Find the latest Webinar content from the Sprocket Testing Team.

Shield check icon Security Research

From Threat Volume to Real-World Exposure: What the 2025 Comcast Cybersecurity Threat Report Tells Us

From Threat Volume to Real-World Exposure: What the 2025 Comcast Cybersecurity Threat Report Tells Us

Comcast Business Cybersecurity Threat Report analyzed events, revealing how attackers are shifting tactics and accelerating the pace at which exposures become exploitable. We will expand on four of the threats that keep showing up in breach postmortems, how they work in reality, and what organizations should do about them.
Weird Ways to DA

Weird Ways to DA

Sprocket Security's Director of Technical Operations reveals how Domain Admin access was gained through overlooked misconfigurations and intricate attack paths, with both insight and humor.
Lost in Transliteration: Hidden Passwords in a Multilingual World

Lost in Transliteration: Hidden Passwords in a Multilingual World

Sprocket Security Senior Penetration Tester examines how transliteration and language backgrounds shape password creation, adding complexity for both users and attackers in his 2025 CypherCon talk.
A Primer on Insecure Reflection Practices in Java and C# Applications

A Primer on Insecure Reflection Practices in Java and C# Applications

Explore common pitfalls in Java and C# reflection practices—understand how insecure use of reflection can expose applications to vulnerabilities like code injection, unauthorized access, and bypassed security controls, and learn key strategies to harden your code.
CVE ALERT (CVE-2025-44043 & CVE-2025-44044) - The Search Bar Hacks Aren't Dead Yet

CVE ALERT (CVE-2025-44043 & CVE-2025-44044) - The Search Bar Hacks Aren't Dead Yet

Explore how Sprocket Security uncovered chained vulnerabilities and learn how overlooked parameters led to serious security risks.
What It Really Means to Be a Hacker: Lessons from 10 Years in Offensive Security

What It Really Means to Be a Hacker: Lessons from 10 Years in Offensive Security

What being a hacker really means—no title required. After a decade in offensive security, Nate Fair shares honest lessons on hacking.
A Vulnerability Hunter's View of Next.js (CVE-2025-29927) Exploit Validation

A Vulnerability Hunter's View of Next.js (CVE-2025-29927) Exploit Validation

Explore a security expert's take on validating the Next.js CVE-2025-29927 exploit, its impact, and techniques for assessing and mitigating the risk.
Recent InfoSec Talks, Defcon 32 Demo Labs - Farming n-days with GreyNoise

Recent InfoSec Talks, Defcon 32 Demo Labs - Farming n-days with GreyNoise

In this series the service delivery team writes about an outstanding talk they saw at a conference and implementing those lessons at scale.

Your Always-On Security Engine

Our team utilizes a custom blend of methodologies from the best penetration testing standards.

Testing Lab Logos
Casey Cammilleri

As an offensive security team, we are committed to providing a world-class capability that blends more seamlessly with your larger operations. While there’s always more work to do, we pride ourselves on our commitment to the continuous model, and expanded risk intelligence it can provide to our customers. If you’re locked into a contract, but are curious to know what this band of practitioners can do, consider engaging us for our Red Team Events.

Casey Cammilleri
Founder & CEO
Eye icon

Webcasts

Explore our collection of webcasts to stay informed and inspired.

Jun 16, 2026
AI agents can accelerate testing, but they don’t eliminate the need for human judgment. Watch our discussion on accountability, oversight, and what it really takes to build trustworthy agentic pentesting.
Watch Play icon
Apr 06, 2026
AI tools are moving fast, but are they secure? Hear real-world pentest findings on shadow AI, prompt injection, and overpermissioned integrations, along with practical guidance for securing enterprise AI.
Watch Play icon
Nov 05, 2025
No slides. No sales pitches. Just real talk about how security leaders evaluate, select, and justify security solutions.
Watch Play icon
Oct 23, 2025
No slides. No sales pitches. Just real talk about how security leaders evaluate, select, and justify security solutions.
Watch Play icon
Aug 22, 2025
Join Sprocket's Team as they expose real techniques used to bypass security tools and learn what this means for validating security tools before you buy.
Watch Play icon
Jul 24, 2025
Penetration testing remains a core pillar of cybersecurity, but not all tests are created equal. This webinar with Sprocket Security and ISC2 recorded on July 24, 2025 explores 5 types ...
Watch Play icon
Jun 24, 2025
Black Hat and DEFCON (affectionately dubbed Hacker Summer Camp) is right around the corner! Join us as "hackers" everywhere gear up for one of the most anticipated events of the ...
Watch Play icon
Apr 04, 2025
On this episode of Pentesters Chat, our team explored offensive security engagements.
Watch Play icon
Apr 03, 2025
Whether you're just starting to explore ASM or are looking to refine your existing strategy, this webinar will provide valuable insights and actionable advice to strengthen your organization’s security posture.
Watch Play icon
Mar 07, 2025
The Sprocket testing team discusses Single Sign On (SSO).
Watch Play icon
Jan 31, 2025
The Sprocket testing team discusses Attack Surface Management.
Watch Play icon
Dec 06, 2024
The Sprocket testing team discusses Password Protected Systems.
Watch Play icon