The Library · 97 Articles
How real attacks worked, the skills that stop them, and the moves that grow a security career. If you are new here, AI Security and Cyber Careers run deepest; each section says where to start and which tool or lab pairs with it.
How AI systems create attack surface: agents, prompt injection, MCP servers and the incidents that prove it. Start with the field guide, then test your own setup with the MCP Self-Check and the OWASP crosswalk.
Eight entries moved in the 2026 revision, and 7,714 real incidents tested a ranking that still keeps prompt injection first.
Aug 2026Two commands that test whether your MCP server leaks its tool catalogue, plus why authentication alone misses the lethal trifecta
Aug 2026How four frontier-lab evaluation breaches unfolded, and why Hugging Face had to self-host a model after commercial ones refused forensic work.
Jul 2026Four unrelated 2026 LiteLLM failures all reached the same provider keys: why your AI gateway needs secrets-manager controls, not router treatment.
Jul 2026
Which EU AI Act obligations land on engineering teams, why the deployer-versus-provider question decides your penalty tier, and the real deadlines.
Jul 2026Why agent sprawl repeats the identity and device sprawls, and the four controls, identity, inventory, least privilege, audited enforcement, that tame it.
Jun 2026
Three Claude Code security reviewers tested on one codebase, including the name collision that silently runs CodeGuard instead of the built-in command.
Jun 2026Honeytoken measurements put stolen .env AWS keys into live API abuse in 67 seconds, with validator traffic persisting ten days after takedown.
May 2026Honeypot data from 72 hours shows commercial scanners mapping exposed AI infrastructure while exploitation targets the credentials on the same hosts.
May 2026What Anthropic ending OpenClaw subscription access means for agent tooling costs, and the single-vendor dependency risk it exposes.
Apr 2026Why the drop from 135,000 to 63,070 exposed OpenClaw instances measures visibility, not safety, and what your scan probably missed.
Mar 2026
Three months of production testing show local models handle CVE reformatting but hallucinate MITRE IDs, and where the hardware line falls.
Mar 2026
Why MCP turned AI agents into a supply chain problem, with 1,184 malicious ClawHub skills and five hardening steps to take now.
Mar 2026Point Claude or ChatGPT at the CyberDesserts Coach MCP server for role roadmaps, certification economics and source-backed defensive guidance.
Jan 2026Reproducible analysis of GitHub Innovation Graph data showing public code pushes up 78.4 per cent, and what nobody measures about security checks
Jan 2026Real injection payloads from direct overrides to poisoned documents, with defence layers and the evidence that none fully hold
Dec 2025Which defences counter AI-weaponised attacks and which protect the AI systems you deploy, backed by 442% vishing growth data.
Dec 2025Metr's data shows AI task capability doubling every seven months, putting month-long autonomous projects within reach by 2030.
Nov 2025
Attacks on ChatGPT Atlas and Perplexity Comet, from prompt injection to memory poisoning, and why Gartner advised blocking AI browsers.
Oct 2025Podcast takeaways on attacker advantage: unrestricted models, expertise amplifying AI output, and a default password exposing 64 million job applications
Oct 2025
Five elements every AI acceptable use policy needs, plus the ISACA templates and DLP controls that make it actually enforceable.
Oct 2025Three layers of shadow AI risk, from personal chatbots to agentic access, and why 72% visibility confidence meets 65% detection rates.
Oct 2025Getting into security and getting ahead in it: role roadmaps, certification strategy, and the skills that survive automation. Pair with the Cloud Security Architect roadmap download and CyberDesserts Coach.
Why compliance is the largest US hiring category at 355,590 postings, with the entry, mid and senior skills that compound.
May 2026Entry-level roles carry a 10% candidate surplus while mid-career shortfalls hit 24%: where the market still rewards new entrants.
May 2026How to replace patch counts and MTTR with board-level metrics answering the question that matters: what can an attacker still reach?
Apr 2026
Why the shortage is a skills-matching problem, with a full DevSecOps career arc from AppSec triage to product security leadership.
Apr 2026Ten practitioner-tested books mapped to roles and career stages, from Linux Basics for Hackers to adversarial machine learning.
Mar 2026
Why judgment, taste, context and relationships gain value as AI makes output cheap, and how the tool trap ships nothing
Mar 2026
Free downloadable roadmap covering lab building, portfolio projects, certifications worth taking and interview strategy for SOC, pentest, cloud and GRC careers.
Mar 2026How to benchmark your skills against the UK Government Security Career Framework and mine NCSC's free training, whatever sector you work in.
Mar 2026
Two books cover blue team fundamentals, Murdoch's Blue Team Handbook version 3 and the original BTFM, plus which imitation edition to avoid.
Mar 2026
Hiring managers rank problem solving and communication above every technical skill, and test log analysis rather than tool name recognition.
Mar 2026Former BBC editor Keith Beech on why lived experience beats polished AI output when 74% of new pages are machine generated.
Mar 2026
Free and under $200 training mapped to career tracks, including the free ISC2 CC certification and platform picks per specialisation
Feb 2026
A skill matrix from new graduate to senior, plus the four practical areas hiring managers expect that degrees rarely teach.
Feb 2026Which security roles genuinely demand programming and which never will, from a former developer who took a pay cut into malware triage.
Feb 2026Cloud security leads a market with 4.8 million unfilled roles: skills ladders across ten domains, salary data and certifications employers ask for.
Feb 2026Qilin's 188 victims, EDR-killing BYOVD tradecraft and seven new KEV entries, mapped to the detection gaps your SOC should close.
Feb 2026Technical and non-technical specialisations mapped with entry pathways, and why AI, cloud and risk expertise decide how fast you advance.
Dec 2025
Four phases from zero to job ready, matching SOC, pentest, cloud, GRC and DevSecOps tracks to labs, certs and projects
Dec 2025
Eighteen skills that separate top security performers, drawn from 20 years at vendors, spanning business acumen, communication and proof of value
Oct 2025Compromised packages, poisoned registries and the dependency chains nobody reads. Includes the incidents that changed how teams pin and verify what they install.
Why npm's risk is now trust-flow exploits, traced through four Shai-Hulud generations, with an explicit-trust workflow to defend against them.
May 2026
A grep check for compromised axios versions, plus the remediation steps and how UNC1069 staged the three-hour maintainer-account attack.
Apr 2026
Lotus Blossom hijacked Notepad++ update infrastructure for six months: version checks, Chrysalis backdoor indicators, and the developer workstation gap exploited.
Feb 2026Which npm packages carry the most real risk, lodash to hijacked chalk, plus detection and remediation steps against 454,648 malicious packages.
Dec 2025
Detection commands, patch versions and incident response steps for React2Shell, the CVSS 10 RCE now weaponised by ransomware and nation states.
Dec 2025
Why semver ranges stop npm audit fix resolving transitive vulnerabilities, and safer fixes using overrides, production filtering and documented acceptance
Dec 2025Credential theft, ownership transfer and offboarding failures give attackers npm publishing rights, traced from event-stream to the UNC1069 Axios operation.
Nov 2025Four accelerating threat shifts, from the Shai-Hulud npm worm to OAuth abuse, and where they leave defenders exposed in 2026.
Oct 2025Gartner's 45% supply chain attack forecast landed at 75% in reality, driven by open-source abuse, SaaS sprawl and industrialised attackers.
Oct 2025
Build a free deps.dev scanner that catches abandoned packages and cross-database CVEs npm audit misses, running in under two minutes
Oct 2025How the Shai-Hulud worm compromised 500 plus npm packages, with warning signals that catch poisoned dependencies before npm audit does
Sept 2025Building and tuning detection: log pipelines, alerting that holds up, and the engineering behind a SOC that notices. The elk_stack and splunk_setup repositories give you a lab to practise in.
When to use syslog, Elastic Beats agents or API integrations to feed your ELK stack without leaving detection gaps.
Dec 2025
What Elasticsearch, Logstash and Kibana each do, whether the stack counts as a SIEM, and when it beats commercial alternatives.
Dec 2025
NIST CSF, CMMC and threat-hunting maturity levels compared, with a four-phase roadmap for benchmarking your security posture against the mature 3%.
Nov 2025Splunk Enterprise running in Docker within 30 minutes, with syslog ingestion on port 514, persistent storage and automated test scripts
Oct 2025
Docker-based ELK stack build in 45 minutes, with telemetry scripts tracking authentication failures, network activity and file changes across three platforms
Oct 2025
Community poll on Splunk, Sentinel, QRadar and Wazuh in production, with Docker quick starts for trying Splunk and ELK free.
Oct 2025Continuous threat exposure management: knowing what an attacker can reach before they do, and deciding what to fix first. The Quantum Exposure Calculator settles one specific deadline question.
Run Mosca's inequality against your data's secrecy life and migration time to learn whether harvest now, decrypt later already applies.
Jun 2026Inside the Detectify-powered scanning service covering 6,000 public sector organisations that cut DNS fix times from 50 days to eight.
Mar 2026Ten controls backed by Verizon DBIR breach data, with the operational detail that separates policy on paper from consistent execution
Feb 2026
Why patch-perfect estates still get breached: CTEM's five stages surface identity, misconfiguration and control failures no scanner reports
Dec 2025
Mapping CTEM's five stages onto NIST CSF 2.0's six functions turns periodic assessments into continuous validation against real attack techniques.
Oct 2025Hardening, auditing and understanding the systems most infrastructure actually runs on, from permissions and logging to the tools attackers reach for first.
A four-phase path from command line fundamentals through Nmap reconnaissance and NSE automation to building your own isolated practice lab.
Nov 2025
Build an isolated practice lab across VirtualBox, Docker and AWS, with Kali, Metasploitable and AI-assisted workflows for cert-ready skills.
Nov 2025Which of NSE's 600 plus Lua scripts to run, how --script vuln works, and the categories that can crash production systems.
Nov 2025Command line reference for security work: navigating logs, hunting SUID binaries, reading permissions and monitoring processes during incident response
Nov 2025Hands-on route from installing Docker Desktop to running Compose stacks, aimed at spinning up security tools like Wazuh, Pi-hole and DVWA.
Sept 2025Skills you build by doing: network scanning, cloud fundamentals, tooling workflows and the habits that make practice stick. Most of these pair with a lab you can run in one click.
Zettelkasten note-taking in Obsidian applied to security work, so ELK configs, detection rules and incident lessons never need relearning
Dec 2025
Why employees in poor security cultures are 52 times likelier to share credentials, and the structural changes that fix it
Dec 2025Three psychology-backed training methods, including a staged CEO fraud exercise that cut risky behaviour 50%, plus the SPARK implementation framework.
Nov 2025
How Storm-0501 and Void Blizzard map Azure tenants with AzureHound, and the Graph activity logging most organisations never switched on.
Nov 2025Nmap scan types compared for stealth and accuracy, with a four-phase reconnaissance workflow from host discovery to service fingerprinting
Nov 2025The shared responsibility split, IAM least privilege, encryption and segmentation practices that stop the misconfigurations behind most cloud breaches.
Oct 2025
A free threat news pipeline built from Google Alerts search operators, RSS delivery and Feeder, tuned to your industry and tools
Oct 2025Analysis of active groups, campaigns and incidents as they happened. News ages; the patterns in how these attacks worked do not.
Why patching every published CVE still leaves you exposed: a quarter of open-source security fixes ship silently, SharePoint's missing advisory included.
Jul 2026How EASM maps your internet-facing estate the way attackers see it, now that public-facing app exploitation leads initial access.
Jul 2026Why the June 2026 Miasma npm worm survives package removal: backdoor hooks committed into .claude and .cursor config directories
Jul 2026Lookup table for the CensysInspect, Xpanse and Umai banners in your logs, built from 682 attributed scanner IPs, with blocking advice.
Jun 2026How a TLS handshake hash identifies client tooling, pulled from Suricata, and why one JA3 spanned four unrelated attack campaigns.
May 2026One JA3 hash spans Interlock ransomware, AndroxGh0st credential theft and two further campaigns: TLS fingerprints mark toolkits, not operators.
May 2026How Anthropic's six-month Mythos lead collapsed in twenty days, and which vetted cyber-model programmes defenders can actually access today.
Apr 2026The six-phase playbook behind the MGM and M&S breaches mapped to MITRE ATT&CK, with the detection points that interrupt each phase.
Apr 2026Case table of Interlock, Akira and Cl0p breaching firewalls and VPN appliances, and the controls that limit damage when patching cannot.
Mar 2026
How Handala wiped Stryker's fleet through the Intune console, and the phishing-resistant MFA and scoped RBAC controls that limit the blast radius.
Mar 2026Why Digg's purpose-built bot defences collapsed within hours of launch, and what that failure means for detection speed and vendor claims.
Mar 2026
Why LLM non-determinism and hallucinated IoCs keep humans in the loop, despite the selloff Claude Code Security's launch triggered.
Mar 2026A hijacked Notepad++ update server and a Windows Notepad Markdown RCE in one week show why developer toolchains are attack surface.
Feb 2026Over 1,184 malicious ClawHub skills, 60+ CVEs and 63,070 exposed OpenClaw instances, with the audit and hardening steps security teams need.
Feb 2026IOCs, rogue admin account names and log patterns for the FortiCloud SSO bypass that compromised fully patched FortiGate devices in January.
Jan 2026
Inside the Hunters International rebrand running pure data extortion, from the 630GB Tata Electronics leak to Nike's stolen design files
Jan 2026Cobalt Strike, Mimikatz, Sliver and the rest of the attacker toolkit mapped to MITRE ATT&CK techniques and the groups deploying them.
Jan 2026
Fake CAPTCHA prompts now drive 47% of initial compromises: the clipboard hijack mechanic and three defence layers that hold across variants.
Jan 2026How NoName057(16) times DDoS campaigns to elections and holidays, with the La Poste outage as a case study in what survives.
Dec 2025Fourteen scam patterns behind $9.3 billion in US crypto losses, from pig butchering to the Coinbase insider bribery breach
Dec 2025Pre-authentication memory leak in MongoDB exposing credentials on 87,000 servers, the Ubisoft breach it enabled, and detection plus patching steps.
Dec 2025
How stealer malware harvested 1.8 billion credentials in six months, bypasses MFA via session cookies, and feeds ransomware operators
Aug 2025