CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·5d ago · 5 min readTeaching an Autonomous Pentest Agent to Prove a Breach — Not Just Claim OneThe hardest part of an autonomous exploitation engine isn't landing a shell. It's knowing you landed one. Point an LLM-driven agent at a target and it will cheerfully report 23/23 ports popped — while10
AAAhmed Awad ( NullC0d3 )inahmedawadnullc0d3.pro·5d ago · 9 min readHunterX: The AI-Powered Offensive Security Platform Redefining Red Teaming, Bug Bounty Hunting, and Penetration TestingTraditional Vulnerability Scanners Are Reaching Their Limits The cybersecurity industry has spent decades improving vulnerability scanners. They became faster. They became capable of sending millions 10
YBYash Bhardwajindata-privacy.hashnode.dev·Jul 23 · 6 min readVulnerability Assessment vs. Penetration Testing: Why Both Are Essential for Modern CybersecurityCyber threats continue to evolve in both sophistication and frequency, making proactive security testing an essential part of every organization's cybersecurity strategy. Whether it's ransomware targe00
AKAyesha Khaninayeshakoder.hashnode.dev·Jul 22 · 8 min readDefending LLMs: What Actually Works, and Where It Still BreaksPart 1 of this series mapped how prompt injection and jailbreaking get malicious instructions into a model and past its guardrails. This post is the other half of the same coin: what defenses engineer00
VGVivek Goswamiinvivekgoswami.hashnode.dev·Jul 19 · 2 min readTryHackMe’s Room - Tomghost Walkthrough Reconnaissance I usually begin with a classic Network Mapper(nmap) scan with the service version detection and aggressive scanning. As we can see here 22,53,8009,8080 are in open state 8080 HTTP wit10
PBPradip Bhattaraiinblog.pradeepbhattarai.me·Jul 3 · 11 min readAbusing Resource-Based Constrained Delegation (RBCD) in Active DirectoryActive Directory delegation is one of those features that makes complete sense on paper and causes constant headaches in practice. It solves a real problem. It's also misconfigured in almost every env10
EAErkan Aksoyinerkanaksoy.hashnode.dev·Jun 11 · 11 min readWhy I Run Azure and Entra ID Pentesting From LinuxIntroduction Most people meet Azure security through the portal. You click around, read some role assignments, maybe run a few az commands, and it can feel like the whole job lives in a browser tab. I00
OROhm Ramwalainhashbyte20.hashnode.dev·Jun 10 · 4 min readHack The Box: TwoMillion Walkthrough - Invite Code, API Abuse & RootIntroduction TwoMillion is an Easy-rated Linux machine on Hack The Box that combines web enumeration, API abuse, command injection, credential discovery, and privilege escalation. The machine is inspi10
4F404 Foundersin404-founders.com·Jun 5 · 3 min read The AI Intern Just Joined The Red Team The New Workflow For years, breaking into a network was only part of the job. Attackers still needed to: map Active Directory identify privileged accounts understand trust relationships locate sensit00
NPNarges Pourkamaliinsafeai.blog·May 29 · 2 min readAI Security is far more complex than just tricky prompts! 🚀Recently, I started reviewing an incredible document: the "AI Security Assessment Blueprint". It has truly opened a new window of knowledge for me, answering so many of my deepest questions about AI v00