The CyberSec Guru

Beginner’s Guide to Conquering Paperwork on Hack the Box
Conquer Paperwork on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

Wi-Fi Networks (802.11): The Complete Guide for Penetration Testers
Complete 802.11 pentesting guide: WPA2 handshake capture, PMKID attacks, WPS cracking, and Evil Twin setup with aircrack-ng commands

How VPN Detection Works and the Protocol Stack Built to Outrun It
Governments are increasingly targeting VPNs after age verification laws. Learn how Deep Packet Inspection works and why Shadowsocks etc are needed

GhostLock (CVE-2026-43499): a fifteen-year-old rtmutex bug just handed root to anyone with a shell
GhostLock (CVE-2026-43499) is a 15-year rtmutex use-after-free giving root to any local Linux user. Full technical breakdown of the exploit chain

Accenture, 888, and the Anatomy of a Believable Breach Claim
Threat actor "888" claims 35GB of Accenture source code, SSH keys, and Azure tokens. A technical breakdown of the claim, the credentials, and what's actually verified

The blog is getting a video series. First one drops next week
The first video in a new cybersecurity and networking course series is free and ad supported. Full library access requires membership. Watch it next week

GitHub’s “Verified” Commit Isn’t Unique, and Its AI Agent Will Leak Your Private Repos If You Ask Nicely
New CMU research shows GitHub's Verified commit badge isn't a unique fingerprint, plus how GitLost tricks GitHub's AI agent into leaking private repos

Januscape (CVE-2026-53359): The 16-Year-Old KVM Bug That Lets a Guest VM Take Down Its Host
CVE-2026-53359, dubbed Januscape, is a 16-year-old KVM use-after-free letting guest VMs crash or escalate into the host. Here's the full technical breakdown

GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention
Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout






