Weekly Threat Intel: Agentic AI, Stealer Logs, Edge CVEs
Stealer-log markets, edge-device exploitation and agentic-AI abuse: what defenders must patch, monitor and drill this week.
Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.
Stealer-log markets, edge-device exploitation and agentic-AI abuse: what defenders must patch, monitor and drill this week.
How Sigma turns SIEM detections into portable YAML, how pySigma pipelines compile them to any backend, and how to test rules like code with Atomic Red Team.
Build a local MCP security lab: intercept, audit and attack Model Context Protocol servers with proxies, rogue tools and logging you fully control.
A hands-on recon-to-exploit walkthrough: fuzz hidden endpoints and parameters with ffuf and Caido, chain the findings, and document the impact.
Agentic-AI abuse, the September 2026 CVE wave and ransomware tradecraft — this week’s defensive checklist.
How NTP and PTP keep infrastructure clocks honest, why leap seconds took down Cloudflare and Reddit, and how to run time sync you can trust.
The Kubernetes security layers that stop real cluster compromises: control plane, RBAC, Pod Security Admission, network policy and image supply chain — with a ten-point audit checklist.
SPDX vs CycloneDX compared honestly, how to generate SBOMs that match production, and the failure modes that sink real adoption — plus the EU CRA deadlines now in force.
ADS-B broadcasts aircraft position worldwide with no authentication — and GNSS spoofing corrupts it. The attacks, the documented incidents since 2022, and why there is no quick fix.
EFB operational safety: lithium thermal runaway containment, failure & redundancy policy, human factors and common-mode risk — plus AI-era EFBs from 2026 on.
How the industry defends EFBs: DO-326A/ED-202A airworthiness security, MDM hardening, signed chart data, AID isolation and continuous monitoring.
The EFB attack surface mapped: device tampering, chart data poisoning, AID attacks, malicious updates and supply chain — with real published aviation research.