Writing and blogging background

Articles

Technical articles, conference debriefs, and security research

AI Vishing
AI Security

AI Vishing

The Future of Social Engineering Attacks

Exploring how AI voice cloning is revolutionizing social engineering attacks and why most organizations are not prepared for this emerging threat.

Read
DEFCON Debrief 2024
Cybersecurity

DEFCON Debrief 2024

Highlights and Takeaways from DEFCON 32

Key insights, notable experiences, and lessons learned from attending DEFCON 32 - the world's largest hacking conference in Las Vegas.

Read
Mastering Windows Privilege Escalation
Offensive Security

Mastering Windows Privilege Escalation

Part 1: SeImpersonatePrivilege Exploitation

A comprehensive guide to Windows privilege escalation techniques exploiting SeImpersonatePrivilege, covering Juicy Potato, Rogue Potato, and PrintSpoofer.

Read
Tunneling with Ligolo-ng
Offensive Security

Tunneling with Ligolo-ng

Modern Pivoting Techniques

Deep dive into using Ligolo-ng for network pivoting during penetration tests, with practical examples and configuration tips.

Read
The Remediation Paradox
Vulnerability Management·May 21, 2026·15 min

The Remediation Paradox

Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower

Vulnerability exploitation overtook credential theft as the number one initial access vector. Median patch time increased to 43 days. The gap between attacker speed and defender remediation is widening on both sides simultaneously.

Read
The Extension Blind Spot
Supply Chain Security·May 20, 2026·13 min

The Extension Blind Spot

How One VS Code Plugin Gave Attackers GitHub's Source Code

A single VS Code extension on a single employee's device gave attackers access to 3,800 of GitHub's internal repositories. VS Code extensions have full, unrestricted access to everything on the developer's machine, and 97% of the marketplace is unverified.

Read