Aug 4-6 · Las VegasCantina is at Black Hat USA · Booth 5200, AI ZoneBook a meeting
Back to Whitepapers
Field ReportAutonomous AppSec

Apex Black Field Report

Autonomous Adversarial Discovery of Web-Application Vulnerabilities at Scale

What 100 days of continuous autonomous adversarial testing revealed across 612 production targets.

Written by Pranamya Keshkamat11 pages
Apex Black Field Report cover PDF · 11 pages
100days of testing
612production targets
4,032reported findings
702high or critical
37.4%of targets affected
99.9%network-reachable
01Abstract

The field report

What autonomous adversarial testing found in production.

Apex Black tested live web applications and APIs, developed attack hypotheses, and checked whether weaknesses could be exploited. Across its first quarter in use, the system produced 4,032 CVSS-scored findings across 612 production targets. The report examines where risk concentrated, which security boundaries failed most often, and what continuous adversarial testing changes for modern security teams.

All target identities, endpoints, and reproduction details are redacted or paraphrased. Aggregate statistics and de-identified case studies only.

02Finding classes

A taxonomy of what breaks

The largest categories were missing-control failures.

Secret exposure, broken authentication, and broken access control accounted for more than half of the classified findings.

Secret and data exposure
843
Broken authentication / session
773
Broken access control
728
Injection / RCE / file write
295
Business logic / abuse
222
CORS / redirect / CSRF
170
SSRF
119
Request / header manipulation
70
XSS / client-side
43
Denial of service
37

One primary class per finding. Approximately 18% did not map to a single displayed category.

03Redacted cases

Selected findings

Six paths from exposed boundary to real impact.

Open a case to review the de-identified mechanism, sector, severity, and disposition.

01Cross-account token theft via web-cache deception7.4 High

A caching flaw served one user's live login token to the next person who opened the same link, with no phishing or user interaction.

AI writing-assistance platformVendor resolved
02Victim-independent account takeover9.1 Critical

HTTP parameter pollution let an attacker reset any account's password without victim participation or a known secret.

European financial-market-infrastructure platform
03Server-side template injection to remote code execution9.9 Critical

A self-service report template became a path to arbitrary command execution on the vendor's servers.

Enterprise reporting and export SaaS
04Mass PII exposure through a leaked live API credential9.3 Critical

A payment API key in public documentation exposed personal records and could initiate payment operations.

Global digital-payments providerVendor resolved
05Unauthenticated remote code execution9.8 Critical

An anonymous document upload escaped a rendering sandbox and became full remote code execution.

Global ride-hailing platformVendor resolved
06Stored cross-user XSS in a real-time message field9.6 Critical

One crafted chat event could execute attacker-controlled code in every other user's authenticated session.

Consumer social-media platform

Method and limits

Read the evidence with its boundaries intact.

The corpus covers authorized web and API bug-bounty targets tested between April 8 and July 17, 2026. It is not a random sample of the internet. Severity and class labels come from Apex Black's process; external vendor review applies only to the six selected cases.

Read the full methodology

Work with us

See what Apex Black finds in your environment.

Find exploitable paths before an attacker does, with continuous testing connected to remediation.

Book a demo