
cve-2026-20833-rc4-kerberos
Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

Advisory detailing CVE-2025-56221, an authentication rate-limiting flaw in Ascertia SigningHub allowing brute-force attacks, with affected versions…

Documentation of CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0 Web API, including affected…

Documentation of a broken access control vulnerability in TCS Cognix Recon Client v3.0, detailing CWE-862/639, affected endpoints, and remediation…

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Curated macOS security and privacy guide with practical instructions for threat modeling, disk encryption, firewall configuration, secure…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

A compact guide to network pivoting for penetration testings / CTF challenges.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Mind-Maps of Several Things

Wireshark RDP resources

This cheatsheet maps common impacket workflows to their modern alternatives

😎 Awesome list of all things related to Microsoft Entra

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…