Identity and Access Microsoft Entra ID penetration testing guide
Assess Entra ID tokens, consent, roles, Conditional Access, PIM, service principals, workload identities, hybrid trust and cloud identity detection.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Identity and Access Assess Entra ID tokens, consent, roles, Conditional Access, PIM, service principals, workload identities, hybrid trust and cloud identity detection.
Identity and Access A technical model for NTLM relay to SMB, LDAP and HTTP, with safe assessment, signing, channel binding, EPA, detection and NTLM migration guidance.
Identity and Access Understand S4U2self, S4U2proxy, KCD and RBCD, then safely assess delegation ACLs, SPNs, tickets, detection and lateral-movement exposure.
Identity and Access Audit AD CS, certificate templates and ESC1–ESC15 paths. Understand PKINIT, strong mapping, safe validation, detection and enterprise PKI hardening.
Penetration Testing and AppSec A practical guide to hardening Linux servers — no copying hundred-item checklists, with an emphasis on the highest-impact actions.
Threats and Incidents In spring 2026 several Polish hospitals were hit by ransomware in quick succession. Why healthcare is a target and how to limit the impact.
Human Security How to protect your child online without surveillance and bans? A practical guide to the risks, parental control settings and the conversation that works.
AI Security Muse Spark combines tool use, visual chain of thought and multi-agent orchestration. We analyse Contemplating mode, benchmarks, safety and test awareness.
Penetration Testing and AppSec Test SaaS tenant isolation across APIs, databases, caches, queues, storage and support tooling with a safe, evidence-led penetration testing method.
Penetration Testing and AppSec A technical gRPC and Protobuf pentest methodology covering reflection, HTTP/2, mTLS, metadata, interceptors, schemas, streaming, limits and hardening.
Supply Chain Security Technical analysis of the March 2026 supply-chain wave: hijacked Trivy and KICS tags, LiteLLM .pth execution, axios, CI/CD secrets and recovery.
Penetration Testing and AppSec A technical WebSocket pentest methodology covering handshakes, CSWSH, Origin, cookies, tokens, message authorisation, subscriptions, limits and hardening.
Penetration Testing and AppSec How to test web cache poisoning and cache deception safely: cache keys, URL normalisation, CDN policy, Vary, private responses, detection and hardening.
Cloud, Infrastructure and DevSecOps A technical SSRF testing methodology for webhooks, URL parsers, DNS rebinding, redirects, AWS IMDSv2, Azure and GCP metadata, and egress hardening.
Penetration Testing and AppSec How to test HTTP request smuggling, CL.TE, TE.CL and HTTP/2 downgrades safely. A technical methodology for detection, hardening and retesting.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.