Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets
A practical guide to software supply chain security covering dependency risks, secrets exposure, CI/CD trust failures, artifact integrity verification, SBOM management, and real-world attack…
Read analysis →
HMMNM is an independent cybersecurity education and research practice led by Prabhu Kalyan Samal. We publish hands-on ethical hacking tutorials, detection engineering guides, weekly threat intelligence, and deep dives into the breaches that shaped the industry — so students, developers, and defenders learn security by studying how it really breaks.
Featured Posts
Security
Exploitation techniques, vulnerabilities, and defense strategies
Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets
A practical guide to software supply chain security covering dependency risks, secrets exposure, CI/CD trust failures, artifact integrity verification, SBOM management, and real-world attack…
Read analysis →
Ransomware Evolution 2016-2026: What Defenders Keep Missing
A decade analysis of ransomware evolution from 2016 to 2026, covering RaaS operations, double extortion, initial access brokers, living off the land techniques, and…
Read analysis →
Deep Dive into Server-Side Template Injection (SSTI)
A deep dive into Server-Side Template Injection (SSTI) — how template engines turn attacker input into RCE, with discovery, exploitation and defense patterns.
Read analysis →
Request Smuggling Explained: Detection and Mitigation in Depth
In-depth guide to HTTP request smuggling attacks. Learn how to exploit discrepancies between frontend proxies and backend servers in both HTTP/1.1 and HTTP/2 environments…
Read analysis →
Agentic AI Security: Attack Surface in Autonomous Systems
A practical guide to agentic AI security covering goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, multi-agent trust issues, and defense frameworks…
Read analysis →
Learn step by step
Twenty guided paths — web pentesting, bug bounty, incident response, threat modeling, cloud, and more — with progress tracking, no account needed.
Explore Learning Paths →Need it done for you?
Hmmnm offers professional security services — from penetration testing, red teams, AD, containers, wireless, AI security and virtual CISO — built on the research you read here.
View Security Services →Security Products
Customizable compliance documents & checklists plus in-house security scanners — built from the research you read here.
Browse Products →Technology
MCP, APIs, cloud, and emerging tech deep dives
Beyond Security
New seriesField notes from outside the terminal — health, life and personal journeys.
What Breaking Things in Labs Taught Me That Certifications Never Did
Field notes from building this site hands-on labs: the failure intuition certifications cannot teach, and how to start with zero…
Read the story →
AI and Mental Health: Technology Meets Human Healing
AI is transforming mental health support through chatbots, mood trackers, and diagnostic tools. But can technology replace human empathy? This…
Read the story →
Never miss a security briefing.
New threat analyses, tool guides and hardening playbooks — delivered straight to your inbox, the moment they go live.
