Cyber Security & Tech Articles

The Ultimate COMPTIA SEC AI+ Study Notes
The Ultimate COMPTIA SEC AI+ Study Notes
These COMPTIA SEC AI+ Study Notes are the unofficial companion, meticulously distilling 86 pages of practitioner-grade AI risk management, operational defense, and governance into a high-impact field manual. Unlike generic... Read more...
THM Wazuh: CVE-2026-25769 Walkthrough
THM Wazuh: CVE-2026-25769 Walkthrough
A critical flaw (CVE-2026-25769, CVSS 9.1) was found in Wazuh cluster communications, specifically in how the master node processes JSON messages from worker nodes. The master blindly trusts worker input... Read more...
THM Spring AI: CVE-2026-22738 Walkthrough
THM Spring AI: CVE-2026-22738 Walkthrough
This scenario revolves around a critical remote code execution flaw in Spring AI, specifically inside the Simple Vector Store component. The vulnerability is dangerous because it allows unauthenticated attackers to... Read more...
HackTheBox (HTB) Snapped Writeup
HackTheBox (HTB) Snapped Writeup
HackTheBox Snapped is built around two very modern failure patterns: exposed encrypted backups that aren’t really protected, and a race-condition privilege escalation tied to snapd. The entire compromise flows from weak... Read more...
HackTheBox DarkZero Writeup
HackTheBox DarkZero Writeup
HTB DarkZero is a two-forest assume-breach Active Directory lab. The attack chain is simply: Start with low-privileged domain creds (john.w) in darkzero.htb Enumerate MSSQL on DC01 → discover a linked server to DC02... Read more...
THM SAL2 vs HTB CDSA vs BTL2 : The Real Comparison
THM SAL2 vs HTB CDSA vs BTL2 : The Real Comparison
SYSTEM://THM SAL2 vs BTL2 vs HTB CDSA MNOTES//SEC CYBER · LABS · INTEL SYSTEM ONLINE The blue team certification space just got a new entrant, and predictably, the marketing wars... Read more...
HackTheBox (HTB) Browsed Writeup
HackTheBox (HTB) Browsed Writeup
HTB Browsed Description HTB Broswed is a medium-difficulty Linux machine centred around abusing browser extension functionality to access internal services. By uploading a malicious Chrome extension, we intercept a developer’s... Read more...
The Blue Team Cheat Sheet Every One Needs
The Blue Team Cheat Sheet Every One Needs
If you’ve spent any time exploring a career in cybersecurity particularly on the defensive side, you’ve probably encountered the same overwhelming moment many newcomers face. You decide to pursue blue... Read more...
HackTheBox Expressway Walkthrough
HackTheBox Expressway Walkthrough
HTB Expressway might be tagged as a beginner-friendly Linux machine, but I’m going to stop you right therem do not let that label fool you into casually skimming through your... Read more...
Interactive OSCP/CPTS Roadmap: HTB Machines + THM Rooms
Interactive OSCP/CPTS Roadmap: HTB Machines + THM Rooms
There is a very specific, deeply frustrating kind of paralysis that almost inevitably hits you about two weeks into any serious cybersecurity certification prep, and it is crucial to recognize... Read more...
HackTheBox Guardian Writeup & Walkthrough
HackTheBox Guardian Writeup & Walkthrough
This is a TL;DR, due to the length of the writeup, I created the full post here. HTB Guardian is a Linux machine that hides its real attack surface behind... Read more...
HTB Giveback Writeup & Walkthrough
HTB Giveback Writeup & Walkthrough
HTB Giveback Look, if you've spent any time grinding through complex lab environments or knocking out rooms, you already know that some machines are just built different and are specifically... Read more...