Cyber Security & Tech Articles

Microsoft Office RCE Zero-Day (CVE-2026-21509) Explained
Microsoft Office RCE Zero-Day (CVE-2026-21509) Explained
In the relentless cycle of cybersecurity patches and panic, it is easy to become desensitized to the term Zero-Day. However, the recently disclosed CVE-2026–21509 demands our immediate and undivided attention,... Read more...
GeoServer: CVE-2025-58360 Vulnerability Analysis
GeoServer: CVE-2025-58360 Vulnerability Analysis
If you think XML External Entity (XXE) vulnerabilities are a relic of the past or just theoretical noise, this walkthrough on the GeoServer CVE-2025-58360 is the wake-up call you need.... Read more...
HTB CodePartTwo Writeup
HTB CodePartTwo Writeup
While many boxes challenge you to find a missing patch or a weak password, HTB CodePartTwo machine attacks the fundamental trust developers place in third-party libraries to sanitize execution environments.... Read more...
HackTheBox Sherlock Brutus Writeup
HackTheBox Sherlock Brutus Writeup
Introduction HackTheBox Brutus is a beginner-level DFIR challenge that includes an auth.log file and a wtmp file as key artifacts. Using these, we’ll track how an attacker conducted an SSH brute force attack, ultimately... Read more...
OSCP vs HackTheBox CPTS 2026 Review
OSCP vs HackTheBox CPTS 2026 Review
 Legacy vs. Innovation For years, the OSCP has been the undisputed Gold Standard of entry-level pentesting certifications. It is the certification HR managers look for. However, Hack The Box (HTB) has... Read more...
HackTheBox Spookypass Challenge Writeup
HackTheBox Spookypass Challenge Writeup
Introduction The “SpookyPass” challenge from Hack The Box’s Hack The Boo 2024 event is a reverse engineering task categorized as very easy. You are provided with an executable that prompts... Read more...
The Ultimate Guide to Active Directory and Windows Server Penetration Testing
The Ultimate Guide to Active Directory and Windows Server Penetration Testing
1. Introduction Active Directory (AD) is not just a directory service; it is the nervous system of the modern enterprise.  It controls who has access to what, enforces security policies,... Read more...
HackTheBox Flag Casino | Reverse Engineering Writeups
HackTheBox Flag Casino | Reverse Engineering Writeups
Mission Brief: Your team has breached a derelict gambling hall from the pre-war era. Amidst the dust and skeletal remains of former patrons, the automated staff has reactivated. A robotic... Read more...
How to use Metasploit and Nmap to Enumerate and Scan for Vulnerabilities
How to use Metasploit and Nmap to Enumerate and Scan for Vulnerabilities
In this article, we will discuss combining Nmap and Metasploit together to perform port scanning and enumerate for vulnerabilities. There certain cases where we can’t just go and run noisy... Read more...
Active Directory Pentesting | Offsec Proving Grounds Access Writeup
Active Directory Pentesting | Offsec Proving Grounds Access Writeup
Introduction Proving Grounds Access Lab is a Windows domain controller, utilizing several notable techniques. If you’re studying for OSCP or learning hacking skills, then this box is for you. What... Read more...
HackTheBox Spookypass Challenge Writeup
HackTheBox Spookypass Challenge Writeup
Introduction The “SpookyPass” challenge from Hack The Box’s Hack The Boo 2024 event is a reverse engineering task categorized as very easy. You are provided with an executable that prompts... Read more...
The Unofficial CRTP Notes: The Red Team Professional's Bible
The Unofficial CRTP Notes: The Red Team Professional's Bible
If you are preparing for the Certified Red Team Professional (CRTP) exam, you know that knowing Active Directory is not enough, you need to know how to break it. These... Read more...