Cloud, Infrastructure and DevSecOps AWS IAM privilege escalation testing: technical methodology
Test AWS IAM privilege escalation safely: policy evaluation, PassRole, trust policies, CloudTrail detection, least privilege and remediation.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Cloud, Infrastructure and DevSecOps Test AWS IAM privilege escalation safely: policy evaluation, PassRole, trust policies, CloudTrail detection, least privilege and remediation.
Vulnerabilities and CVEs CVE-2026-33827 is a network race condition in Windows TCP/IP. Review confirmed scope, attack conditions and a defensible patching plan.
Governance and Compliance A small company doesn't need a security department to stop being an easy target. A 90-day plan: what to do in-house, what to buy, what to outsource.
Vulnerabilities and CVEs CVE-2026-32201 scores 6.5 but appears in CISA KEV. Check affected SharePoint Server editions and follow a defensible response plan.
Identity and Access Change your password every 30 days? Invent complex character strings? We explain which password rules are outdated myths and what really protects your accounts.
Vulnerabilities and CVEs Technical BlueHammer analysis: Defender local privilege escalation, safe PoC boundaries, KEV status, platform versions, hunting and remediation.
Identity and Access Assess Entra ID tokens, consent, roles, Conditional Access, PIM, service principals, workload identities, hybrid trust and cloud identity detection.
Identity and Access A technical model for NTLM relay to SMB, LDAP and HTTP, with safe assessment, signing, channel binding, EPA, detection and NTLM migration guidance.
Identity and Access Understand S4U2self, S4U2proxy, KCD and RBCD, then safely assess delegation ACLs, SPNs, tickets, detection and lateral-movement exposure.
Identity and Access Audit AD CS, certificate templates and ESC1–ESC15 paths. Understand PKINIT, strong mapping, safe validation, detection and enterprise PKI hardening.
Penetration Testing and AppSec A practical guide to hardening Linux servers — no copying hundred-item checklists, with an emphasis on the highest-impact actions.
Threats and Incidents In spring 2026 several Polish hospitals were hit by ransomware in quick succession. Why healthcare is a target and how to limit the impact.
Human Security How to protect your child online without surveillance and bans? A practical guide to the risks, parental control settings and the conversation that works.
AI Security Muse Spark combines tool use, visual chain of thought and multi-agent orchestration. We analyse Contemplating mode, benchmarks, safety and test awareness.
Penetration Testing and AppSec Test SaaS tenant isolation across APIs, databases, caches, queues, storage and support tooling with a safe, evidence-led penetration testing method.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.