Raxis Penetration testing, security vulnerability detection, and incident response services to help you meet compliance and stay safe online.

Raxis provides penetration testing, security products, and risk assessments to help keep your organization as secure as possible.

Many organizations assume that if a security tool is detected, the threat is stopped.But detection isn't always that sim...
06/17/2026

Many organizations assume that if a security tool is detected, the threat is stopped.

But detection isn't always that simple.

In the latest post in Raxis blog, Lead Pe*******on Tester Jason Taylor walks through a practical example of building a security tool from source code and explores why some endpoint security products detect known tools immediately while others focus on behavior instead.

The result is an interesting look at how modern defenses identify threats, where those defenses can be challenged, and why realistic security testing matters.

Read the full blog: https://raxis.com/blog/building-security-tools-from-source-to-bypass-endpoint-security/

*******onTesting

The games have started. So have the scams.Fraudsters have spent months preparing for this moment, launching fake ticket ...
06/16/2026

The games have started. So have the scams.

Fraudsters have spent months preparing for this moment, launching fake ticket sites, spoofed merchandise stores, phishing campaigns, fake job listings, and even malware-laced streaming platforms designed to capitalize on event fever.

In Raxis' latest blog, Brian Tant breaks down the fraud ecosystem operating behind the scenes of major sporting events and what organizations should be watching for as employees travel, shop, stream, and engage with the tournament.

Read the full analysis - https://raxis.com/blog/the-game-is-starting-release-the-fraudsters/

Transportation infrastructure is high-stakes, high-visibility, and high-risk.Organizations choose Raxis because we speci...
06/12/2026

Transportation infrastructure is high-stakes, high-visibility, and high-risk.

Organizations choose Raxis because we specialize in pe*******on testing that reflects real-world attacker behavior across transportation systems - ground, water, air, OT, and IoT.

We don’t rely on surface-level scans.
We don’t generalize from other industries.

We test transportation systems with domain-specific expertise - not recycled methods from other industries.

When systems move people and goods, testing must be done right.
🔗 Talk to the experts: raxis.com

*******onTesting

At some point, every security program runs into the same limitation:It’s built around periodic validation in an environm...
06/11/2026

At some point, every security program runs into the same limitation:
It’s built around periodic validation in an environment that no longer operates that way.

The question isn’t whether testing is happening.
It’s whether it’s happening often enough to keep up.

Raxis Attack changes that model by embedding testing into the lifecycle of your environment - so validation doesn’t lag behind change.

Raxis Attack gives you continuous, on-demand testing, real-time findings, direct access to your tester, and unlimited remediation verification - so security validation keeps pace with how your organization actually operates.

At that point, the question isn’t whether you should test.

It’s whether your current model is enough.

🔗 Contact Raxis today → raxis.com

Because experience matters more than automation.Raxis' team is a mix of security engineers, developers, ethical hackers ...
06/11/2026

Because experience matters more than automation.

Raxis' team is a mix of security engineers, developers, ethical hackers - and some unexpected backgrounds too.

We’ve got race car drivers, farmers, radio hobbyists, and even former help-desk pros.

Different skills, one obsession: finding what others miss.

That diversity makes us not just testers - but problem solvers.
🔗 See why organizations trust Raxis → raxis.com

*******onTesting

Regulators are asking a new question: "How did you prove it?"Frameworks like PCI DSS 4.0, GLBA, and HIPAA now require pr...
06/09/2026

Regulators are asking a new question: "How did you prove it?"

Frameworks like PCI DSS 4.0, GLBA, and HIPAA now require proof that your security controls can survive real-world attacks - not just that they exist.

Raxis delivers that proof.

Our pe*******on testing validates the same attack paths hackers use - SQL injection, XSS, authentication flaws, lateral movement - and maps every result directly to your required controls.

What you gain:
- Fewer audit surprises
- Clarity on real risks
- Confidence in front of regulators and boards

Elevate from “documented” to *demonstrated* security → raxis.com

Salesforce touches everything - permissions, APIs, integrations, custom code.That means attackers have plenty of entry p...
06/09/2026

Salesforce touches everything - permissions, APIs, integrations, custom code.

That means attackers have plenty of entry points.

Our Salesforce Pe*******on Testing covers it all, from overprivileged users to insecure Lightning components.

When’s the last time your Salesforce setup was tested like a real attack?

🔗 Explore our full approach: raxis.com

What is a pe*******on test, really?A real pentest is a deliberate, controlled cyberattack performed by ethical hackers u...
06/05/2026

What is a pe*******on test, really?

A real pentest is a deliberate, controlled cyberattack performed by ethical hackers using the same tools and techniques as real attackers.

The goal isn’t just to “find vulnerabilities.”
It’s to show how those vulnerabilities could actually be exploited inside your environment.

At Raxis, our testers successfully breach systems in roughly 85% of engagements - not to create fear, but to provide organizations with a realistic understanding of where risk exists and how attackers think.

That includes demonstrating potential business impact through controlled exploitation and proof-of-concept access to sensitive systems or data.

A quality pe*******on test should leave you with more than a report.
It should leave you with clarity.

🔗 Learn what separates real pe*******on testing from surface-level scanning → raxis.com

*******onTesting

Raxis delivers manual, human-led pe*******on testing services and red team engagements. Senior testers find what automated scans miss. Atlanta-based.

Not every environment needs continuous testing.But every environment that changes frequently needs more than a single va...
06/05/2026

Not every environment needs continuous testing.

But every environment that changes frequently needs more than a single validation point.

That's where the distinction between Raxis Strike and Raxis Attack matters.

Raxis Strike is built for focused, point-in-time assessments - ideal for pre-launch validation, targeted testing, annual requirements, and organizations that need a snapshot of risk at a specific moment.

Raxis Attack is built for environments that keep evolving. It provides continuous, expert-led testing, real-time findings, unlimited retesting, and audit-ready reporting that supports compliance efforts across major frameworks.

Same team. Same methodology. Same hands-on testing depth.

The difference isn't quality. It's whether your security validation happens once - or keeps pace with change.

🔗 Talk to Raxis about the right approach → raxis.com

*******onTesting

🚨 Raxis vulnerability research → officially assigned CVE-2026-36748During a routine pe*******on test, Raxis' Jason Taylo...
06/04/2026

🚨 Raxis vulnerability research → officially assigned CVE-2026-36748

During a routine pe*******on test, Raxis' Jason Taylor discovered a high-severity XSS vulnerability in Rock RMS that could allow a standard user to escalate privileges to administrator access.

What started as a routine finding turned into a full privilege escalation path with a CVSS score of 9.0.

Today's write-up covers:
- How the vulnerability works
- The privilege escalation
- Affected versions
- Mitigation guidance
- Full disclosure timeline

This is exactly why real-world pe*******on testing matters. Vulnerabilities that appear “minor” on the surface can quickly become critical when chained together by experienced testers.

Read the full breakdown from Jason, https://raxis.com/blog/cve-2026-36748-xss-in-rock-rms-leads-to-privilege-escalation/

*******onTesting

Address

2870 Peachtree Road #915-8924
Atlanta, GA
30305

Alerts

Be the first to know and let us send you an email when Raxis posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share