MCMarco Carolainblog.redghostops.com·4d ago · 8 min readGhostLoot part 2: the Microsoft cookie mess, the inbox, and the Google wallPart 1 got the loot out of Evilginx's session list. Part 2 is what I learned the hard way after that: which Microsoft cookie is actually money, which "TTL" is a fiction, how the panel had to stop bein00
AJAmartya Jhainsecurity-research.hashnode.dev·5d ago · 8 min readRed Team Authorization: Solving the Paradox of Testing People Who Can't Know They're Being TestedA red team engagement exists to answer one question: can your security team detect and respond to a real attack. For that answer to mean anything, the security team being tested, the blue team, cannot00
4F404 Foundersin404-founders.com·Sep 2 · 12 min readCISA AA26-237A: Two SOCs, One SurvivesThe red team read the security team's email. That detail from CISA advisory AA26-237A, released August 25, 2026, is the cleanest summary of what went wrong at Organization A. The red team compromised 10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 18 min readBrunnerCTF 2026 : The Three Ways WriteupSummary Two connected challenges built around the same Gitea/Drone/rollout-agent environment. The first stage (Flow) gets code execution on the Drone CI runner. The second stage (Feedback / Continuous00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 18 · 5 min readTryHackMe : Bugged - WriteupOverview Bugged is an easy TryHackMe box built around an MQTT broker (Mosquitto) that allows anonymous connections. The broker exposes normal-looking IoT device telemetry alongside a hidden backdoor t00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 6 · 3 min readClaude Code Just Hijacked My Workflow… and My Screen Started Glowing I asked Claude Code to do one of the most boring tasks imaginable. “Find the music file I made.” That’s it. No penetration testing. No coding marathon. No AI agent swarm coordinating across containers02S
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 7 min readTryHackMe : CryptoCabana WriteupOverview CryptoCabana is a fake crypto-backup service hosted as an Azure Static Website. The attack path chains together four separate misconfigurations: A low-privilege Azure user with only Reader o10
AAAhmed Awad ( NullC0d3 )innullc0d3.hashnode.dev·Jul 28 · 9 min readHunterX: The AI-Powered Offensive Security Platform Redefining Red Teaming, Bug Bounty Hunting, and Penetration TestingTraditional Vulnerability Scanners Are Reaching Their Limits The cybersecurity industry has spent decades improving vulnerability scanners. They became faster. They became capable of sending millions 10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 24 · 18 min readTryHackMe : Enterprise WriteupSummary Enterprise is an Active Directory box that starts as a classic external AD footprint (DNS, Kerberos, LDAP, SMB, RDP, WinRM) plus two extra web ports: an IIS site on 80 and a Bitbucket-branded 10