# appsecco.com > AI-optimized mirror of appsecco.com containing 24 pages totalling 16,322 words of clean markdown content, structured data, and semantic HTML. Original source: https://appsecco.com/. Last updated: 2026-06-15T07:49:58.995Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Security Testing for Products that Ship AI, MCP, and Agents](/content/site-root.html): We test your apps, APIs, cloud infrastructure, MCP servers, AI chatbots, and agents — then deliver findings your engineering team can act on. (1,882 words) ## Articles & Blog Posts - [blog/exploiting-weak-configurations-in-google-identity-platform.html](/content/blog/exploiting-weak-configurations-in-google-identity-platform.html) (1 words) - [blog/exploiting-weak-configurations-in-amazon-cognito-in-aws.html](/content/blog/exploiting-weak-configurations-in-amazon-cognito-in-aws.html) (1 words) - [blog/automating-migration-to-version-2-of-aws-ec2-instance-metada.html](/content/blog/automating-migration-to-version-2-of-aws-ec2-instance-metada.html) (1 words) - [Exploiting IAM security Misconfigurations — Part 2](/content/blog/exploiting-iam-security-misconfigurations-part-2/index.html): Part 2 of the IAM misconfiguration series: exploiting overly permissive CreatePolicyVersion permissions to escalate privileges and gain access to sensitive AWS resources like S3. (790 words) - [A Pentester’s Approach to Kubernetes Security — Part 2](/content/blog/a-pentester-s-approach-to-kubernetes-security-part-2.html): Part 2 of Appsecco's Kubernetes pentest series, focusing on overprivileged RBAC, cloud IAM to Kubernetes mappings, and how attackers escape from cluster to cloud. (1,279 words) - [Identity & Authentication](/content/blog/category/identity-auth/index.html): Broken authentication is consistently in the OWASP Top 10. We cover identity platforms, session management, and auth bypass techniques — including Cognito and Google Identity Platform. (100 words) - [MCP server security testing](/content/ai-security/mcp-pentesting/index.html): Specialized penetration testing for Model Context Protocol servers. We test transport security, tool safety, prompt injection, and OAuth hygiene. (1,362 words) - [Finding SSRF via HTML Injection inside a PDF file on AWS EC2](/content/blog/finding-ssrf-via-html-injection-inside-a-pdf-file-on-aws-ec2.html): How a stored HTML injection vulnerability in a PDF generation feature was escalated to a full SSRF on AWS EC2, enabling access to instance metadata and temporary IAM credentials., We test your apps, APIs, cloud infrastructure, MCP servers, AI chatbots, and agents — then deliver findings your engineering team can act on. (3,206 words) - [Exploiting IAM security Misconfigurations — Part 1](/content/blog/exploiting-iam-security-misconfigurations-part-1/index.html): How attackers exploit AWS IAM misconfigurations — starting with a misconfigured AssumeRole policy — to perform privilege escalation and move laterally through cloud environments. (1,121 words) - [A Pentester’s Approach to Kubernetes Security — Part 1](/content/blog/a-pentester-s-approach-to-kubernetes-security-part-1.html): A practical rundown of the most common Kubernetes misconfigurations found during real pentests, covering network policy gaps, exposed API proxies, and service account privilege issues. (986 words) - [AWS EC2 IMDSv2 versus an esoteric HTTP Method](/content/blog/aws-ec2-imdsv2-versus-an-esoteric-http-method/index.html): An investigation into whether the X-HTTP-Method-Override header can be used to bypass IMDSv2 on AWS EC2 instances — and why the answer is definitively no. (1,135 words) - [Security Research & Insights](/content/blog/index.html): Security research and technical deep dives from the Appsecco team — cloud attacks, Kubernetes security, vulnerability analysis, and AppSec engineering. (822 words) - [Security Testing for AI Systems](/content/ai-security/index.html): MCP server pentesting, LLM integration security, and AI agent assessments. We test the attack surfaces that traditional pentesters don't know exist. (475 words) - [Cloud & AWS Security](/content/blog/category/cloud-security/index.html): AWS misconfigurations are the #1 attack vector we find in product security assessments. These deep dives cover IAM, EC2, Lambda, App Runner, and cloud-native attack paths. (666 words) - [AI agent security testing](/content/ai-security/ai-agent-security/index.html): Security testing for autonomous AI agents. We test tool invocation controls, memory manipulation, and privilege escalation vectors. (820 words) - [Kubernetes Security](/content/blog/category/kubernetes/index.html): Container orchestration expands the attack surface. We test K8s clusters the way real attackers approach them — from RBAC to pod escapes. (218 words) - [LLM Integration Security Testing](/content/ai-security/llm-integration/index.html): Security testing for RAG pipelines, embeddings, fine-tuning, and LLM API integrations. We find the vulnerabilities in your AI stack. (695 words) - [Security testing for products people trust](/content/about/index.html): We help engineering teams identify and fix security issues in their applications, APIs, and cloud infrastructure. 700+ engagements across 150+ organizations over 10+ years. (359 words) - [Vulnerability Analysis](/content/blog/category/vulnerability-analysis/index.html): When critical vulnerabilities emerge, we break them down with technical depth — what happened, how it was exploited, and what you should do about it. (177 words) - [AppSec Engineering](/content/blog/category/appsec-engineering/index.html): Security architecture, authorization patterns, and engineering practices that make products harder to break. (132 words) - [Docker & Container Security](/content/blog/category/container-security/index.html): Containers are only as secure as their configuration. Hardening guides and attack techniques for Docker and container runtimes. (92 words) - [sitemap-index-xml.html](/content/sitemap-index-xml.html) (1 words) - [sitemap-0-xml.html](/content/sitemap-0-xml.html) (1 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives