

Read →
Penetration Testing a Digital Bank: What PSD2's Open Banking Rules Put In Scope
Penetration Testing · 8 min read

Penetration Testing a Digital Bank: What PSD2's Open Banking Rules Put In Scope

Scoping a pentest for a digital bank's PSD2 dedicated interface: the testing-facility deadline, the SLA-parity rule, and the fallback-trigger threshold.

Read →
CVE-2026-19490: auth bypass on your Citrix NetScaler gateway
Response · 5 min read

CVE-2026-19490: auth bypass on your Citrix NetScaler gateway

CVE-2026-19490 is a CVSS 9.3 unauthenticated Citrix NetScaler auth bypass, actively exploited and now on CISA's KEV list. What to check in 24 hours.

Read →
How often should a digital bank run a vulnerability assessment?
Compliance · 7 min read

How often should a digital bank run a vulnerability assessment?

DORA sets a weekly vulnerability-scan floor for critical ICT assets — stricter than PCI's quarterly casino rule or NYDFS's risk-based clock for exchanges.

Read →
Managed SOC for a Digital Bank: What PSD2's Transaction-Monitoring Rule Actually Asks a SOC to Watch
Managed SOC · 8 min read

Managed SOC for a Digital Bank: What PSD2's Transaction-Monitoring Rule Actually Asks a SOC to Watch

PSD2's RTS on strong customer authentication names five risk factors a transaction-monitoring mechanism must catch — two sit in a cybersecurity SOC's scope, three sit with fraud-ops, and most generic SOC coverage was never tuned for either.

Read →
Private Anycast for Web3 Infrastructure: The BGP Hijack DDoS Protection Misses
Infrastructure · 7 min read

Private Anycast for Web3 Infrastructure: The BGP Hijack DDoS Protection Misses

BGP hijacking rerouted KLAYswap and Celer Bridge users to attacker infrastructure in 2022 — a routing risk only the ASN/prefix owner can defend with RPKI.

Read →
Security Hardening for a Digital Bank: When 'Segmented' Isn't 'Severable'
Infrastructure · 8 min read

Security Hardening for a Digital Bank: When 'Segmented' Isn't 'Severable'

DORA Article 9 requires network infrastructure that can be instantly severed or segmented during a live incident — a materially higher bar than the VLAN diagram most 'segmented' banks actually have.

Read →
DDoS Protection for a Crypto Exchange: When the Trading Surge Looks Like the Attack
DDoS · 9 min read

DDoS Protection for a Crypto Exchange: When the Trading Surge Looks Like the Attack

A casino's DDoS traffic is uniform; a bank's is identity-verified. A crypto exchange's legitimate volatility spike can look statistically identical to an attack.

Read →
Incident Response for a Digital Bank: The Payment-Finality Clock
Response · 9 min read

Incident Response for a Digital Bank: The Payment-Finality Clock

Incident response for a digital bank after a confirmed real-time payment fraud: why settlement finality, not encryption, sets the first-minutes clock.

Read →
DDoS Stress Testing Sign-Off for a Digital Bank
DDoS · 8 min read

DDoS Stress Testing Sign-Off for a Digital Bank

Who has to approve an authorized DDoS stress test at a digital bank, and whether it counts toward DORA's testing programme — not TLPT.

Read →
How often should a crypto exchange run a vulnerability assessment?
Penetration Testing · 6 min read

How often should a crypto exchange run a vulnerability assessment?

NYDFS 23 NYCRR 500.5 sets no fixed calendar cadence for vulnerability scans — it makes your own risk assessment the clock. What that means in practice, and what happens when the risk assessment itself is wrong.

Read →
Private Anycast for a Digital Bank: When a Single CDN Becomes a DORA Concentration Risk
Infrastructure · 9 min read

Private Anycast for a Digital Bank: When a Single CDN Becomes a DORA Concentration Risk

DORA's concentration-risk assessment asks whether a critical ICT provider is easily substitutable — for a bank running its entire edge through one CDN, the honest answer is usually no.

Read →
DDoS Protection for Digital Banks: The Uptime-Budget Problem
DDoS · 9 min read

DDoS Protection for Digital Banks: The Uptime-Budget Problem

DDoS protection for banks runs on a different clock than for a casino or crypto exchange — a fixed regulatory uptime budget, not a revenue-per-hour estimate.

Read →
Private Anycast for a Crypto Exchange: When Shared DDoS Protection Isn't Enough
Infrastructure · 8 min read

Private Anycast for a Crypto Exchange: When Shared DDoS Protection Isn't Enough

Shared, multi-tenant Anycast protection queues incident response across every customer on the edge — why that queuing model is a specific risk for a crypto exchange, not a casino.

Read →
Hardening a Fintech Payment Platform: What Comes First
Infrastructure · 8 min read

Hardening a Fintech Payment Platform: What Comes First

Network, API gateway, identity, cloud config, server — five hardening categories for a fintech payment platform, ranked by what PCI DSS and PSD2 gate first.

Read →
Crypto Exchange Breach Response: The First Hours
Response · 9 min read

Crypto Exchange Breach Response: The First Hours

What to do in the first hours of an active crypto exchange hot-wallet compromise: cut the signing path, sweep funds, trace on-chain, screen against OFAC first.

Read →
Ransomware Response for an Online Casino: The First Hours
Response · 9 min read

Ransomware Response for an Online Casino: The First Hours

What a licensed casino or sportsbook should actually do in the first hours of a ransomware incident — isolation, evidence preservation, and the gaming-license notification clock most guides skip.

Read →
Migrating a Live Casino to Private Anycast Without Downtime
Infrastructure · 9 min read

Migrating a Live Casino to Private Anycast Without Downtime

The cutover runbook for moving a live casino's production traffic onto a new private Anycast edge — phased traffic shift, rollback triggers, and what to rehearse before go-live.

Read →
Cloudflare vs AWS Shield vs Akamai for an Online Casino
DDoS · 8 min read

Cloudflare vs AWS Shield vs Akamai for an Online Casino

Cloudflare, AWS Shield, and Akamai lock you into different support models, not just different price tags — here's what actually decides the fit for a casino.

Read →
DDoS Readiness for an Online Casino: A Pre-Peak-Season Audit
DDoS · 8 min read

DDoS Readiness for an Online Casino: A Pre-Peak-Season Audit

A DDoS readiness assessment is a 2-week audit of your architecture, provider config, and runbooks — done before peak season, not after the first outage.

Read →
DDoS Testing Sign-Off: AWS vs Cloudflare
DDoS · 9 min read

DDoS Testing Sign-Off: AWS vs Cloudflare

AWS DDoS testing and Cloudflare DDoS testing are gated by different mechanisms — whose sign-off a crypto exchange needs first, and what to line up first.

Read →
Load testing vs DDoS stress testing
DDoS · 8 min read

Load testing vs DDoS stress testing

Load testing proves a casino platform handles expected traffic; DDoS stress testing proves mitigation holds under attack. Different traffic, different proof.

Read →
Hardening a Crypto Exchange: What Comes First
Infrastructure · 8 min read

Hardening a Crypto Exchange: What Comes First

Identity, cloud config, server, network, application — five hardening categories for a crypto exchange, ranked by what wallet-drainer losses run through.

Read →
Leaked Stripe keys: what to check in 24 hours
Penetration Testing · 8 min read

Leaked Stripe keys: what to check in 24 hours

659 merchants' live Stripe secret keys leaked, exposing 688,000 customer records — not a Stripe breach, but secrets pulled from merchants' own code and logs. What to verify now.

Read →
Cloud Hardening for an Online Casino: What Comes First
Infrastructure · 7 min read

Cloud Hardening for an Online Casino: What Comes First

Server, network, identity, application, cloud config — five hardening categories and only so many change windows. The priority order that actually cuts risk fastest for a casino.

Read →
How often should an online casino run a vulnerability assessment?
Penetration Testing · 6 min read

How often should an online casino run a vulnerability assessment?

Quarterly is the compliance floor, not the answer. The cadence framework for online casinos — regulatory minimums, the AnySec baseline, and the five risk-based triggers that should move a scan off-cycle.

Read →
Scoping an external vulnerability assessment for a casino
Penetration Testing · 6 min read

Scoping an external vulnerability assessment for a casino

What an external vulnerability assessment actually scans on an online casino perimeter, what it structurally cannot prove, and where PCI-DSS ASV scope ends.

Read →
24/7 SOC Coverage Models for a Crypto Exchange
Managed SOC · 7 min read

24/7 SOC Coverage Models for a Crypto Exchange

Co-managed, follow-the-sun, or an in-house night shift — how to pick the staffing model that actually delivers 24/7 SOC coverage for a crypto exchange.

Read →
Scoping a penetration test for a crypto exchange
Penetration Testing · 9 min read

Scoping a penetration test for a crypto exchange

How to scope a penetration test for a crypto exchange: wallet and custody assets, RoE for live production funds, tiers, and what the report covers.

Read →
Black-box vs grey-box vs white-box pentest
Penetration Testing · 9 min read

Black-box vs grey-box vs white-box pentest

Black-box, grey-box (grey box), and white-box penetration testing give a tester different starting knowledge — here's which to request for an online casino, and why.

Read →
CVE-2026-72898: admin takeover via Metabase
Penetration Testing · 8 min read

CVE-2026-72898: admin takeover via Metabase

CVE-2026-72898 is a CVSS 10.0 unauthenticated Metabase SQL injection giving full admin access, already tied to a real breach. What to check in 24 hours.

Read →
SOC vs MDR vs SIEM for iGaming
Managed SOC · 10 min read

SOC vs MDR vs SIEM for iGaming

SOC, MDR, and SIEM are three different operating models, not the same purchase — here is the decision framework and cost drivers for an iGaming platform.

Read →
Casino cashier security testing: the test-case matrix
Penetration Testing · 8 min read

Casino cashier security testing: the test-case matrix

The specific test cases a penetration test of an online casino cashier should cover — deposit, withdrawal, bonus engine, API, and privileged-access — so you can check a vendor's scope before signing.

Read →
Online casino account takeover: what to do now
Managed SOC · 8 min read

Online casino account takeover: what to do now

The signals that confirm an online casino account takeover is happening now, and the first 24 hours a SOC should follow before escalating to incident response.

Read →
Incident response retainers for online casinos
Response · 9 min read

Incident response retainers for online casinos

Incident response retainers for online casinos only beat a cold engagement if onboarding, evidence preservation, and SLA triggers are signed in advance.

Read →
Scoping a penetration test for an online casino
Penetration Testing · 8 min read

Scoping a penetration test for an online casino

How to scope penetration testing for an online casino: what's in the RoE, which assets matter, what drives cost, and what the report contains.

Read →
Managed SOC for iGaming
Managed SOC · 8 min read

Managed SOC for iGaming

Managed SOC for iGaming only works if log sources, detection coverage, and response boundaries are fixed before onboarding, not during the first incident.

Read →
Scoping DDoS stress testing for an online casino
DDoS · 8 min read

Scoping DDoS stress testing for an online casino

DDoS stress testing for an online casino only proves resilience if the RoE, provider coordination, and abort conditions are scoped correctly first.

Read →
Vulnerability assessment vs penetration testing
Penetration Testing · 9 min read

Vulnerability assessment vs penetration testing

Vulnerability assessment vs penetration testing for iGaming: what each one covers, the evidence each produces, and how a casino decides which it truly needs.

Read →
CVE-2026-32194: your SVG uploads may be next
Penetration Testing · 6 min read

CVE-2026-32194: your SVG uploads may be next

Bing Images had a CVSS 9.8 SVG-to-RCE flaw via ImageMagick delegates. If your app processes user-uploaded images server-side, check this today.

Read →
CVE-2026-54121: any AD user can seize your domain
Penetration Testing · 6 min read

CVE-2026-54121: any AD user can seize your domain

CVE-2026-54121 ("Certighost") lets a low-privileged Active Directory user impersonate a Domain Controller and compromise the domain. What to check this week.

Read →
CVE-2026-16232: auth bypass in Check Point console
Response · 6 min read

CVE-2026-16232: auth bypass in Check Point console

CVE-2026-16232 lets an unauthenticated attacker log into Check Point SmartConsole with full admin rights and rewrite firewall policy. Check this in 24 hours.

Read →
How to protect an online casino from DDoS attacks
DDoS · 8 min read

How to protect an online casino from DDoS attacks

A 2026 casino DDoS protection guide: anycast absorption, L7 filtering, origin isolation, and the runbook that keeps sportsbooks and casinos live.

Read →
Credential stuffing against casino cashiers
Casinos · 10 min read

Credential stuffing against casino cashiers

Credential stuffing rarely loses money at login — the loss lands at the cashier. The full attack chain against casino withdrawal flows, and how to break it.

Read →
When your SOC tool is the target: CVE-2026-20253
Managed SOC · 8 min read

When your SOC tool is the target: CVE-2026-20253

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise, now on CISA's KEV list. If your SOC platform is internet-reachable, it's attack surface too.

Read →
The casino cybersecurity threat landscape in 2026
Casinos · 9 min read

The casino cybersecurity threat landscape in 2026

What we've seen actually hitting licensed online casinos this year — bonus abuse, withdrawal fraud, and the slow rise of AI-assisted social engineering.

Read →
Building a SOC for a crypto exchange from scratch
Managed SOC · 10 min read

Building a SOC for a crypto exchange from scratch

Detection rules, alert thresholds, and on-call playbooks for threats unique to a regulated exchange — wallet drainers, custody compromise, address-poisoning.

Read →
NIS2 + DORA without the consultant theatre
Compliance · 11 min read

NIS2 + DORA without the consultant theatre

What EU operators actually need to do to be ready for NIS2 and DORA — control by control, with the time and effort to expect.

Read →
Anatomy of a modern L7 DDoS attack
DDoS · 11 min read

Anatomy of a modern L7 DDoS attack

What we see hitting casino and exchange edges in 2026 — and why provider defaults don't catch it.

Read →
Why we still do pure-manual penetration testing
Penetration Testing · 8 min read

Why we still do pure-manual penetration testing

Automated scanners have improved and PTaaS platforms are everywhere. Here's why our senior engineers test by hand, and what they catch that scanners don't.

Read →
What a real pentest report looks like
Penetration Testing · 9 min read

What a real pentest report looks like

If your last pentest results were a Nessus PDF export, you got scammed. Here's exactly what a real report should contain.

Read →
Building a private Anycast edge from scratch
Infrastructure · 11 min read

Building a private Anycast edge from scratch

Why some of our clients run their own ASN, IP blocks, and edge — the trade-offs vs Cloudflare, and how the math actually works.

Read →

Facing something you'd rather not write about later?

Talk to the engineers behind these write-ups — no sales script, just a straight read on where you stand.

Get a fixed quote