Penetration Testing and AppSec gRPC and Protobuf penetration testing guide
A technical gRPC and Protobuf pentest methodology covering reflection, HTTP/2, mTLS, metadata, interceptors, schemas, streaming, limits and hardening.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Penetration Testing and AppSec A technical gRPC and Protobuf pentest methodology covering reflection, HTTP/2, mTLS, metadata, interceptors, schemas, streaming, limits and hardening.
Supply Chain Security Technical analysis of the March 2026 supply-chain wave: hijacked Trivy and KICS tags, LiteLLM .pth execution, axios, CI/CD secrets and recovery.
Penetration Testing and AppSec A technical WebSocket pentest methodology covering handshakes, CSWSH, Origin, cookies, tokens, message authorisation, subscriptions, limits and hardening.
Penetration Testing and AppSec How to test web cache poisoning and cache deception safely: cache keys, URL normalisation, CDN policy, Vary, private responses, detection and hardening.
Cloud, Infrastructure and DevSecOps A technical SSRF testing methodology for webhooks, URL parsers, DNS rebinding, redirects, AWS IMDSv2, Azure and GCP metadata, and egress hardening.
Penetration Testing and AppSec How to test HTTP request smuggling, CL.TE, TE.CL and HTTP/2 downgrades safely. A technical methodology for detection, hardening and retesting.
Human Security Without SPF, DKIM and DMARC anyone can send emails impersonating your domain. We explain these three mechanisms simply and show how to deploy them.
Vulnerabilities and CVEs Critical CVSS 9.8 Cisco SSM On-Prem flaw: exposed internal service, unauthenticated commands as root, affected versions, detection and upgrade plan.
AI Security An absurd space farce about an AI agent, a suspicious USB drive and a crew that confused automation with abdication. Funny—until the oxygen goes offline.
Vulnerabilities and CVEs Google confirmed active exploitation of an out-of-bounds write in Skia and a use-after-free in Dawn. Fixed releases and an enterprise response runbook.
AI Security Meta SAM 3.1 doubles throughput to 32 FPS through object multiplexing and global reasoning. Technical deployment, evaluation and surveillance risks.
Cybersecurity History Trace modern cryptography from DES, Diffie–Hellman and RSA through AES and TLS 1.3 to NIST post-quantum standards, with practical security lessons.
Cybersecurity History Learn how vulnerability disclosure evolved into CVE, NVD, CVSS and CISA KEV, how each layer works and how defenders should prioritise remediation.
Vulnerabilities and CVEs Jenkins handled tar symlinks unsafely. We explain the code-execution path, exploit conditions, affected releases and the 2.555/LTS 2.541.3 fix.
Cybersecurity History From Creeper and Fred Cohen through the Morris worm, ILOVEYOU, Mirai and ransomware. Learn how malware evolved and which defensive lessons endured.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.