Network Security
9 articles

CVE-2026-19478: How to Detect and Mitigate GitLab's Critical 9.4 Code Injection Zero-Day
GitLab released an emergency out-of-band security patch to address CVE-2026-19478, a critical code injection vulnerability rating 9.4 on the CVSS scale. The flaw allows unauthenticated remote attackers to modify or delete public projects, rewrite repository state, and ban maintainers using a single crafted HTTP GraphQL request. Threat intelligence teams confirm that automated, AI-driven exploitation is actively reaching honeypots in the wild, making immediate patching or mitigation critical for

Active Zero-Day Alert: Microsoft Confirms Exploitation of CVSS 10.0 Entra ID Flaw Prior to Patch
On Thursday, Microsoft revealed that a critical remote code execution (RCE) vulnerability in Entra ID—the identity engine powering Microsoft 365, Azure, and Dynamics 365—was actively exploited in the wild prior to server-side mitigations. Tracked as CVE-2026-69836 and assigned a maximum CVSS score of 10.0, the flaw allows unauthenticated remote code execution. While Microsoft has patched the infrastructure, the lack of published indicators of compromise (IOCs) leaves enterprise defenders

Linux Firewalls: What You Need to Know About iptables and firewalld
In the Linux ecosystem, packet filtering and network address translation (NAT) happen inside the kernel via frameworks like Netfilter and nftables .

AI-Generated Malware Campaign Scales Threats Through Vibe Coding Techniques
Normal 0 false false false false EN-US X-NONE X-NONE The campaign consists of more than 440 malicious ZIP archives distributed across…

How AI Puts Data Security at Risk
However, it also brings significant risks to data security.

What Is Penetration Testing
Penetration testing (pen testing) is a legal and authorized simulated cyber-attack on a computer system to evaluate its security. Pen testers act like real hackers: they use the same tools, techniques, and thinking to find and show weaknesses that could hurt the business.

Understanding what Threat, Vulnerability, Risk, Impact, Severity, and assesing Severity based on CVSS
A threat is anything that has the potential to do damage, even if the damage has not happened yet. In this case, a thief who walks around looking for houses to break into is the threat. The thief might or might not attack, but the possibility exists, and that possibility itself is the threat.

Understanding What IP, Port, and Protocol Is
This topic focuses on understanding the definitions of IP addresses, ports, and protocols, the differences between each of them, as well as commonly used standard ports and the network services that operate on those ports.

Network Mapping for Beginners: Exploring Networks with Nmap
Network mapping is an early stage in network analysis, cybersecurity, and penetration testing activities. At this stage, the main objective is not to exploit vulnerabilities, but to understand the structure of the network. We want to know what devices exist, which hosts are active, and how the network is organized.
