Brute force doesnโt guess โ it grinds through every possible password until one works.
Short and simple passwords can fall fast. Add length, complexity, and variety, and cracking time jumps from minutes to years or beyond.
Here is why strong passwords still matter ๐๐
Find a high-res pdf book with all my cybersecurity related infographics from https://study-notes.org
#cybersecurity #infosec #informationsecurity #passwords #pentesting
Confidence in Automated AI Vulnerability Scanning Plummets
Confidence in automated AI vulnerability scanning has taken a nosedive, with a recent survey revealing a dramatic drop from 29% to 9% in organizations relying solely on AI for testing. Instead, nearly half are turning to a hybrid approach, combining AI with human expertise for more reliable results.
#AiVulnerabilityScanning #AutomatedVulnerabilityScanning #FalsePositives #HybridTestingModel #Pentesting
๐ก๏ธ GRC is broken. FedRAMP 20x might fix it
๐ We are auditing a curated version of history. Iโve worked in security long eno...
https://www.csoonline.com/article/4188995/grc-is-broken-fedramp-20x-might-fix-it.html
๐ฐ GRC is broken. FedRAMP 20x might fix it | CSO Online
๐ง You have got to be KDDI-ng โ Japanese telco exposes 14.2 million m...
๐ Japanese telco ...
๐ฐ www.theregister.com - Articles
If you have ever been curious what it actually looks like to break space systems and have not grabbed our book yet, this is a good moment to fix that.
Barnes & Noble is running a preorder sale through Friday, June 26. Get 25% off sitewide plus an extra 10% for Premium Members using code PREORDER25. "The Spacecraft Hacker's Handbook" is part of the deal.
Get it here:
https://www.barnesandnoble.com/w/the-spacecraft-hackers-handbook-andrzej-olchawa/1150118940
๐ WebDAV isn't automatically a vulnerability.
Weak authentication, exposed methods, and poor permissions are the real problem.
๐ https://7asecurity.com/blog/2026/06/webdav-security-guide/
๐ WebDAV isn't automatically a vulnerability.
Weak authentication, exposed methods, and poor permissions are the real problem.
๐ https://7asecurity.com/blog/2026/06/webdav-security-guide/
More coding!
This one is not really anything new.
It's just a tool that allows to interact with Microsoft SQL from the command line in different ways.
I used it in a few engagements I had and I thought it came in handy every time, so I decided to publish the code.
Maybe someone else will find it useful as well.
https://codeberg.org/ti-kallisti/Tessera
#foss #coding #InfoSec #pentesting #redteaming #codeberg #windows #mssql #csharp