Research

  • CVE-2025-12520 – SSRF to XSS

    We discovered a Server-Side Request Forgery (SSRF) → Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin WP Airbnb Review Slider (versions < 4.3). The issue allowed attacker-controlled HTTP responses to be fetched and stored by the plugin, resulting in persistent XSS in admin and front-end contexts. The issue has been responsibly disclosed and patched…

  • Security Testing LLMs: A Guide to Penetration Testing

    Penetration testing of Large Language Models (LLMs) refers to deliberately probing and exploiting them to uncover vulnerabilities much like traditional pen testing, but focused on how malicious user inputs or content manipulations can cause dangerous or unintended behaviors. AI security testing is a specialized discipline that targets large language models and addresses the unique risks…

  • To Become a Truly Competent Blue Teamer, Take Red Team Courses

    When most people start their journey into blue teaming and SoC Analyst roles (defensive work) they gravitate toward blue team certifications. That makes sense on the surface. After all, if you want to defend against attacks, shouldn’t you study how to detect them? Well… yes and no. Blue team certs like Security+, CySA+, or even…

  • Using Macros in BurpSuite

    Web application penetration testing often involves tedious and repetitive actions especially when dealing with login sequences, CSRF tokens, and dynamic sessions. Enter macros in BurpSuite, a powerful feature that lets you automate these repetitive tasks and enable automated testing, improving efficiency and consistency. If you’ve ever wondered why your Burp Intruder attacks fail after a…

  • What Is Threat Intelligence in Cybersecurity?

    In a world where cyberattacks grow more sophisticated by the day, businesses and governments alike are turning to one powerful weapon: threat intelligence. But what is threat intelligence, really? At its core, threat intelligence refers to the collection, analysis, and application of information about potential or active cyber threats. It’s not just data it’s actionable…

  • Is Cyber Security An Entry Level Field?

    The short answer? No, cybersecurity is not an entry level field. Despite what flashy online ads and social media influencers may suggest, getting into cybersecurity isn’t as simple as taking one course and landing a job. It’s a deep, complex, and high-responsibility domain that typically requires foundational skills in IT, networking, and systems administration skills…

  • Is Cybersecurity Hard to Learn?

    The short answer? It can be challenging, but it’s absolutely learnable especially with the right mindset, resources, and persistence. Like any technical field, cybersecurity has its learning curve, but it’s not an impossible mountain to climb. In fact, thousands of people from all backgrounds have successfully broken into cybersecurity. Some started with tech degrees. Others…