HTTP/3 and QUIC: How the Web Moved to a New Transport
How QUIC rebuilt web transport on UDP: per-stream delivery, 1-RTT handshakes with TLS 1.3 inside, connection migration — and the real costs.
Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.
How QUIC rebuilt web transport on UDP: per-stream delivery, 1-RTT handshakes with TLS 1.3 inside, connection migration — and the real costs.
Build a CTF-style lab that reproduces dependency confusion and namespace squatting — then lock them down with scoped registries, lockfile pinning and reproducible builds.
Sign and verify artifacts step-by-step with Sigstore Cosign: keyless signing, transparency log entries, and admission-time verification in a hands-on lab.
Golden Ticket, Silver Ticket and Kerberoasting explained: what each forgery needs, what it bypasses, and the log signals that catch them.
How DNSSEC signs the DNS: RRSIG, DS chains anchored at the root, NSEC3 trade-offs, and the KSK rollover landing October 11, 2026.
Hijack your own lab: find and exploit BOLA and broken-auth flaws in a vulnerable API using Burp Suite — then learn the authorization checks that actually fix them.
Break your own API with OWASP ZAP: active scanning, authenticated scan contexts and API definitions in a step-by-step DAST lab you can rebuild for any target.
How eBPF runs verified, JIT-compiled programs safely in the Linux kernel — and why networking and security tools bet their stacks on it.
How SSRF turns one forged request into cloud-wide credential theft — the Capital One chain, IMDSv2, and the controls that actually block it.
Decode live aircraft ACARS and VDL2 datalink traffic with about $30 of SDR hardware, acarsdec, dumpvdls2 and Wireshark — a complete hands-on radio lab.
Agentic-AI abuse, the fall 2026 Edge CVE wave and infostealer tradecraft — this week’s defensive priorities in one briefing.
How Certificate Transparency Merkle logs, SCTs and monitors make every TLS certificate publicly auditable — and how they caught Symantec in 2015.