Skip to content

Tag

#security

14posts

Developer Tools12 min read

authentik Explained: IdP, SSO, SAML, OAuth2/OIDC, Okta, and Auth0

A smooth primer on authentik, IdP, SSO, and login protocols that turns identity-management jargon into a usable mental model.

#security#identity#sso
Updated
AI & Agents13 min read

Strix AI Pentesting: What It Is, How It Works & Setup Guide

What is Strix? The open-source autonomous AI pentesting agent (usestrix/strix) that proves real exploits with reproducible sandboxes - no noisy CVE list spam.

#ai#security#pentesting
AI & Agents8 min read

Anthropic Cybersecurity Skills: The Binder Behind a Senior Analyst

754 Markdown playbooks an AI agent can load: Volatility3 runs, Kerberoasting hunts, cloud breach scoping. Mapped to ATT&CK, NIST, ATLAS, D3FEND.

#security#ai-agents#claude-code
Developer Tools5 min read

The VSCode extension that robbed GitHub

GitHub confirmed ~3,800 internal repos were stolen after one employee installed a trojanized Nx Console extension - and the attackers want $50K for the data.

#security#vscode#supply-chain
AI & Agents5 min read

Open CTFs Are Now Pay-to-Win, and Frontier AI Did It

A top-10 CTF competitor argues that Claude Opus 4.5 and GPT-5.5 have automated enough of the scoreboard that open CTFs no longer measure human security skill.

#ctf#security#ai
System Design6 min read

Five Days vs. Five Years: Apple's New Kernel Defense, Cracked

Apple spent five years building MIE on M5 to stop kernel exploits. Calif cracked it in five days with AI, then drove to Apple Park to deliver the report.

#security#apple#macos
Developer Tools5 min read

hackingtool: All-In-One Terminal Arsenal for Pentesters

The Python TUI putting 185+ security tools - BloodHound to Nuclei - one search command away. A catalog, not a weapon.

#pentesting#security#ctf-tools
Developer Tools8 min read

Maigret: The OSINT Detective That Finds Every Account

OSINT tool that checks 3,000+ platforms for a username, recursively hunts linked accounts, and generates full HTML/PDF dossiers; no API keys required.

#osint#python#cli
AI & Agents5 min read

Android Reverse Engineering Skill: Unpacking APKs Like a Pro

A Claude Code skill that decompiles Android apps and extracts their hidden APIs - no source code required. For security pros, hackers, and the curious.

#android#reverse-engineering#security
Updated
AI & Agents9 min read

PentAGI: What It Is, Autonomous AI Pentesting & Docker Setup Guide

What is PentAGI? Complete guide to the autonomous AI pentesting platform (vxcontrol/pentagi): orchestrate Kali Linux tools in Docker to exploit flaws.

#ai#security#pentesting
Updated
AI & Agents11 min read

Shannon Explained: The Autonomous AI Pentester That Breaks Your App Before Hackers Do

Shannon by Keygraph is a fully autonomous AI penetration tester that executes real exploits - not just advice - across web apps and networks.

#ai#security#pentesting
Software Craft4 min read

Verify vs Cert: The Python Requests Handbook

Understanding SSL/TLS in Python Requests: The 'verify' and 'cert' arguments explained with interactive animations.

#security#software-craft
System Design6 min read

API Certificates: The Mastery Guide to Debugging & The Chain of Trust

Stop guessing with SSLErrors. A mastery-level guide to the Chain of Trust, openssl debugging, and proving exactly whose fault it is.

#system-design#security#api
System Design5 min read

Authentication vs. Authorization vs. OAuth: The 'ID Card' Mental Model

Stop mixing up 401 and 403. A mastery guide to AuthN (Who you are), AuthZ (What you can do), and the OAuth Valet Key.

#system-design#security#api