Container security is a big deal, with OWASP A9 showing up more and more. Here is a tool that...
Read More
If you have been in my classes, you know that I often point to weev as my example for why not to hac...
Read More
Another Weblogic deserialization bug.
https://securityaffairs.co/wordpress/84450/breaking-news/oracl...
Read More
Hacky Easter is on! Go get your CTF rolling.
https://hackyeaster.hacking-lab.com/hackyeaster/...
Read More
The Stack Overflow Survey is out and has some interesting insights
https://insights.stackoverflow.co...
Read More
PortSwigger has replaced the exercises in the Web Application Security Hacker's Handbook with the ne...
Read More
No April Fools here.
Solid primer on using burp Collaborator for blind command injection.&nbs...
Read More
Bruce has some thoughts on a well-circulated article suggesting that application security isn't that...
Read More
Android malware had almost 150 MILLION Googe Play Store downloads before it is was discovered and pu...
Read More
The NSA has open sourced their internal reverse engineering tool. It's so good, many consultan...
Read More
As the network boundary becomes more ephemeral, and attackers don't have obvious kickoff points for...
Read More
A new tool for finding malicious JavaScript and securely using external libraries.
https://blog.foca...
Read More