The Library · 97 Articles

The CyberDesserts Library

How real attacks worked, the skills that stop them, and the moves that grow a security career. If you are new here, AI Security and Cyber Careers run deepest; each section says where to start and which tool or lab pairs with it.

AI Security 22

How AI systems create attack surface: agents, prompt injection, MCP servers and the incidents that prove it. Start with the field guide, then test your own setup with the MCP Self-Check and the OWASP crosswalk.

Cover image for the article OWASP LLM Top 10 2026: what changed and what the evidence shows

OWASP LLM Top 10 2026: what changed and what the evidence shows

Eight entries moved in the 2026 revision, and 7,714 real incidents tested a ranking that still keeps prompt injection first.

Aug 2026
Cover image for the article MCP Security Best Practices: Check Your Own Server First

MCP Security Best Practices: Check Your Own Server First

Two commands that test whether your MCP server leaks its tool catalogue, plus why authentication alone misses the lethal trifecta

Aug 2026
Cover image for the article Hugging Face's AI breach needed AI to investigate it. The models refused.

Hugging Face's AI breach needed AI to investigate it. The models refused.

How four frontier-lab evaluation breaches unfolded, and why Hugging Face had to self-host a model after commercial ones refused forensic work.

Jul 2026
Cover image for the article LiteLLM Security: Your AI Gateway Is a Secrets Manager. Benchmark It Like One

LiteLLM Security: Your AI Gateway Is a Secrets Manager. Benchmark It Like One

Four unrelated 2026 LiteLLM failures all reached the same provider keys: why your AI gateway needs secrets-manager controls, not router treatment.

Jul 2026
Cover image for the article The EU AI Act Lands on Your Codebase, Not Just Your Legal Team

The EU AI Act Lands on Your Codebase, Not Just Your Legal Team

Which EU AI Act obligations land on engineering teams, why the deployer-versus-provider question decides your penalty tier, and the real deadlines.

Jul 2026
Cover image for the article The Agent Control Plane: Security's Third Sprawl

The Agent Control Plane: Security's Third Sprawl

Why agent sprawl repeats the identity and device sprawls, and the four controls, identity, inventory, least privilege, audited enforcement, that tame it.

Jun 2026
Cover image for the article Claude Code Security Review: CodeGuard vs the Built-in Tools

Claude Code Security Review: CodeGuard vs the Built-in Tools

Three Claude Code security reviewers tested on one codebase, including the name collision that silently runs CodeGuard instead of the built-in command.

Jun 2026
Cover image for the article Exposed AWS Credentials Are Used in Under 90 Seconds: Findings from AI Infrastructure Research

Exposed AWS Credentials Are Used in Under 90 Seconds: Findings from AI Infrastructure Research

Honeytoken measurements put stolen .env AWS keys into live API abuse in 67 seconds, with validator traffic persisting ten days after takedown.

May 2026
Cover image for the article The Scanners Mapping AI Infrastructure Aren't After Your Model. They're After Your Credentials.

The Scanners Mapping AI Infrastructure Aren't After Your Model. They're After Your Credentials.

Honeypot data from 72 hours shows commercial scanners mapping exposed AI infrastructure while exploitation targets the credentials on the same hosts.

May 2026
Cover image for the article Anthropic Cuts OpenClaw Off Claude Subscriptions And It's Just the Start

Anthropic Cuts OpenClaw Off Claude Subscriptions And It's Just the Start

What Anthropic ending OpenClaw subscription access means for agent tooling costs, and the single-vendor dependency risk it exposes.

Apr 2026
Cover image for the article What Censys's OpenClaw Count Reveals That February's Headlines Did Not

What Censys's OpenClaw Count Reveals That February's Headlines Did Not

Why the drop from 135,000 to 63,070 exposed OpenClaw instances measures visibility, not safety, and what your scan probably missed.

Mar 2026
Cover image for the article Can You Use AI for Security Work Without the Cloud?

Can You Use AI for Security Work Without the Cloud?

Three months of production testing show local models handle CVE reformatting but hallucinate MITRE IDs, and where the hardware line falls.

Mar 2026
Cover image for the article AI Agent Security Risks in 2026: The Incident Landscape and Hardening Framework

AI Agent Security Risks in 2026: The Incident Landscape and Hardening Framework

Why MCP turned AI agents into a supply chain problem, with 1,184 malicious ClawHub skills and five hardening steps to take now.

Mar 2026
Cover image for the article Connect Your AI to a Cybersecurity MCP Server

Connect Your AI to a Cybersecurity MCP Server

Point Claude or ChatGPT at the CyberDesserts Coach MCP server for role roadmaps, certification economics and source-backed defensive guidance.

Jan 2026
Cover image for the article Public Code Pushes on GitHub Grew 78% in a Year

Public Code Pushes on GitHub Grew 78% in a Year

Reproducible analysis of GitHub Innovation Graph data showing public code pushes up 78.4 per cent, and what nobody measures about security checks

Jan 2026
Cover image for the article Prompt Injection Attacks: Examples, Techniques, and Defence

Prompt Injection Attacks: Examples, Techniques, and Defence

Real injection payloads from direct overrides to poisoned documents, with defence layers and the evidence that none fully hold

Dec 2025
Cover image for the article AI Security Threats: Complete Guide to Attack Vectors

AI Security Threats: Complete Guide to Attack Vectors

Which defences counter AI-weaponised attacks and which protect the AI systems you deploy, backed by 442% vishing growth data.

Dec 2025
Cover image for the article AI's Capability And Exponential Growth: 2030 is Closer Than You Think

AI's Capability And Exponential Growth: 2030 is Closer Than You Think

Metr's data shows AI task capability doubling every seven months, putting month-long autonomous projects within reach by 2030.

Nov 2025
Cover image for the article AI Browser Security Risks: What to Know

AI Browser Security Risks: What to Know

Attacks on ChatGPT Atlas and Perplexity Comet, from prompt injection to memory poisoning, and why Gartner advised blocking AI browsers.

Oct 2025
Cover image for the article AI and Cybersecurity: Some Interesting Thoughts from a Recent Podcast Chat

AI and Cybersecurity: Some Interesting Thoughts from a Recent Podcast Chat

Podcast takeaways on attacker advantage: unrestricted models, expertise amplifying AI output, and a default password exposing 64 million job applications

Oct 2025
Cover image for the article Writing An Acceptable Use Policy For AI - And What to Put In It

Writing An Acceptable Use Policy For AI - And What to Put In It

Five elements every AI acceptable use policy needs, plus the ISACA templates and DLP controls that make it actually enforceable.

Oct 2025
Cover image for the article Why Shadow AI Governance Keeps Failing

Why Shadow AI Governance Keeps Failing

Three layers of shadow AI risk, from personal chatbots to agentic access, and why 72% visibility confidence meets 65% detection rates.

Oct 2025

Cyber Careers 19

Getting into security and getting ahead in it: role roadmaps, certification strategy, and the skills that survive automation. Pair with the Cloud Security Architect roadmap download and CyberDesserts Coach.

Cover image for the article Cybersecurity Compliance Career Guide 2026

Cybersecurity Compliance Career Guide 2026

Why compliance is the largest US hiring category at 355,590 postings, with the entry, mid and senior skills that compound.

May 2026
Cover image for the article Is Cybersecurity a Good Career in 2026? The Honest Reality

Is Cybersecurity a Good Career in 2026? The Honest Reality

Entry-level roles carry a 10% candidate surplus while mid-career shortfalls hit 24%: where the market still rewards new entrants.

May 2026
Cover image for the article Information Security Metrics for Executives: How to Report Cyber Risk to the Board

Information Security Metrics for Executives: How to Report Cyber Risk to the Board

How to replace patch counts and MTTR with board-level metrics answering the question that matters: what can an attacker still reach?

Apr 2026
Cover image for the article Cybersecurity Career Report: April 2026

Cybersecurity Career Report: April 2026

Why the shortage is a skills-matching problem, with a full DevSecOps career arc from AppSec triage to product security leadership.

Apr 2026
Cover image for the article Best Cybersecurity Books for 2026

Best Cybersecurity Books for 2026

Ten practitioner-tested books mapped to roles and career stages, from Linux Basics for Hackers to adversarial machine learning.

Mar 2026
Cover image for the article Your Father Spent His Life Savings on Claude Code and We Shipped Nothing

Your Father Spent His Life Savings on Claude Code and We Shipped Nothing

Why judgment, taste, context and relationships gain value as AI makes output cheap, and how the tool trap ships nothing

Mar 2026
Cover image for the article Cybersecurity Career Guide (2026)

Cybersecurity Career Guide (2026)

Free downloadable roadmap covering lab building, portfolio projects, certifications worth taking and interview strategy for SOC, pentest, cloud and GRC careers.

Mar 2026
Cover image for the article How to Use UK Government Cybersecurity Resources to Advance Your Security Career

How to Use UK Government Cybersecurity Resources to Advance Your Security Career

How to benchmark your skills against the UK Government Security Career Framework and mine NCSC's free training, whatever sector you work in.

Mar 2026
Cover image for the article Best Blue Team Cybersecurity Books to Read in 2026

Best Blue Team Cybersecurity Books to Read in 2026

Two books cover blue team fundamentals, Murdoch's Blue Team Handbook version 3 and the original BTFM, plus which imitation edition to avoid.

Mar 2026
Cover image for the article What SOC Hiring Managers Test For In Interviews

What SOC Hiring Managers Test For In Interviews

Hiring managers rank problem solving and communication above every technical skill, and test log analysis rather than tool name recognition.

Mar 2026
Cover image for the article Being Authentic in the Age of AI

Being Authentic in the Age of AI

Former BBC editor Keith Beech on why lived experience beats polished AI output when 74% of new pages are machine generated.

Mar 2026
Cover image for the article Free Cybersecurity Training: Resources by Career Path

Free Cybersecurity Training: Resources by Career Path

Free and under $200 training mapped to career tracks, including the free ISC2 CC certification and platform picks per specialisation

Feb 2026
Cover image for the article Cybersecurity Graduate Guide: From Degree to First Job

Cybersecurity Graduate Guide: From Degree to First Job

A skill matrix from new graduate to senior, plus the four practical areas hiring managers expect that degrees rarely teach.

Feb 2026
Cover image for the article Does Cybersecurity Require Coding? A Practitioner's Take

Does Cybersecurity Require Coding? A Practitioner's Take

Which security roles genuinely demand programming and which never will, from a former developer who took a pay cut into malware triage.

Feb 2026
Cover image for the article Cybersecurity Career Report: February 2026

Cybersecurity Career Report: February 2026

Cloud security leads a market with 4.8 million unfilled roles: skills ladders across ten domains, salary data and certifications employers ask for.

Feb 2026
Cover image for the article Cybersecurity Threat Landscape Report: February 2026

Cybersecurity Threat Landscape Report: February 2026

Qilin's 188 victims, EDR-killing BYOVD tradecraft and seven new KEV entries, mapped to the detection gaps your SOC should close.

Feb 2026
Cover image for the article Cybersecurity Career Paths: How to Choose Your Specialisation and Advance in 2026

Cybersecurity Career Paths: How to Choose Your Specialisation and Advance in 2026

Technical and non-technical specialisations mapped with entry pathways, and why AI, cloud and risk expertise decide how fast you advance.

Dec 2025
Cover image for the article Cybersecurity Learning Roadmap 2026: Beginner to Job-Ready

Cybersecurity Learning Roadmap 2026: Beginner to Job-Ready

Four phases from zero to job ready, matching SOC, pentest, cloud, GRC and DevSecOps tracks to labs, certs and projects

Dec 2025
Cover image for the article Cybersecurity Career Playbook - 2026

Cybersecurity Career Playbook - 2026

Eighteen skills that separate top security performers, drawn from 20 years at vendors, spanning business acumen, communication and proof of value

Oct 2025

Supply Chain Security 11

Compromised packages, poisoned registries and the dependency chains nobody reads. Includes the incidents that changed how teams pin and verify what they install.

Cover image for the article Is npm Safe? A Practitioner Guide to npm Security in 2026

Is npm Safe? A Practitioner Guide to npm Security in 2026

Why npm's risk is now trust-flow exploits, traced through four Shai-Hulud generations, with an explicit-trust workflow to defend against them.

May 2026
Cover image for the article Axios NPM Supply Chain Attack (2026): What Happened and What to Do

Axios NPM Supply Chain Attack (2026): What Happened and What to Do

A grep check for compromised axios versions, plus the remediation steps and how UNC1069 staged the three-hour maintainer-account attack.

Apr 2026
Cover image for the article Notepad++ Compromised for 6 Months: Check Your Version Now

Notepad++ Compromised for 6 Months: Check Your Version Now

Lotus Blossom hijacked Notepad++ update infrastructure for six months: version checks, Chrysalis backdoor indicators, and the developer workstation gap exploited.

Feb 2026
Cover image for the article npm Security Risks: Most Vulnerable Packages in 2026

npm Security Risks: Most Vulnerable Packages in 2026

Which npm packages carry the most real risk, lodash to hijacked chalk, plus detection and remediation steps against 454,648 malicious packages.

Dec 2025
Cover image for the article CVE-2025-55182: React2Shell Detection and Fix Guide

CVE-2025-55182: React2Shell Detection and Fix Guide

Detection commands, patch versions and incident response steps for React2Shell, the CVSS 10 RCE now weaponised by ransomware and nation states.

Dec 2025
Cover image for the article Why npm audit fix Isn't Working

Why npm audit fix Isn't Working

Why semver ranges stop npm audit fix resolving transitive vulnerabilities, and safer fixes using overrides, production filtering and documented acceptance

Dec 2025
Cover image for the article How Attackers Target npm Maintainer Accounts

How Attackers Target npm Maintainer Accounts

Credential theft, ownership transfer and offboarding failures give attackers npm publishing rights, traced from event-stream to the UNC1069 Axios operation.

Nov 2025
Cover image for the article Four Threat Shifts That Will Define the 2026 Security Landscape

Four Threat Shifts That Will Define the 2026 Security Landscape

Four accelerating threat shifts, from the Shai-Hulud npm worm to OAuth abuse, and where they leave defenders exposed in 2026.

Oct 2025
Cover image for the article Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

Gartner's 45% supply chain attack forecast landed at 75% in reality, driven by open-source abuse, SaaS sprawl and industrialised attackers.

Oct 2025
Cover image for the article Build an npm Vulnerability Scanner (Free deps.dev)

Build an npm Vulnerability Scanner (Free deps.dev)

Build a free deps.dev scanner that catches abandoned packages and cross-database CVEs npm audit misses, running in under two minutes

Oct 2025
Cover image for the article Poisoned Packages: Auditing the NPM Supply Chain

Poisoned Packages: Auditing the NPM Supply Chain

How the Shai-Hulud worm compromised 500 plus npm packages, with warning signals that catch poisoned dependencies before npm audit does

Sept 2025

SIEM & Detection 6

Building and tuning detection: log pipelines, alerting that holds up, and the engineering behind a SOC that notices. The elk_stack and splunk_setup repositories give you a lab to practise in.

Exposure Management 5

Continuous threat exposure management: knowing what an attacker can reach before they do, and deciding what to fix first. The Quantum Exposure Calculator settles one specific deadline question.

Linux Security 5

Hardening, auditing and understanding the systems most infrastructure actually runs on, from permissions and logging to the tools attackers reach for first.

Hands-on & Fundamentals 7

Skills you build by doing: network scanning, cloud fundamentals, tooling workflows and the habits that make practice stick. Most of these pair with a lab you can run in one click.

Threat Intelligence & News 22

Analysis of active groups, campaigns and incidents as they happened. News ages; the patterns in how these attacks worked do not.

Cover image for the article The Vulnerabilities That Never Get a CVE

The Vulnerabilities That Never Get a CVE

Why patching every published CVE still leaves you exposed: a quarter of open-source security fixes ship silently, SharePoint's missing advisory included.

Jul 2026
Cover image for the article External Attack Surface Management: Seeing What Attackers Already See

External Attack Surface Management: Seeing What Attackers Already See

How EASM maps your internet-facing estate the way attackers see it, now that public-facing app exploitation leads initial access.

Jul 2026
Cover image for the article Your AI Coding Assistant's Config Folder Is a Persistence Surface

Your AI Coding Assistant's Config Folder Is a Persistence Surface

Why the June 2026 Miasma npm worm survives package removal: backdoor hooks committed into .claude and .cursor config directories

Jul 2026
Cover image for the article What Is Scanning My Server? An Internet Scanner Reference

What Is Scanning My Server? An Internet Scanner Reference

Lookup table for the CensysInspect, Xpanse and Umai banners in your logs, built from 682 attributed scanner IPs, with blocking advice.

Jun 2026
Cover image for the article What is a JA3 Fingerprint? How TLS Client Fingerprinting Works

What is a JA3 Fingerprint? How TLS Client Fingerprinting Works

How a TLS handshake hash identifies client tooling, pulled from Suricata, and why one JA3 spanned four unrelated attack campaigns.

May 2026
Cover image for the article AndroxGh0st and the limits of TLS fingerprinting

AndroxGh0st and the limits of TLS fingerprinting

One JA3 hash spans Interlock ransomware, AndroxGh0st credential theft and two further campaigns: TLS fingerprints mark toolkits, not operators.

May 2026
Cover image for the article Anthropic expected six months of lead on Claude Mythos. It got twenty days.

Anthropic expected six months of lead on Claude Mythos. It got twenty days.

How Anthropic's six-month Mythos lead collapsed in twenty days, and which vetted cyber-model programmes defenders can actually access today.

Apr 2026
Cover image for the article Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

The six-phase playbook behind the MGM and M&S breaches mapped to MITRE ATT&CK, with the detection points that interrupt each phase.

Apr 2026
Cover image for the article Why Ransomware Groups Are Targeting Firewalls and VPN Appliances

Why Ransomware Groups Are Targeting Firewalls and VPN Appliances

Case table of Interlock, Akira and Cl0p breaching firewalls and VPN appliances, and the controls that limit damage when patching cannot.

Mar 2026
Cover image for the article Microsoft Intune Security: Hardening Privileged Access

Microsoft Intune Security: Hardening Privileged Access

How Handala wiped Stryker's fleet through the Intune console, and the phishing-resistant MFA and scoped RBAC controls that limit the blast radius.

Mar 2026
Cover image for the article The Dead Internet Is a Security Problem: What Digg's Collapse Teaches Us

The Dead Internet Is a Security Problem: What Digg's Collapse Teaches Us

Why Digg's purpose-built bot defences collapsed within hours of launch, and what that failure means for detection speed and vendor claims.

Mar 2026
Cover image for the article Will AI Replace SOC Analysts?

Will AI Replace SOC Analysts?

Why LLM non-determinism and hallucinated IoCs keep humans in the loop, despite the selloff Claude Code Security's launch triggered.

Mar 2026
Cover image for the article Two Notepad Attacks in One Week: Your Tools Are the Target

Two Notepad Attacks in One Week: Your Tools Are the Target

A hijacked Notepad++ update server and a Windows Notepad Markdown RCE in one week show why developer toolchains are attack surface.

Feb 2026
Cover image for the article OpenClaw Security Risks: Malicious Skills, Exposed Instances and Real Exploits

OpenClaw Security Risks: Malicious Skills, Exposed Instances and Real Exploits

Over 1,184 malicious ClawHub skills, 60+ CVEs and 63,070 exposed OpenClaw instances, with the audit and hardening steps security teams need.

Feb 2026
Cover image for the article CVE-2026-24858: The Fortinet Patch That Wasn't

CVE-2026-24858: The Fortinet Patch That Wasn't

IOCs, rogue admin account names and log patterns for the FortiCloud SSO bypass that compromised fully patched FortiGate devices in January.

Jan 2026
Cover image for the article Who Is WorldLeaks? The Ransomware Group Behind the Nike and Tata Electronics Breaches

Who Is WorldLeaks? The Ransomware Group Behind the Nike and Tata Electronics Breaches

Inside the Hunters International rebrand running pure data extortion, from the 630GB Tata Electronics leak to Nike's stolen design files

Jan 2026
Cover image for the article Threat Actor Tools: The Complete Guide for Defenders

Threat Actor Tools: The Complete Guide for Defenders

Cobalt Strike, Mimikatz, Sliver and the rest of the attacker toolkit mapped to MITRE ATT&CK techniques and the groups deploying them.

Jan 2026
Cover image for the article ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them

ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them

Fake CAPTCHA prompts now drive 47% of initial compromises: the clipboard hijack mechanic and three defence layers that hold across variants.

Jan 2026
Cover image for the article Hacktivist DDoS Attacks: A Defender's Guide

Hacktivist DDoS Attacks: A Defender's Guide

How NoName057(16) times DDoS campaigns to elections and holidays, with the La Poste outage as a case study in what survives.

Dec 2025
Cover image for the article 14 Crypto Scams to Watch For in 2026

14 Crypto Scams to Watch For in 2026

Fourteen scam patterns behind $9.3 billion in US crypto losses, from pig butchering to the Coinbase insider bribery breach

Dec 2025
Cover image for the article MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers

MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers

Pre-authentication memory leak in MongoDB exposing credentials on 87,000 servers, the Ubisoft breach it enabled, and detection plus patching steps.

Dec 2025
Cover image for the article Top Infostealers in 2026: How They Work and How to Stop Them

Top Infostealers in 2026: How They Work and How to Stop Them

How stealer malware harvested 1.8 billion credentials in six months, bypasses MFA via session cookies, and feeds ransomware operators

Aug 2025