
Mario Luckeneder
Mario Luckeneder is the founder of Ceron, a security company based in Scottsdale, Arizona. He writes about application security, AI threats, identity, cloud risk, and security assessments.
About Mario and CeronArticles by Mario Luckeneder
82 articles- AI & security
AI Security Evaluations Need Different Questions From Accuracy Tests
Design AI release checks that distinguish answer quality from unauthorized access, unsafe actions, and failures of business controls.
- Security operations
Detecting Outdated Answers in a Security Questionnaire Library
Connect reusable security answers to system changes, evidence versions, review triggers, and correction records before stale statements are reused.
- Software supply chain
Browser Extensions Belong in the SaaS Access Inventory
Assess extension permissions, business use, update ownership, and access to sensitive browser pages alongside ordinary SaaS integrations.
- Cloud & application security
URL Import Features Give the Server a New Network Request
Review redirects, DNS resolution, destination rules, and response limits when applications fetch links supplied by users or AI tools.
- Identity & access
Vendor Access Reviews Need More Than an MFA Checkbox
Examine authentication methods, fallback paths, privilege, and session behavior for external administrators and support providers.
- AI & security
Knowledge Base Poisoning: Checking the Sources Behind an AI Answer
Examine how document ownership, ingestion, version history, and source verification affect the integrity of answers from a company knowledge base.
- Security operations
security.txt Makes a Reporting Channel Discoverable. The Channel Still Needs an Owner.
Connect a discoverable security contact to report intake, triage, scope, acknowledgments, and a maintained vulnerability disclosure process.
- Security testing
A Critical CVE Affects Your Technology Stack. Do You Need a Security Assessment?
A CVE with a 9-plus CVSS score lands in your inbox, a vendor's security page turns red, and five different people in Slack ask the same question in five different ways: are we affected?
- Software supply chain
Private Package Names Need Explicit Registry Rules
Review package scopes, registry routing, lockfiles, and install behavior to prevent private dependencies resolving from unintended sources.
- Cloud & application security
File Upload Security Continues After the Upload Finishes
Trace uploaded files through validation, storage, scanning, previews, downloads, and deletion to review the full processing path.
- Security testing
How to Check If Your Website Is Secure: A Practical Guide
Most website security problems aren't hidden.
- Security testing
Missing Security Headers: What They Mean and How to Fix Them
A missing security header rarely takes more than one line to fix.
- Security testing
What Can Hackers Learn About Your Company From Its Domain?
Before an attacker ever touches a login form or tries a single exploit, they've usually already learned a lot about your company just from your domain name.
- Security testing
Does HTTPS Mean Your Website Is Secure?
The padlock icon in a browser's address bar has become shorthand for safe.
- Security testing
Website Security Scan Results Explained: What's Actually Dangerous?
Run any website security scan and you'll get a list back. Some of it will look alarming.
- Security testing
How to Choose a Security Assessment Provider: 10 Questions to Ask Before Hiring
Security assessment providers all sound similar on a sales call.
- Identity & access
SSO Domain Claims: Proving Which Company Controls a Workspace
Review domain verification, tenant selection, account linking, and ownership changes in enterprise single sign-on onboarding.
- AI & security
A Model Download Is Part of the Software Supply Chain
Review model files, loading code, dependencies, and artifact provenance before introducing a downloaded model into business infrastructure.
- Security operations
Remediation Metrics: Measure Verified Closure as Well as Ticket Speed
Distinguish discovery, engineering completion, deployment, retesting, and accepted exceptions when reporting vulnerability remediation.
- AI & security
OpenAI vs Open Source: Hacking of HuggingFace
None of the traditional lines of defense move at the speed of an agent swarm coordinating over its own private channel.
- Software supply chain
Self-Hosted CI Runners Extend the Build’s Access Into Your Network
Review persistent state, network reachability, credentials, and job isolation when builds run on company-managed CI infrastructure.
- Cloud & application security
Webhook Security Includes What Happens When the Same Event Arrives Twice
Separate sender verification, replay checks, duplicate handling, and business-state validation in webhook consumers.
- Security testing
Switching IT Providers? Why Your Company Should Consider a Security Assessment During the Handover
The contract with your old IT provider ends on a Friday. The new provider starts Monday.
- Security testing
Security Assessments for SaaS Integrations: What to Test Before Connecting Customer Accounts
Between August 8 and August 18, 2025, attackers used stolen OAuth tokens from a single third-party chat integration to pull data out of more than 700 Salesforce environments, plus a subset of connected Google Workspace inboxes.
- Security testing
No Findings, No Fee Security Assessments: How Does Outcome-Based Pricing Work?
Most security assessment providers get paid the same amount whether they find a critical vulnerability or nothing at all.
- Security testing
Bug Bounty Programs vs. Security Assessments: What Should Businesses Pay For?
Two CTOs can spend the same security budget on completely different things and end up with completely different answers to the same question: what's actually wrong with our systems.
- Security testing
Customer Portal Security Assessments: Protecting the Systems Your Clients Log Into
Every SaaS product eventually earns a login screen that matters more than the rest of the site combined.
- Security testing
Security Assessments After Cloud Migration: What Needs to Be Revalidated?
A cloud migration doesn't move your security posture along with your data. It resets it.
- Security testing
Security Due Diligence Before Fundraising: What Should Startups Have Ready?
Investors used to evaluate a startup on three things: the team, the market, and the traction.
- Security testing
Vibe Coding Security: What to Audit Before Deploying an AI-Built Application
You can describe an entire SaaS product in a chat window and have a working, deployed application within a weekend.
- Security testing
Multi-Domain Security Assessments: How to Identify and Scope Every Public-Facing Asset
Ask most companies how many domains and subdomains they operate, and the number they give you is almost always wrong, not because anyone is lying, but because nobody has actually looked.
- Security testing
Your Web Agency Just Delivered Your Website. Who's Responsible for Security?
The website is done. The agency sends the final invoice, you make the last payment, and the project moves into "launched" status.
- Security testing
E-commerce Security Assessments: What to Check Before Peak Sales
Attackers don't wait for Black Friday to start planning for it.
- Security testing
Cybersecurity Due Diligence for Acquisitions: What to Assess Before Buying a Company
Buying a company means buying its data, its infrastructure, and every unresolved vulnerability sitting inside it, whether anyone disclosed those vulnerabilities or not.
- Security testing
Security Assessment Retesting: How to Verify Vulnerabilities Have Actually Been Fixed
A vulnerability assessment report tells you what's broken.
- Security testing
Web Application vs. Infrastructure Security Assessments: Which One Do You Need?
Security assessment gets treated as one product on most sales pages, but web application testing and infrastructure testing check fundamentally different layers of your environment, using different methodology, finding different categories of risk.
- Security testing
Vulnerability Assessment for Startups: Your Enterprise Customer Requested a Security Assessment. What Happens Next?
An enterprise prospect's security team sends over a questionnaire, or a one-line email asking for your latest penetration test report, and the deal that was moving through your pipeline suddenly stalls on a document you don't have.
- Security testing
Vulnerability Assessment for Startups: What to Test Before Launching
Pre-launch is the cheapest point in your company's life to find a security problem, and the most expensive point to skip looking for one.
- Security testing
Website Security Audit for Businesses: What Gets Checked and What You'll Receive
A website security audit means something specific: a scoped engagement where your web applications, APIs, cloud infrastructure, and access controls get tested against real exploitation techniques, not just matched against a list of known software versions.
- Security testing
Automated vs. Manual Vulnerability Assessments: Which Does Your Business Need?
The old framing was simple: automated vulnerability scanning was fast and shallow, manual penetration testing was slow and thorough, and businesses picked one or budgeted for both.
- Security testing
How Often Should Your Company Conduct a Security Assessment?
The right cadence depends on compliance obligations, how fast your attack surface changes, and what happens between assessments if something new gets exposed and nobody catches it.
- Security testing
What Is an External Security Assessment? A Guide for Businesses
An external security assessment tests your organization the way an actual attacker sees it: from outside your network, with no privileged access, using only what's publicly reachable.
- AI & security
AI Security Assessments: How They Work, What They Find, and Their Limitations
Security testing has run on the same basic model for two decades: automated scanners flag known issues, and human testers manually dig for what the scanners miss.
- Security testing
How Much Does a Security Assessment Cost in 2026?
Security assessment pricing spans an enormous range in 2026, anywhere from a few hundred dollars for an automated scan subscription to well into the six figures for a full penetration test across a complex enterprise environment.
- Security testing
Vulnerability Assessment vs. Penetration Testing: What's the Difference?
Compliance frameworks like SOC 2 and PCI DSS often require both a vulnerability assessment and a penetration test, but plenty of security budgets get spent on one when the mandate actually called for the other.
- Identity & access
SCIM Offboarding: Verify the Access Change Behind the Directory Update
Follow deprovisioning from the identity provider to SaaS roles, active sessions, API credentials, and scheduled work.
- AI & security
AI Prompt Logs: Where Business Data Goes After the Answer
Trace prompts, responses, and retrieved documents across AI logs to define retention, access, and evidence collection for business data.
- Security operations
CVSS, EPSS, and KEV Answer Different Vulnerability Questions
Combine severity, predicted exploitation, known exploitation, and local exposure without treating any one score as a complete risk decision.
- AI & security
The AI Arms Race
AI has changed the economics of cyberattacks. Mario Luckeneder explores what happens when offense scales faster than defense.
- Software supply chain
Pinned Container Images Need a Deliberate Update Process
Connect container digests, base-image updates, rebuilds, and running deployments to verify that a patch reaches production.
- Cloud & application security
GraphQL Rate Limits Need to Account for Query Cost
Review depth, breadth, aliases, batching, and resolver authorization when testing the workload behind a GraphQL request.
- Identity & access
Emergency Administrator Access Must Work During an Identity Outage
Evaluate emergency account dependencies, custody, monitoring, and recovery drills without weakening normal administrator access.
- AI & security
AI Usage Limits Are Also Availability Controls
Examine how token budgets, concurrent jobs, retries, and tenant quotas affect the cost and availability of an AI business feature.
- Security operations
Application Audit Logs Need to Explain the Business Action
Design and test audit events that connect actors, customer accounts, actions, outcomes, and request identifiers without retaining unnecessary secrets.
- Software supply chain
Dependency Lockfiles Make Changes Reviewable, but They Still Need Review
Understand what dependency lockfiles establish, how clean installs use them, and which package changes still require security review.
- Cloud & application security
API Field Permissions: Which Parts of a Record May a User Read or Change?
Review response fields, editable properties, nested updates, and schema changes when a user may access a record but not every value inside it.
- Identity & access
Service Accounts Need Owners, Expiration Decisions, and Retirement Tests
Build a reviewable lifecycle for automated identities, including ownership, permissions, credential use, and safe retirement.
- AI & security
AI Output Validation: From a Generated Answer to a Business Action
Separate structured output, authorization, and transaction validation before model-generated content reaches databases or business systems.
- Security testing
Support Impersonation Needs Its Own Access Boundary
Review approval, scope, actor attribution, restricted actions, and expiry for tools that let support staff view customer accounts.
- Software supply chain
A Leaked Secret Requires Revocation, Not Just a Deleted Commit
Trace a disclosed credential through revocation, replacement, access review, and repository cleanup to verify the exposure is contained.
- Cloud & application security
Retiring a Cloud Service Also Means Retiring Its DNS Record
Follow subdomains, provider bindings, certificates, and ownership records when decommissioning a hosted application or campaign site.
- Identity & access
OIDC for Deployments: Replacing a Stored Secret With a Trust Policy
Review repository, workflow, environment, and audience conditions when CI jobs exchange OIDC tokens for cloud deployment credentials.
- AI & security
MCP Security: Why a Valid Token May Still Be the Wrong Token
Understand token audience, delegated access, and consent boundaries when connecting business applications through Model Context Protocol.
- Security testing
A Checkout Success Page Is Not Payment Evidence
Connect provider payment status to order fulfillment, duplicate handling, delayed methods, and customer-account binding.
- Software supply chain
SBOM and VEX: Two Different Records in a Vulnerability Investigation
Use component inventories and exploitability statements together while checking release identity, completeness, and deployment context.
- Cloud & application security
Cloud Audit Logs May Record Configuration Changes Without Recording File Reads
Distinguish management events from data events and verify which cloud actions are visible before an investigation depends on them.
- Identity & access
OAuth Refresh Token Rotation: When Two Workers Renew the Same Grant
Follow concurrent token renewal, replay detection, lost responses, and recovery without turning integration failures into repeated credential reuse.
- AI & security
RAG Access Control: What Happens When Document Permissions Change?
Follow document permissions through retrieval, cached answers, and citations to test whether an AI search system respects access changes.
- Security testing
Race Conditions Can Break a Business Rule Without Breaking Authentication
Test whether concurrent requests preserve single-use actions, balances, and approval limits across business transactions.
- Software supply chain
npm Trusted Publishing Changes How a Release Gets Permission
Examine OIDC publishing, workflow identity, package ownership, and remaining credentials when moving npm releases to trusted publishing.
- Cloud & application security
Kubernetes RBAC: Review What a Permission Allows Indirectly
Examine workload creation, secrets, service accounts, and namespace boundaries when assessing Kubernetes access permissions.
- Identity & access
Password Reset Flows Deserve Their Own Security Review
Test reset-token binding, expiry, reuse, notifications, and session behavior across the full account recovery workflow.
- AI & security
AI Agent Permissions: Defining What a Business Workflow May Change
Map an AI agent’s tools to business authority, separate preparation from execution, and verify permissions with controlled workflow tests.
- Security testing
Background Exports Need Authorization at More Than One Moment
Follow queued exports from request through generation and download, including permission changes, retries, and tenant-bound storage.
- Software supply chain
Artifact Attestations: What Build Provenance Can Prove
Separate artifact identity, build provenance, and software quality when evaluating signed release evidence in a deployment pipeline.
- Cloud & application security
A Completed Backup Is the Start of a Recovery Test
Verify data restoration, credentials, application dependencies, and business output instead of relying only on successful backup jobs.
- Identity & access
After an Account Reset, Which Sessions Still Work?
Distinguish passwords, access tokens, refresh tokens, and application sessions when verifying that an account reset removes access.
- AI & security
When Business Documents Become Instructions for an AI Assistant
How prompt injection reaches assistants through documents, where business permissions matter, and what a controlled security test can establish.
- Security testing
When a Cache Stores a Customer-Specific Response
Check cache keys, response directives, authentication, and invalidation before customer-specific content reaches a shared cache.
- Software supply chain
GitHub Actions: The Trust Boundary Between a Pull Request and a Release
Review how untrusted contributions, workflow permissions, artifacts, and release jobs interact in a GitHub Actions pipeline.
- Cloud & application security
Presigned Download URLs Carry Access Beyond the Login Screen
Review how signed file links are issued, shared, logged, expired, and invalidated when private documents leave an application’s access checks.
- Identity & access
Passkey Rollouts Need an Account Recovery Plan
Review enrollment, lost devices, recovery, and session handling when introducing passkeys to employee or customer accounts.