
Tutorials
The Autonomous Pentest Lab: Architecting a Secure Claude-to-Kali MCP Bridge

Malicious npm package ‘indexed-btree’ evades install-script defenses and detonates at runtime
The malicious indexed-btree npm package bypassed npm v12 install-script defenses using a runtime trigger, Slack and Telegram exfiltration, and Ethereum-based C2

Public Exploits Drop for Four Linux Kernel Flaws as CISA Warns of Active Exploitation: A Complete Technical Breakdown
Four Linux kernel vulnerabilities now have public root exploits, while CISA warns of three actively exploited kernel flaws. CVEs, affected versions, fixes and mitigations

How an open-weight AI model hacked TikTok: the DepthFirst Labs camera and microphone exploit
Researchers at DepthFirst Labs used an AI agent to exploit TikTok code, demonstrating a zero-click RCE chain that could access a phone’s camera, microphone and photos

Chat Control 2.0: The September 29 Trilogue and the Future of Digital Privacy in Europe
Chat Control 2.0 explained: what the September 29 EU trilogue means for encryption, private messages, detection orders, age verification and Chat Control 1.0

Click2Shell Explained: Anatomy of the Critical WordPress Pre-Auth RCE Chain
Click2Shell is a critical WordPress pre-auth RCE chain patched in WordPress 7.1.1. Learn how the exploit works, its impact, PoC, and how to secure WordPress

Remote Desktop Software AnyDesk Hacked, Users Urged to Change Passwords
AnyDesk hacked: Cyberattack compromises production systems, raising concerns over source code security and user data. Immediate actions taken, passwords revoked, and new security measures implemented

Jenkins Security Alert: Critical Vulnerability Exposes Servers to Remote Code Execution (RCE) Attacks
Jenkins Security Alert: Critical vulnerability poses remote code execution risk. Servers exposed. Immediate action required to patch and safeguard systems against potential exploitation. Stay vigilant










