IntroductionWhat is Roundcube? Roundcube is a free, open-source, browser-based email client that lets you access, send, and organise your emails from any web browser. How does it work?Roundcube operates as an IMAP client. This means it connects directly to your mail server to read and manage...
IntroductionToday we have an exciting TryHackMe challenge that we will go through . It is a XOR encryption based challenge that tests how well you understand XOR cipher and know how to use it to decrypt the encrypted flags. Sounds like a fun challenge! On their website, it is given as an easy...
What is n8n? n8n is a visual workflow automation platform that connects different apps, services, and AI models so they can talk to each other. It acts as a digital assistant to automate boring, repetitive tasks without requiring you to write everything from scratch. Versions 0.211.0 through...
I got tired of digging through endless cybersecurity âawesomeâ lists, abandoned GitHub repos, blog posts from 2017, broken links, random tool dumps, and websites that require half a JavaScript framework just to show me one useful URL. So, naturally, I built another cybersecurity list. Yes, I see...
Back in October, I wrote âSchneier on LLM vulnerabilities, agentic AI, and âtrusting trust'â about fundamental architectural weaknesses in current LLMs and agents, and why I personally donât yet trust AI agents with my credentials. At the end, I wrote: I love AI and LLMs. I use them every day....
BeCPP just posted this video of my talk at their March 30 Symposium. This is the first time Iâve given this material on camera â itâs extension of themes in my New Yearâs Eve blog post, with major updates because some big industry changes happened in the first quarter of 2026. This talk...
This article is about building a HexStrike AI Lab with Kali, Fedora, Roo Code and DeepSeek. Enjoy!
HexStrike AI popped up in the Parrot 7.0 release notes as a new âAI Toolâ category.
We are known to have very strong opinions on
An intriguing phone call from Seven Bank over the summer offered a glimpse into the IT security vulnerabilities confronting Japanâs banks nowadays. First, however, let me clarify that I come not to bury Seven Bank, but to praise them. Opening a personal account with Seven Bank still to this day...
This 80's book of espionage story still brings attention to modern cybersecurity professionals, and remains surprisingly relevant to todayâs world. The book is made up of many easy-to-read short to medium-sized chapters, and things start to get really thrilling around chapter 29. I could be biased...
I'm generally a big believer in "learning in public" and emphasizing transparency, for numerous reasons. I won't detail those reasons now, but that might make a good blog post in its own right. But for now, I'm just going to share something that happened to me in the process of setting up this...
Securing kubernetes resources that you want to expose to only some users externally is often done through IP allowlisting and a VPN. While this is a tried and true method, there are some drawbacks.VPNs may require manual installation and configuration on your coworkersâ devices. This is especially...
The Biden administration just issued another executive order (EO) on hardening U.S. cybersecurity. This is all great stuff. (*) (**) A lot of this EO is repeating the same things I urged in my essay nearly a year ago, âC++ safety â in contextâ⌠hereâs a cut-and-paste of my âCall(s) to actionâ...
Scope. To talk about C++âs current safety problems and solutions well, I need to include the context of the broad landscape of security and safety threats facing all software. I chair the ISO C++ standards committee and I work for Microsoft, but these are my personal opinions and I hope they will...
I was reading an article about cybersecurity strategy and how some principles could be brought on table for a business to hold a stable cybersecurity posture, like having global policy with all its procedures, guidelines and baselines, maintaining a disaster recovery plan for potential...
I passed the CISSP exam on the first try at the 125th question, Thanks to GOD. I'm relieved as I don't have take this exam again.This is the most significant experience in my career, acquiring new knowledge in information security while studying for the exam, was a wonderful...