Cybersecurity professional & pentester | Associate Director @ CaptureTheBug | Securing web, APIs & networks one vulnerability at a time.
Payment APIs fail differently than standard APIs. Scanners miss the attacks that cost money. Here is exactly how Capture The Bug tests for transaction manipulation, IDOR, and race conditions.
An RCE vulnerability does not announce itself. It gives an attacker code execution on your systems with no credentials required. Here is exactly how that becomes a business crisis in under 30 minutes.
ASD's ACSC issued a High Alert on August 19 confirming active exploitation of N-able N-central vulnerabilities in Australia. Here is what MSPs and enterprise IT teams need to do right now.
Most pentest findings sit in a PDF until someone reads them. Capture The Bug integrates with Slack, GitHub, Jira, and Microsoft Teams so findings reach the right engineers the moment they are confirmed.
When you share security findings with a pentest provider, the platform holding that data needs to be secured properly. Here is how Capture The Bug uses TOTP authentication to protect every account.
Financial services is the second most expensive sector to breach globally. Here is what the 2026 data says about how banks and insurers in NZ, AU, and the USA are actually testing their security.
Capture The Bug CEO Ankita Dhakar has been named one of 16 finalists for the 2026 EY Entrepreneur Of The Year New Zealand award, recognising her work building a cybersecurity platform from Aotearoa.
Before attackers exploit a vulnerability, they find it. Here is exactly how they discover unpatched assets across cloud and SaaS environments, and what that means for your security posture.
34% of ANZ organisations paid a ransom in 2026. Most regretted it. The real reason was not fear of attackers. It was not knowing if their backups would actually work when needed.
Attackers don't need zero-days. They rely on known flaws your team already found but hasn't fixed. Here's the real reason the patch gap keeps growing and what to do about it.
The report sitting in that folder is not your security posture. It is a photograph of it, taken on one day, already fading.
The most significant shift in security testing right now is not what gets tested. It is when and how fast a qualified expert can start.
The question is not whether to use fast testing tools or experienced testers. The question is whether you can afford to present unverified findings to your auditor, your board, or your enterprise customer.
An annual penetration test tells you what your security looked like on one day. A continuous offensive security programme tells you what it looks like right now, and keeps that answer current all year.
Most payment businesses in New Zealand and Australia know they need quarterly ASV scans. Far fewer understand what happens when that scan fails, or why passing it once is not the same as staying compliant.
What auditors actually want from your penetration test, and why the report you have today may not be enough to close the deal or pass the audit.
What looks like financial control often turns out to be the most expensive security decision a growing ANZ company makes.
A full year between tests is not a security strategy. Here is what that gap actually costs New Zealand, Australian, and Pacific businesses, and why more teams are choosing continuous coverage.
A clear, no-spin look at what penetration testing really costs New Zealand and Australian SaaS teams in 2026, and how to turn every dollar of that budget into security you can actually show customers.
The Privacy Act 2020 does not require penetration testing. It requires reasonable security safeguards, and the difference between those two statements is where most New Zealand CTOs get their risk assessment wrong.
Neither SOC 2 nor ISO 27001 names penetration testing as a mandatory line item. Both expect ongoing vulnerability management, and that distinction determines what evidence actually satisfies an auditor.
The New Zealand market for security testing has changed significantly heading into 2026, and most buyers are still using a framework built for a different era. Here is what actually matters now.
Six months of continuous testing across 100 SaaS products in New Zealand and Australia turned up five patterns that rarely make it into a typical security blog post, but kept showing up anyway.
Thirty New Zealand CTOs were asked one blunt question about their last pentest vendor. The same five complaints came up again and again, and almost none of them were about security skill.
A buried code review comment cost one New Zealand startup over $200,000. The fix would have taken two hours and a fraction of the budget, if anyone had run it in time.
Learn what to do after a penetration test. Capture The Bug walks through triage, remediation, verification, and re-testing to help your team close vulnerabilities for good.
Flexible, scalable PTaaS for modern product teams.