All Posts

Mastering Nimbus Beginner's Guide from HackTheBox

Beginner’s Guide to Conquering Nimbus on Hack the Box

The CyberSec Guru

Conquer Nimbus on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

CVE-2026-42530 & CVE-2026-42055

Two 9.2s in stock NGINX: inside the HTTP/3 QPACK use-after-free and the gRPC heap overflow F5 just patched

The CyberSec Guru

F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCs

Zero Trust Security

Zero Trust Security: What It Actually Means When You Strip Away the Marketing

The CyberSec Guru

Deep technical breakdown of Zero Trust architecture - identity, device trust, mTLS, NIST 800-207, ZTNA, and complete implementation roadmap

FortiBleed

FortiBleed: How a Russian-Speaking Threat Group Quietly Compromised 75,000 Fortinet Firewalls Worldwide

The CyberSec Guru

FortiBleed exposed verified credentials for 75,000 Fortinet firewalls across 194 countries. Here's the full technical breakdown of how it was all done

Mullvad vs Proton VPN

Mullvad vs Proton VPN: The Ultimate Privacy-First Technical Breakdown

The CyberSec Guru

Mullvad vs Proton VPN - deep technical comparison: RAM servers, DAITA, GotaTun, 2023 police raid, ProtonMail controversy, audits, payments

Mastra npm Supply Chain Attack

How 144 Mastra npm Packages Got Poisoned in Under an Hour And Nobody Noticed Until It Was Too Late

The CyberSec Guru

144 Mastra npm packages were compromised on June 17, 2026 via easy-day-js, a typosquatted dependency that drops a cross-platform infostealer

How a Single Rogue BGP Announcement Took Telegram Offline Across Three Continents

How a Single Rogue BGP Announcement Took Telegram Offline Across Three Continents

The CyberSec Guru

A single unauthorized BGP route from Reliance AS18101 redirected Telegram's global traffic into a blackhole taking users offline in India and more

Proton’s Privacy Promise Has an Asterisk

Proton’s Privacy Promise Has an Asterisk: what 40,000 government orders actually tell us

The CyberSec Guru

Proton’s privacy claims face scrutiny as 40,389 complied government orders, metadata exposure, IP logging, and MLAT cases reveal the limits of it

PSN Single-Letter Username Glitch

PSN’s One-Letter Username Glitch: What Actually Happened Under the Hood

The CyberSec Guru

A PSN glitch let users claim single-letter usernames blocked since 2006. Here's the validation failure behind it and what Sony will likely do next

Instructure Canvas Breach

The Instructure Canvas Breach (2026): How a Single Support Ticket Exposed 275 Million Students

The CyberSec Guru

The Instructure Canvas breach exposed 275M students through stored XSS, hijacked sessions, weak CSP, and ShinyHunters’ large-scale data theft