The CyberSec Guru

Mastering Paperwork Beginner's Guide from Hack The Box

Beginner’s Guide to Conquering Paperwork on Hack the Box

The CyberSec Guru

Conquer Paperwork on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

Wi-Fi Hacking Guide

Wi-Fi Networks (802.11): The Complete Guide for Penetration Testers

The CyberSec Guru

Complete 802.11 pentesting guide: WPA2 handshake capture, PMKID attacks, WPS cracking, and Evil Twin setup with aircrack-ng commands

How VPN Detection Works and the Protocol Stack Built to Outrun It

The CyberSec Guru

Governments are increasingly targeting VPNs after age verification laws. Learn how Deep Packet Inspection works and why Shadowsocks etc are needed

GhostLock (CVE-2026-43499): a fifteen-year-old rtmutex bug just handed root to anyone with a shell

The CyberSec Guru

GhostLock (CVE-2026-43499) is a 15-year rtmutex use-after-free giving root to any local Linux user. Full technical breakdown of the exploit chain

Accenture Data Breach

Accenture, 888, and the Anatomy of a Believable Breach Claim

The CyberSec Guru

Threat actor "888" claims 35GB of Accenture source code, SSH keys, and Azure tokens. A technical breakdown of the claim, the credentials, and what's actually verified

The blog is getting a video series. First one drops next week

The blog is getting a video series. First one drops next week

The CyberSec Guru

The first video in a new cybersecurity and networking course series is free and ad supported. Full library access requires membership. Watch it next week

GitHub Verified commit vulnerability

GitHub’s “Verified” Commit Isn’t Unique, and Its AI Agent Will Leak Your Private Repos If You Ask Nicely

The CyberSec Guru

New CMU research shows GitHub's Verified commit badge isn't a unique fingerprint, plus how GitLost tricks GitHub's AI agent into leaking private repos

Januscape (CVE-2026-53359)

Januscape (CVE-2026-53359): The 16-Year-Old KVM Bug That Lets a Guest VM Take Down Its Host

The CyberSec Guru

CVE-2026-53359, dubbed Januscape, is a 16-year-old KVM use-after-free letting guest VMs crash or escalate into the host. Here's the full technical breakdown

GoDaddy Is Quietly Fighting for WHOIS Privacy

GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention

The CyberSec Guru

Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout