Articles
Technical articles, conference debriefs, and security research

AI Vishing
The Future of Social Engineering Attacks
Exploring how AI voice cloning is revolutionizing social engineering attacks and why most organizations are not prepared for this emerging threat.

DEFCON Debrief 2024
Highlights and Takeaways from DEFCON 32
Key insights, notable experiences, and lessons learned from attending DEFCON 32 - the world's largest hacking conference in Las Vegas.
Mastering Windows Privilege Escalation
Part 1: SeImpersonatePrivilege Exploitation
A comprehensive guide to Windows privilege escalation techniques exploiting SeImpersonatePrivilege, covering Juicy Potato, Rogue Potato, and PrintSpoofer.
Tunneling with Ligolo-ng
Modern Pivoting Techniques
Deep dive into using Ligolo-ng for network pivoting during penetration tests, with practical examples and configuration tips.

The Remediation Paradox
Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
Vulnerability exploitation overtook credential theft as the number one initial access vector. Median patch time increased to 43 days. The gap between attacker speed and defender remediation is widening on both sides simultaneously.

The Extension Blind Spot
How One VS Code Plugin Gave Attackers GitHub's Source Code
A single VS Code extension on a single employee's device gave attackers access to 3,800 of GitHub's internal repositories. VS Code extensions have full, unrestricted access to everything on the developer's machine, and 97% of the marketplace is unverified.