Tag
#security
14posts

authentik Explained: IdP, SSO, SAML, OAuth2/OIDC, Okta, and Auth0
A smooth primer on authentik, IdP, SSO, and login protocols that turns identity-management jargon into a usable mental model.

Strix AI Pentesting: What It Is, How It Works & Setup Guide
What is Strix? The open-source autonomous AI pentesting agent (usestrix/strix) that proves real exploits with reproducible sandboxes - no noisy CVE list spam.

Anthropic Cybersecurity Skills: The Binder Behind a Senior Analyst
754 Markdown playbooks an AI agent can load: Volatility3 runs, Kerberoasting hunts, cloud breach scoping. Mapped to ATT&CK, NIST, ATLAS, D3FEND.

The VSCode extension that robbed GitHub
GitHub confirmed ~3,800 internal repos were stolen after one employee installed a trojanized Nx Console extension - and the attackers want $50K for the data.

Open CTFs Are Now Pay-to-Win, and Frontier AI Did It
A top-10 CTF competitor argues that Claude Opus 4.5 and GPT-5.5 have automated enough of the scoreboard that open CTFs no longer measure human security skill.

Five Days vs. Five Years: Apple's New Kernel Defense, Cracked
Apple spent five years building MIE on M5 to stop kernel exploits. Calif cracked it in five days with AI, then drove to Apple Park to deliver the report.

hackingtool: All-In-One Terminal Arsenal for Pentesters
The Python TUI putting 185+ security tools - BloodHound to Nuclei - one search command away. A catalog, not a weapon.

Maigret: The OSINT Detective That Finds Every Account
OSINT tool that checks 3,000+ platforms for a username, recursively hunts linked accounts, and generates full HTML/PDF dossiers; no API keys required.

Android Reverse Engineering Skill: Unpacking APKs Like a Pro
A Claude Code skill that decompiles Android apps and extracts their hidden APIs - no source code required. For security pros, hackers, and the curious.

PentAGI: What It Is, Autonomous AI Pentesting & Docker Setup Guide
What is PentAGI? Complete guide to the autonomous AI pentesting platform (vxcontrol/pentagi): orchestrate Kali Linux tools in Docker to exploit flaws.

Shannon Explained: The Autonomous AI Pentester That Breaks Your App Before Hackers Do
Shannon by Keygraph is a fully autonomous AI penetration tester that executes real exploits - not just advice - across web apps and networks.

Verify vs Cert: The Python Requests Handbook
Understanding SSL/TLS in Python Requests: The 'verify' and 'cert' arguments explained with interactive animations.

API Certificates: The Mastery Guide to Debugging & The Chain of Trust
Stop guessing with SSLErrors. A mastery-level guide to the Chain of Trust, openssl debugging, and proving exactly whose fault it is.

Authentication vs. Authorization vs. OAuth: The 'ID Card' Mental Model
Stop mixing up 401 and 403. A mastery guide to AuthN (Who you are), AuthZ (What you can do), and the OAuth Valet Key.