We share our expertise to make the world a safer place.
InfoSec moves at a rapid pace and sometimes it’s hard to keep up—that’s where we enter the chat.

Discover current cybersecurity insights
Get vital information straight from the experts, without all the noise.

Black Hat USA Training - Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack
During our Black Hat training, go beyond network pentesting fundamentals and gain the attacker and defender perspective needed to conduct modern,…

AMA: CCPA's New Cybersecurity Audit Requirement
During this live AMA, you’ll get the chance to ask your pressing questions about the new CCPA regulations and find out how your organization can prepare for…

CMMC is (Not) Cancelled
Word is out that the Department of War (DoW) has suspended the rollout of CMMC Phase II. However, contractors working on CMMC compliance should not abandon…

Pandora’s Container Part 1: Unpacking Azure Container Security
Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting…

Vulnify: Giving Your Agents a CVE Brain
The CVE brain your AI agent has been missing. In this blog, we introduce Vulnify, an open-source tool that stitches eight authoritative vulnerability databases…

Offense Meets Defense: A Candid Conversation on AI in Detection Engineering
Join TrustedSec and Binary Defense for a candid conversation that brings together offensive and defensive practitioners to explore how AI is reshaping…

Welcoming ObfusGit
What if your public repo could stay out of AI training data without changing how you commit? In this blog, we introduce ObfusGit, a Python tool that obfuscates…

Inheriting the Receipts: Securing the AI Your Company Already Adopted
The work is not new. The speed is. In this blog, we're outlining how existing security pillars apply to the AI your organization has already adopted; no new…

Large Workflows with Local LLMs
As it turns out, local LLMs have a few opinions about large workflows. In this blog, we walk through the scaling challenges of local LLMs and the custom Python…

Modern Web Application Content Discovery
Staring at a web app with no links and no navigation? In this blog, we break down modern content discovery, from forced browsing and web crawling to Google…

JQ for Hackers
Grey-bearded hackers and sysadmins still reaching for cut and CSV files, this one's for you. In this blog, we break down jq and why it's time to embrace JSON.

JS-Tap v3: Endpoint Post-Exploitation With JavaScript Implants
JavaScript escaped the browser. JS-Tap v3 followed it. In this blog, we introduce three new beacons targeting the Electron apps, browser extensions, and Node…
Loading...
Get our best blogs, latest webinars, and podcasts sent to your inbox.
Our monthly newsletter makes it easy to stay up-to-date on the latest in security.
