Raxis

Raxis

Share

Penetration testing, security vulnerability detection, and incident response services to help you meet compliance and stay safe online.

06/17/2026

Many organizations assume that if a security tool is detected, the threat is stopped.

But detection isn't always that simple.

In the latest post in Raxis blog, Lead Pe*******on Tester Jason Taylor walks through a practical example of building a security tool from source code and explores why some endpoint security products detect known tools immediately while others focus on behavior instead.

The result is an interesting look at how modern defenses identify threats, where those defenses can be challenged, and why realistic security testing matters.

Read the full blog: https://raxis.com/blog/building-security-tools-from-source-to-bypass-endpoint-security/

*******onTesting

06/11/2026

At some point, every security program runs into the same limitation:
It’s built around periodic validation in an environment that no longer operates that way.

The question isn’t whether testing is happening.
It’s whether it’s happening often enough to keep up.

Raxis Attack changes that model by embedding testing into the lifecycle of your environment - so validation doesn’t lag behind change.

Raxis Attack gives you continuous, on-demand testing, real-time findings, direct access to your tester, and unlimited remediation verification - so security validation keeps pace with how your organization actually operates.

At that point, the question isn’t whether you should test.

It’s whether your current model is enough.

🔗 Contact Raxis today → raxis.com

06/09/2026

Salesforce touches everything - permissions, APIs, integrations, custom code.

That means attackers have plenty of entry points.

Our Salesforce Pe*******on Testing covers it all, from overprivileged users to insecure Lightning components.

When’s the last time your Salesforce setup was tested like a real attack?

🔗 Explore our full approach: raxis.com

06/05/2026

Not every environment needs continuous testing.

But every environment that changes frequently needs more than a single validation point.

That's where the distinction between Raxis Strike and Raxis Attack matters.

Raxis Strike is built for focused, point-in-time assessments - ideal for pre-launch validation, targeted testing, annual requirements, and organizations that need a snapshot of risk at a specific moment.

Raxis Attack is built for environments that keep evolving. It provides continuous, expert-led testing, real-time findings, unlimited retesting, and audit-ready reporting that supports compliance efforts across major frameworks.

Same team. Same methodology. Same hands-on testing depth.

The difference isn't quality. It's whether your security validation happens once - or keeps pace with change.

🔗 Talk to Raxis about the right approach → raxis.com

*******onTesting

06/04/2026

🚨 Raxis vulnerability research → officially assigned CVE-2026-36748

During a routine pe*******on test, Raxis' Jason Taylor discovered a high-severity XSS vulnerability in Rock RMS that could allow a standard user to escalate privileges to administrator access.

What started as a routine finding turned into a full privilege escalation path with a CVSS score of 9.0.

Today's write-up covers:
- How the vulnerability works
- The privilege escalation
- Affected versions
- Mitigation guidance
- Full disclosure timeline

This is exactly why real-world pe*******on testing matters. Vulnerabilities that appear “minor” on the surface can quickly become critical when chained together by experienced testers.

Read the full breakdown from Jason, https://raxis.com/blog/cve-2026-36748-xss-in-rock-rms-leads-to-privilege-escalation/

*******onTesting

Want your business to be the top-listed Business in Atlanta?
Click here to claim your Sponsored Listing.

Address


2870 Peachtree Road #915-8924
Atlanta, GA
30305