EXPERT

Toby Davenport

toby-davenport

Expert: Toby Davenport

Role: Offensive Security Practice Lead

Specialises in: Offensive Security

About Toby Davenport

Toby is a Managing Cyber Security Consultant with a background in offensive security. Since joining Stripe OLT in 2022 as a Penetration Tester, he has built expertise in web application and API security, as well as red teaming engagements. Outside of client work, Toby is an active bug bounty hunter and security researcher, ranked in the top 10 on HackerOne programs and credited with multiple high-impact CVEs in widely used open-source software.

“Understanding how protections can be bypassed is just as important as implementing them.”
  • notepad compromise

    How the Notepad++ Breach Underlines the Value of Internal Penetration Testing

    Notepad++ recently disclosed a compromise of its shared hosting infrastructure that affected its update endpoint. Threat actors altered update endpoints within configuration files to deliver a malicious version of the software to specific targets. This resulted in downstream users – potentially including businesses – downloading what appeared to be a legitimate update, but which gave attackers a foothold on compromised devices and therefore internal networks.
    April 1, 2026
  • flyd-olrxnzxfbjo-unsplash

    The importance of proper filtering within web applications

    Many times, during software security testing (penetration tests), whitelisting and blacklisting are encountered, with testers trying to bypass the regex (regular expression). But, what is the actual process of identifying these characters that can bypass filters? How are new payloads formed? If you're looking for some technical, offensive security insights, you've come to the right place...
    October 23, 2025
  • CVE-2023-42439

    CVE-2023-42439: SSRF Vulnerability

    A CVE (Common Vulnerabilities and Exposures) is a standardised identifier for a specific security vulnerability in a software application, hardware device, or system. Our pen tester Toby takes you through this latest discovery - CVE-2023-40017.
    October 22, 2025
  • password

    Discovering CVE-2023-40017

    A CVE (Common Vulnerabilities and Exposures) is a standardised identifier for a specific security vulnerability in a software application, hardware device, or system. Our pen tester Toby takes you through this latest discovery - CVE-2023-40017.
    February 10, 2026
find us on Youtube

Unlock the secrets of cybersecurity, Explore our videos for expert insights and actionable strategies