Rrathsarainrr-cyber.hashnode.dev·2d ago · 19 min readOpenID Connect: The Identity Layer OAuth Was MissingBy the time I actually heard the word OIDC, I'd already been through OAuth and PKCE conversations I hadn't fully understood, years apart from each other, and this one arrived even later than those. It00
CHConnor Harteinconnorhartecybersecurity.hashnode.dev·6d ago · 4 min readBTLO: MetaBTLO Meta Challenge: A Hands-On Image Metadata Investigation I recently completed the Meta challenge on Blue Team Labs Online, a digital-forensics exercise focused on image metadata analysis using an 00
Ppraveeninthecoderegistry.hashnode.dev·Aug 25 · 17 min readHow to Detect Hidden Risks in Third-Party SoftwareModern applications are rarely built entirely from code written by one engineering team. A typical production application may depend on open-source packages, commercial libraries, cloud services, APIs00
Aarosioninarosion-labs.hashnode.dev·Aug 23 · 6 min readVulnCicadaVulnCicada is a Medium Windows Active Directory machine that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is v10
OIOghenemaro Ikelegbeincybersage.hashnode.dev·Aug 17 · 3 min readDetecting Synthetic Identity FraudSome of the most damaging financial fraud out there isn't committed by criminals stealing your identity. It's committed by criminals building an identity from scratch, one that never belonged to anyon00
Rrathsarainrr-cyber.hashnode.dev·Aug 15 · 10 min readWhat We Got: From Cloud Security Platform to Operational CapabilityA few months after the operationalizing work covered in the last article, it stopped being a project. It became part of how we worked. This article is about what changed once that happened. The Metri00
Rrathsarainrr-cyber.hashnode.dev·Aug 14 · 31 min readUnderstanding OAuth 2.0: Delegation, Grant Types, and the Attacks That Actually HappenThe first time I heard the term OAuth, I didn't know what it meant. I was in a conversation with a DBA lead about something adjacent to authentication and authorization, and he mentioned, almost in pa00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
Rrathsarainrr-cyber.hashnode.dev·Aug 6 · 15 min readIdentity Foundations: Everything Before OAuthBefore any protocol makes sense on its own terms, a few things underneath it need to be settled first: what authentication and authorization actually are as distinct concepts, how identity gets carrie13N
HSHarshal Shahindelvingwithharshal.hashnode.dev·Aug 5 · 6 min readAI Security Guardrails: Building Safe and Trustworthy AI ApplicationsAs AI applications become more powerful, they also become more vulnerable to misuse, prompt injection, sensitive data leakage, hallucinations, and unsafe actions. AI Security Guardrails provide the pr00