Blog

AppSec Blog

Web Security

Invicti Agentic Pentest: transforming penetration testing with autonomous AI and proof-based DAST

IaC security in CI/CD: Best practices for a secure pipeline

How do you benchmark your DAST coverage against industry standards?

What is the NIST AI RMF? From AI governance principles to security evidence

False positive triage checklist: How to validate findings and reduce AppSec noise

OWASP LLM Top 10 2026: 7,714 incidents analyzed – and the #1 risk almost didn’t make it

AppSec annual planning checklist

Iframe injection payloads: Detection and prevention

How to reduce AppSec alert fatigue and improve signal quality

Security Research

Security Labs

Security issues in vibe-coded web applications: 20,000 apps built and analyzed

Security research in the age of AI tools: Django and Node.js SQL injection analysis

When your AI chatbot does more than chat: The security of tool usage by LLMs

Behind the scenes: How Invicti built the security engine of the future

Next.js middleware authorization bypass vulnerability: Are you vulnerable?

First tokens: The Achilles’ heel of LLMs

Ducks, dinosaurs, and XSS: A little knowledge is a dangerous thing in security

Brainstorm tool release: Optimizing web fuzzing with local LLMs

System prompt exposure: How AI image generators may leak sensitive instructions

Cache bypass techniques for time-based SQL injection

Analyzing WordPress hack access logs with NotebookLM

News

News

Following FBI and EPA warnings, Invicti offers complimentary AppSec support to U.S. water utilities

Invicti DAST leads on coverage and accuracy in independent Miercom benchmark

Latio 2026 Application Security Market Report recognizes Invicti as a leader and innovator

Invicti Security Awarded Best Place to Work Again

Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management

Invicti launches next-gen Application Security Platform with AI-powered DAST

Invicti Security Appoints Kevin Gallagher as President

Invicti Expands App Security Platform with Comprehensive API Security

Invicti Launches First AI-Enabled Predictive Risk Scoring for Application Security Testing

Product Docs & FAQs

Product Docs & FAQs

January 2023 update for Invicti Enterprise on-premises

Invicti improves discovery service and integrations

October 2022 update for Invicti Enterprise on-premises

September 2022 update for Invicti Enterprise On-Demand

Incorporating business logic to get the best out of DAST

August 2022 update for Invicti Enterprise On-Demand

May 2022 update for Invicti Enterprise On-Premises

How Invicti can help with AppSec compliance

Invicti Enterprise achieves WCAG 2.1 accessibility compliance