Apex Black Field Report
Autonomous Adversarial Discovery of Web-Application Vulnerabilities at Scale
What 100 days of continuous autonomous adversarial testing revealed across 612 production targets.
PDF · 11 pagesThe field report
What autonomous adversarial testing found in production.
Apex Black tested live web applications and APIs, developed attack hypotheses, and checked whether weaknesses could be exploited. Across its first quarter in use, the system produced 4,032 CVSS-scored findings across 612 production targets. The report examines where risk concentrated, which security boundaries failed most often, and what continuous adversarial testing changes for modern security teams.
All target identities, endpoints, and reproduction details are redacted or paraphrased. Aggregate statistics and de-identified case studies only.
A taxonomy of what breaks
The largest categories were missing-control failures.
Secret exposure, broken authentication, and broken access control accounted for more than half of the classified findings.
One primary class per finding. Approximately 18% did not map to a single displayed category.
Selected findings
Six paths from exposed boundary to real impact.
Open a case to review the de-identified mechanism, sector, severity, and disposition.
01Cross-account token theft via web-cache deception7.4 High
A caching flaw served one user's live login token to the next person who opened the same link, with no phishing or user interaction.
02Victim-independent account takeover9.1 Critical
HTTP parameter pollution let an attacker reset any account's password without victim participation or a known secret.
03Server-side template injection to remote code execution9.9 Critical
A self-service report template became a path to arbitrary command execution on the vendor's servers.
04Mass PII exposure through a leaked live API credential9.3 Critical
A payment API key in public documentation exposed personal records and could initiate payment operations.
05Unauthenticated remote code execution9.8 Critical
An anonymous document upload escaped a rendering sandbox and became full remote code execution.
06Stored cross-user XSS in a real-time message field9.6 Critical
One crafted chat event could execute attacker-controlled code in every other user's authenticated session.
Method and limits
Read the evidence with its boundaries intact.
The corpus covers authorized web and API bug-bounty targets tested between April 8 and July 17, 2026. It is not a random sample of the internet. Severity and class labels come from Apex Black's process; external vendor review applies only to the six selected cases.
Read the full methodologyWork with us
See what Apex Black finds in your environment.
Find exploitable paths before an attacker does, with continuous testing connected to remediation.