Cyber Security & Tech Articles

Tech Layoffs Continue, But Not Everyone Is Losing
Tech Layoffs Continue, But Not Everyone Is Losing
I’ve been analyzing the headlines about mass layoffs at Amazon, Google, and Microsoft while seeing the exact same companies offer $300k+ packages for AI Specialists, and I think we need to stop... Read more...
The Unofficial OSWE Study Guide & Notes
The Unofficial OSWE Study Guide & Notes
If you are preparing for the OffSec Web Expert (OSWE) exam, formerly known as AWAE OSWE, you likely already know the hard truth: this is a grueling 48-hour marathon of... Read more...
Web Application Firewalls Explained
Web Application Firewalls Explained
I see this misconception constantly: developers or junior admins slap a Web Application Firewall (WAF) in front of a vulnerable app and think they are "secure." The article isn't just... Read more...
HTB Imagery Writeup
HTB Imagery Writeup
I see it all the time in pentest reports: Stored XSS gets rated as Medium or even Low because it requires user interaction. But my recent run through HackTheBox's Imagery... Read more...
The Unofficial HTB CWES Notes: Previously HTB CBBH
The Unofficial HTB CWES Notes: Previously HTB CBBH
If you are transitioning from the Old HTB CBBH (Certified Bug Bounty Hunter) to the newly rebranded HackTheBox Certified Web Exploitation Specialist (HTB CWES), you already know that the game... Read more...
TryHackMe Django: CVE-2025-64459 Walkthrough
TryHackMe Django: CVE-2025-64459 Walkthrough
This walkthrough explains how CVE-2025-64459 impacts Django-based applications and demonstrates the real-world exploitation path inside a TryHackMe lab. It focuses on understanding the root cause of the vulnerability, how improper... Read more...
TryHackMe Data Integrity & Model Poisoning Walkthrough
TryHackMe Data Integrity & Model Poisoning Walkthrough
This walkthrough breaks down Data Integrity and Model Poisoning from a practical, attacker-and-defender perspective.  It explains how trust in data pipelines can be exploited, how poisoned inputs impact machine learning... Read more...
TryHackMe WAF: Exploitation Techniques Walkthrough
TryHackMe WAF: Exploitation Techniques Walkthrough
This article reframes the TryHackMe WAF Exploitation lab as a mindset test, not a payload contest. The box evaluates your understanding of how Web Application Firewalls actually fail in the... Read more...
Cybersecurity Certification Mentoring and Coaching
Cybersecurity Certification Mentoring and Coaching
The material is out there. The problem is a lack of strategy. Get a personalized roadmap to navigate your next certification without wasting weeks on the wrong topics. The material... Read more...
SSTI Explained: HTB Hacknet Walkthrough
SSTI Explained: HTB Hacknet Walkthrough
Most writeups for SSTI will just give you the {{ 7*7 }} payload and the pickle script to copy-paste. I think that’s useless. The real value of HTB Hacknet is... Read more...
The Cyber-Career Accelerator: Cyber security coaching
The Cyber-Career Accelerator: Cyber security coaching
Most aspiring cybersecurity professionals spend 80% of their time figuring out what to study and only 20% actually studying. You buy a course on Udemy then you switch to a... Read more...
The Ultimate Network Engineer Cheat Sheet
The Ultimate Network Engineer Cheat Sheet
If you are looking for the definitive network engineer cheat sheet, you can stop searching. Whether you are a sysadmin battling a volatile server farm or a Red Teamer mapping... Read more...