g3n3r4l12
-
DOM Clobbering (tib3rius.com)
Manipulating the DOM to bypass security controls or influence application logic.
-
HackBench (hackbench.ai)
Practice your offensive security skills in a gamified and competitive environment.
-
Find Your Cybersecurity Degree or Certification (cybersecurityguide.org)
A curated list of cybersecurity degrees and certifications to advance your career.
-
Details on the latest critical RCE vulnerabilities in Ingress NGINX for Kubernetes.
-
Defeating Prompt Injections by Design (huggingface.co)
New research proposing architectural defenses against prompt injection attacks.
-
Report on Paragon Spyware - Schneier on Security (schneier.com)
Analysis of the Paragon spyware and its implications on surveillance.
-
Improper Use of Private iOS APIs in Vietnamese Banking Apps (blog.verichains.io)
A technical analysis uncovering misuse of iOS APIs leading to potential security risks.
-
Novel WAF bypass techniques using character normalization tricks.
-
NVD Backlog Crisis (socket.dev)
The NVD struggles to keep up with the surge in CVE disclosures.
-
Next.js Middleware Bypass (CVE-2025-29927) (slcyber.io)
In-depth analysis of a critical vulnerability in Next.js middleware.
-
High Agency Hacking (josephthacker.com)
A personal journey on how initiative and agency shape great hackers.
-
CrushFTP Authentication Bypass - CVE-2025-2825 (projectdiscovery.io)
Details of a critical auth bypass vulnerability affecting CrushFTP.
X1
-
Signal App Debunking Misinfo (@signalapp)
Addressing widespread misinformation and educating users on secure messaging. Watch Here
y0utube1
-
CRITICAL 9.1 Severity Next.js Vulnerability (youtube.com)
A video breakdown of the latest Next.js vulnerability and its real-world impact. Watch Here
g1thub2
-
Zouuup/landrun (github.com)
Secure, unprivileged sandboxing for Linux processes using Landlock LSM. Explore on GitHub
-
sandumjacob/IngressNightmare-POCs (github.com)
Public POC repository for CVE-2025-1974 - Ingress Nightmare. Explore on GitHub