The Style Attribute Is Your Sanitizer's Blind Spot
A field guide to finding CSS-based page hijacks in HTML sanitizers.
Penetration testing that finds what automated scans miss across web applications, cloud environments, internal networks, and identity systems.
Focused engagements that show where your organization is exposed, what matters most, and how to fix it.
Test the paths an attacker could use to reach your network, identity systems, and critical internal assets.
Best for: Internal networks, remote access, and identity infrastructure.
Uncover business-logic flaws, hidden API risk, and application weaknesses that automated testing often misses.
Best for: Customer-facing applications, portals, and APIs.
Validate cloud identity, configuration, and workload controls before a small gap becomes broad access.
Best for: AWS, Azure, and GCP environments.
Turn technical risk into an actionable security roadmap for leadership, engineering, and operations.
Best for: Security decisions, program direction, and readiness.
Not sure which assessment fits? Request an Assessment Plan →
Senior security practitioners who bring an attacker's curiosity and a defender's responsibility to every engagement.
Josh (“j3tj3rk”) transitioned from law to technology over a decade ago, starting on a small MSP help desk before discovering his passion for offensive security. He has spent the last 7 years consulting for Fortune 500 companies in roles including Network Pentester, Web App Consultant, and Red Team Lead. Josh's team won the 2022 WWHF CTF, and his expertise is backed by Security+, eJPT, CRT, and CISSP certifications. Outside of work, he enjoys hiking, surfing, and eating Al Pastor tacos in Southern California, where he lives, with his wife and their dog, Bruce Wayne.
Nic (“Sav4j”) got his start in technology seven years ago in general IT for the educational system, where he discovered his passion for offensive security. What began as curiosity quickly became an obsession with understanding how systems work, how they fail, and how they can be secured. He spent several years as a Red Team Operator before transitioning into an Offensive Security Engineer role at a SaaS company, with particular interests in web application security, reverse engineering, malware analysis, and binary exploitation. Before entering technology, Nic spent a decade in the United States Navy as a Corpsman and later several years as a police officer. Across each of his careers, he has been driven by a desire to help others, a mindset he now brings to cybersecurity. Outside of work, Nic enjoys reading, camping, and fishing with his two dogs.
Independent research that shows how we investigate real attack paths and why the findings matter to defenders.
A field guide to finding CSS-based page hijacks in HTML sanitizers.
How zero-byte file creations can bypass content-focused removable-media telemetry.
CAPTCHA bypass, phishing relay, and blind SSRF from one unauthenticated endpoint.
How an unauthenticated file-serving endpoint exposed candidate documents.
A technical breakdown of the architectural risks behind the current OWASP Top 10.
Systemic architectural vulnerabilities in multi-tenant SaaS deployments.
How client-side filtering and missing server-side auth checks allowed a standard account to harvest org-wide data.
How a multi-hop redirect chain, automated scanner evasion, and a live operator combined to harvest card data and PII
Security work designed to help people make decisions, not just satisfy a checkbox.
We verify findings manually and explain the realistic impact, so your team can focus on the issues that deserve attention.
Prioritized, developer-friendly guidance gives your team a useful path forward after the assessment.
We follow the routes a capable attacker would explore, including identity, business logic, cloud, and trust boundaries.
A straightforward process that gives leaders clarity and gives technical teams a useful path forward.
We start with your priorities, environment, and concerns to define a focused engagement that fits the decision you need to make.
We combine automation with hands-on validation to distinguish meaningful exposure from noise and false positives.
We walk through the results with your team and align on the next steps.
Tell us about your environment and the decision in front of you. We’ll help identify the appropriate assessment scope.
Request an Assessment PlanPrefer to email us directly? info@bulkheadsec.com
Feedback from security leaders who needed more than a compliance checklist.
"Bulkhead Security uncovered structural flaws within our Active Directory deployment that previous compliance-driven audits missed entirely."
"Their Web App Penetration Testing team provided exceptional business-logic exploitation analysis prior to our core enterprise platform launch."