Vulnerabilities and CVEs CopyFail CVE-2026-31431: Linux root, AF_ALG and a safe PoC
Technical CopyFail analysis: CVE-2026-31431, algif_aead, splice, page-cache overwrite, affected Linux systems, safe PoC, detection and remediation.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Technical CopyFail analysis: CVE-2026-31431, algif_aead, splice, page-cache overwrite, affected Linux systems, safe PoC, detection and remediation.
Identity and Access Technical SAML 2.0 testing for XML signatures, wrapping, Audience, Destination, Recipient, replay, RelayState and identity-provider key rotation.
Human Security A hacked friend's account asks for a BLIK code or a scan of your ID. We explain how account takeovers happen and why the chain of trust is the weakest link.
Identity and Access Audit TLS 1.3, mutual TLS and PKI: protocol negotiation, identity validation, certificate paths, revocation, 0-RTT and key rotation.
Governance and Compliance 'Appropriate technical measures' — but which exactly? GDPR Article 32 as an IT checklist: encryption, access, logs, backups and testing.
Cloud, Infrastructure and DevSecOps Replace static CI/CD cloud keys with OIDC, restrict trust by audience, subject and environment, and test AWS, Azure and Google Cloud federation.
AI Security Technical DeepSeek V4 Pro and Flash analysis: 1.6T/49B and 285B/13B, compressed attention, mHC, Muon, 1M context, MIT licence and deployment.
Cloud, Infrastructure and DevSecOps Secure Terraform from module to apply: provider supply chain, state and plan data, CI identity, policy as code, drift, detection and testing.
AI Security Technical GPT-5.5 analysis: agentic coding, Terminal-Bench 2.0, SWE-Bench Pro, computer use, GB200/GB300 inference and High safeguards.
Identity and Access Stolen personal data lets criminals take out loans or register a company in your name. How identity theft happens and how to protect yourself.
AI Security Deploying language models opens up a class of threats that classic applications never knew. We cover prompt injection, data leakage and over-privileged agents.
Cloud, Infrastructure and DevSecOps A technical container-escape model without exploit payloads: namespaces, capabilities, seccomp, AppArmor, OCI runtime, detection and hardening.
Vulnerabilities and CVEs CVE-2026-35616 in FortiClient EMS is actively exploited and listed in CISA KEV. Check affected releases, the hotfix and investigation steps.
Cloud, Infrastructure and DevSecOps Audit Kubernetes RBAC safely: bind, escalate, impersonate, ServiceAccounts, pod subresources, audit detection, admission and hardening.
Penetration Testing and AppSec A technical LAN and segmentation pentest methodology covering flow matrices, Active Directory, IPv6, detection, hardening and safe evidence.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.