We share our expertise to make the world a safer place.
InfoSec moves at a rapid pace and sometimes it’s hard to keep up—that’s where we enter the chat.

Discover current cybersecurity insights
Get vital information straight from the experts, without all the noise.

InfoSec World 2-Day Workshop - Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack
In this workshop, participants will learn to navigate DevOps attack paths—from code triage to pipeline exploitation—and write detective alerts to defend their…

AMA: Passkeys and Preventing Credential Theft
During this live AMA, you’ll have the chance to ask our experts anything about the process of implementing passkeys as the default and the best ways to help…

Securing Cloud AI: Real-World Scenarios in AWS, Azure, and GCP
Join our cloud security team as they dig into real-world exposures tied to popular AI-based services. Learn how to find the gaps to make AI more secure for…

What's New in hate_crack Since 2.0
You thought you knew hate_crack 👀 Well, version 2.0 changed that. In Part 1 of this latest blog series, we go through 13 new attack methods, menu…

Unpacking a laZzzy Donut
Six stages. Multiple encryption layers. One static analysis. In this blog, we unpack a multi-stage malware loader combining Python obfuscation, Donut…

Finding Your Way on the Passkey Path
Ready to ditch passwords for good, but not sure where to start? Introducing Passkey Path, a choose-your-own-adventure guide to transitioning from passwords to…

Security Noise - Navigating Smart Home Security
On this episode, we are talking home automations, where the lights, the locks, the thermostat, and the doorbell all have opinions (and an internet connection).…

So… You Found AWS Access Keys (Part 1)
The AWS access keys are in hand... now what? In Part 1 of this blog series, we break down AWS credential types, where to find them, and how to validate and use…

Risk at the Edge: Managing Cyber Exposure Across IT & OT Assets
Join Senior Security Consultant Steph Saunders for a practical look at how to close gaps and build cyber resilience across converged IT/OT environments.

LLMHaxor Update
Most LLM testing tools require setup, paid access, or internet; LLMHaxor requires none of that. In this blog, we walk through the latest update, including a…

waf-fu, or Some Log Replay Nonsense
AWS WAF logs are keeping receipts, including your session tokens. In this blog, we walk through the risk of default WAF logging configurations and the tool…

Security Noise - Hacker Summer Camp 2026
We're back from Hacker Summer Camp and are ready to get "Reel" about our experiences in Las Vegas! Join us on this episode of Security Noise as we sit down to…
Loading...
Get our best blogs, latest webinars, and podcasts sent to your inbox.
Our monthly newsletter makes it easy to stay up-to-date on the latest in security.
