Categories

Pick your attack surface

Six tracks covering the work I do and the content I publish. Threats & Exploits is a weekly update covering the most significant newly disclosed CVEs and exploits from the past week.

⚠ Threats & Exploits

Threats & Exploits

Current CVEs, live exploits and threat intel - broken down into clear, defender-ready briefs.

6 posts · active / weekly
🧠 AI / LLMs

AI / LLMs Journey

Learning AI in public, from machine learning basics to neural networks, LLMs and diffusion - then attacking and securing the systems built on them.

21 posts · ongoing
☸ Kubernetes Journey

Kubernetes Journey

From zero K8s knowledge to container and cloud-native attack paths - learning in public, from day one.

42 posts · complete
🌐 Web & API

Web & API Security

Web application and API pentest write-ups - auth flaws, BOLA/BFLA, injection and business-logic abuse.

1 post · active
🏛 AD & Infrastructure

AD & Infrastructure

Active Directory, internal networks and lateral movement - Kerberoasting, relaying, and privilege escalation.

Coming soon
☁ Cloud

Cloud

Cloud configuration reviews and attack paths - IAM, storage, and identity misconfigurations that matter.

Coming soon
🔓 System Breakouts

System Breakouts & More

Kiosk and restricted-shell escapes, thick-client, mobile and the rest of the engagement surface I cover.

Coming soon
📶 Wireless

Wireless & Wi-Fi

Wireless and Wi-Fi attack write-ups - WPA/WPA2 handshakes, evil twin and rogue APs, deauth, and Bluetooth/RFID where it comes up.

Coming soon