SilentGrid / Research

What the work turns up.

Consultants publish what comes out of the work: control bypasses, exploitation write-ups, OT and ICS findings, and the reasoning behind how we scope an engagement.

2026 14

The New OWASP LLM Top 10 Isn’t a Pentest Checklist

OWASP released the 2026 edition of its Top 10 for LLM Applications in August. There are some notable changes in the ranking, but from a penetration testing perspective, the bigger change is what sits behind the model now.

Richard Tan AI/LLM

Handala Hack and Friends

On the 11th of March 2026, the Iranian aligned Handala Hack (Handala) group claimed responsibility for a disruptive cyberattack which affected the medical multinational corporation, Stryker.

Marc Sleeman Red teaming

Cracking the Locker

During one of our red team engagements late last year, we were given a challenge: Once inside the building, could we access employee lockers? At first glance, this didn’t sound too exciting.

Richard Tan

Help Us, Help You.

Maximising Value in Offensive Security Assessments: Why More Information Leads to Better Results When organisations engage offensive security firms like SilentGrid for adversary simulation or penetration testing, a common assumption…

Richard Appleby

Showing the most recent 15 articles. Browse the full archive

Stay across it

New research, when we publish it.

Occasional notes on what we are finding. No newsletter cadence to keep up with, and you can unsubscribe from any email.

Already subscribed? Manage your subscription, or sign up on the blog instead.