The CyberSec Guru

Discord Is Testing Incode for Age Verification

Discord Is Testing Incode for Age Verification, and the Privacy Concerns Are Legitimate

The CyberSec Guru

Discord is running a limited trial with Incode for facial age estimation and ID scanning. Here is what the vendor actually does, what are the privacy concerns

Booking.com Hotel Extranet Breach

Booking.com’s Hotel Extranet Is a Fraud Supermarket – and Japan Is Paying the Price

The CyberSec Guru

Hackers are using ClickFix malware to steal Booking.com hotel extranet credentials, then draining bank accounts and phishing guests with real reservation data

network analysis tools

Network Analysis: The Complete Guide to CLI Tools, Packet Sniffers, tcpdump, and Wireshark

The CyberSec Guru

Deep technical guide to network analysis: CLI tools, tcpdump BPF syntax, Wireshark filters, promiscuous mode, pcap vs pcapng, tshark, and practical exercises

EU Chat Control Is Back

EU Chat Control Is Back – And This Time It Might Actually Pass (Update: It Has Passed)

The CyberSec Guru

EU Chat Control is back in its final legislative round on June 29, 2026. This complete guide covers what Chat Control proposes, the full timeline from 2021, why it keeps returning, and what happens if it passes

Mastering Enigma Beginner's Guide from HackTheBox

Beginner’s Guide to Conquering Enigma on Hack the Box

The CyberSec Guru

Conquer Enigma on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

Linux page cache privilege escalation CVE-2026-46331 CVE-2026-43503

Two new Linux LPEs hit page cache from opposite ends of the kernel

The CyberSec Guru

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

CVE-2026-20896 Gitea authentication bypass

Three Vulnerabilities, One Platform: Why Your Self-Hosted Gitea/Gogs Instance Is Probably Already Owned

The CyberSec Guru

Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI's preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials

Post-Quantum Encryption

Post-Quantum Encryption: Why the US Is Racing Against a Clock It Can’t See

The CyberSec Guru

Post-quantum encryption is no longer theoretical. Full technical breakdown of ML-KEM, FIPS 203/204/205, the HNDL threat, and why the US is migrating

Alibaba Distilled Claude AI

Alibaba Stole Claude’s Brain. Here’s Exactly How They Did It.

The CyberSec Guru

How Alibaba-linked operators ran 25,000 fake accounts and 28.8M Claude exchanges to steal Anthropic's AI capabilities via distillation

ShinyHunters MSG Breach

ShinyHunters MSG Breach: 26M Records, Facial Recognition Dossiers, and a Vishing Attack That Started With a Phone Call

The CyberSec Guru

ShinyHunters leaked 45GB of Madison Square Garden data after a vishing attack on Microsoft Entra exposed 26 million records, biometric facial recognition profiles, and secret activist dossiers