// Featured

Featured Articles

Our handpicked selection of outstanding articles.

CVE-2026-19478: How to Detect and Mitigate GitLab's Critical 9.4 Code Injection Zero-DayLinux

CVE-2026-19478: How to Detect and Mitigate GitLab's Critical 9.4 Code Injection Zero-Day

GitLab released an emergency out-of-band security patch to address CVE-2026-19478, a critical code injection vulnerability rating 9.4 on the CVSS scale. The flaw allows unauthenticated remote attackers to modify or delete public projects, rewrite repository state, and ban maintainers using a single crafted HTTP GraphQL request. Threat intelligence teams confirm that automated, AI-driven exploitation is actively reaching honeypots in the wild, making immediate patching or mitigation critical for

5 min read
Active Zero-Day Alert: Microsoft Confirms Exploitation of CVSS 10.0 Entra ID Flaw Prior to PatchExploits

Active Zero-Day Alert: Microsoft Confirms Exploitation of CVSS 10.0 Entra ID Flaw Prior to Patch

On Thursday, Microsoft revealed that a critical remote code execution (RCE) vulnerability in Entra ID—the identity engine powering Microsoft 365, Azure, and Dynamics 365—was actively exploited in the wild prior to server-side mitigations. Tracked as CVE-2026-69836 and assigned a maximum CVSS score of 10.0, the flaw allows unauthenticated remote code execution. While Microsoft has patched the infrastructure, the lack of published indicators of compromise (IOCs) leaves enterprise defenders

5 min read
KittySploitLatest Tutorials

KittySploit

Modular console : search, configure and execute security modules.

5 min read
Linux Firewalls: What You Need to Know About iptables and firewalldLinux

Linux Firewalls: What You Need to Know About iptables and firewalld

In the Linux ecosystem, packet filtering and network address translation (NAT) happen inside the kernel via frameworks like Netfilter and nftables .

5 min read
How to Install Nginx on Ubuntu: PPA/Official Repository, UFW Firewall, and Configuration StructureLinux

How to Install Nginx on Ubuntu: PPA/Official Repository, UFW Firewall, and Configuration Structure

An active Ubuntu server instance (Ubuntu 24.04 LTS / 26.04 LTS).

5 min read
How to solve network connectivity problems on dedicated serversLatest Tutorials

How to solve network connectivity problems on dedicated servers

To solve network connectivity problems on dedicated servers, start with connection controls (cable, gateway, speed/dupleks), verify IP/snut/gateway, make gateway ping and public hosts, run traceroute/MTR for tracking information, validate. DNS, review firewall/ACL rules, test specific service ports, and collect package capture data/registrees before sending the evidence to your provider.

5 min read
What Is Penetration TestingLatest Tutorials

What Is Penetration Testing

Penetration testing (pen testing) is a legal and authorized simulated cyber-attack on a computer system to evaluate its security. Pen testers act like real hackers: they use the same tools, techniques, and thinking to find and show weaknesses that could hurt the business.

5 min read
What is Vulnerability AssessmentHacking Tools

What is Vulnerability Assessment

A vulnerability assessment is the process of checking a system to find security weaknesses. The goal is to know whether a system can be attacked, how dangerous the weakness is, and how to fix it.

5 min read
Understanding what Threat, Vulnerability, Risk, Impact, Severity, and assesing Severity based on CVSSHacking Tools

Understanding what Threat, Vulnerability, Risk, Impact, Severity, and assesing Severity based on CVSS

A threat is anything that has the potential to do damage, even if the damage has not happened yet. In this case, a thief who walks around looking for houses to break into is the threat. The thief might or might not attack, but the possibility exists, and that possibility itself is the threat.

5 min read
Understanding What IP, Port, and Protocol IsLatest Tutorials

Understanding What IP, Port, and Protocol Is

This topic focuses on understanding the definitions of IP addresses, ports, and protocols, the differences between each of them, as well as commonly used standard ports and the network services that operate on those ports.

5 min read
Active Information Gathering in CybersecurityLinux

Active Information Gathering in Cybersecurity

In cybersecurity, the first phase of ethical hacking is called Reconnaissance or Information Gathering. This phase focuses on collecting information about a target before attempting any attack or security testing. Information gathering is divided into two main types: Passive Information Gathering Active Information Gathering

5 min read
Captcha BypassExploits

Captcha Bypass

Do not send the parameter related to the captcha. Check if the value of the captcha is in the source code of the page. Change some specific characters of the captcha parameter and see if it is possible to. When a new Captcha code is created, the previous code will expire.

5 min read
Network Mapping for Beginners: Exploring Networks with NmapLatest Tutorials

Network Mapping for Beginners: Exploring Networks with Nmap

Network mapping is an early stage in network analysis, cybersecurity, and penetration testing activities. At this stage, the main objective is not to exploit vulnerabilities, but to understand the structure of the network. We want to know what devices exist, which hosts are active, and how the network is organized.

5 min read
A Beginner’s Guide to Port Scanning Using NmapGathering

A Beginner’s Guide to Port Scanning Using Nmap

After identifying active hosts through network mapping, the next step is port scanning. Port scanning aims to determine which network services are running on each host.

5 min read
Understanding Service Enumeration in CybersecurityLinux

Understanding Service Enumeration in Cybersecurity

Service enumeration is an essential stage in ethical hacking and penetration testing. It is performed after the initial information gathering and scanning phases.

5 min read
Information Gathering in CybersecurityGathering

Information Gathering in Cybersecurity

What is Information Gathering Information gathering is an important early step in cybersecurity and ethical hacking. It is the process of collecting and organizing information about a target system before performing deeper security testing.

105 min read
EternalBlue Exploit Analysis – RunbookExploits

EternalBlue Exploit Analysis – Runbook

This runbook details a hands-on simulation of exploiting the EternalBlue vulnerability (CVE-2017-0144), targeting an unpatched Windows 7 machine in a controlled lab environment using Metasploit.

5 min read
Using Wordlists for Brute Force Attack in Kali LinuxLinux

Using Wordlists for Brute Force Attack in Kali Linux

Kali Linux quietly ships with some of the most practical and battle-tested wordlists you can use as a beginner or professional pentester.

5 min read