logo

TrustedSec blog

ID: 2426fd19-0848-58fe-abbd-11e325191761

STIX ID: identity--2426fd19-0848-58fe-abbd-11e325191761

Feed Type: skeleton

Earliest post: 2023-09-20

Latest post: 2026-04-14

The TrustedSec blog shares practical, expert-driven cybersecurity content focused on penetration testing, red teaming, and offensive security techniques, along with real-world insights to help organisations identify and reduce security risks.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem2026-05-21TrueTrue
ARP Around and Find Out: Hijacking GPO UNC Paths for…2026-04-30TrueTrue
Benchmarking Self-Hosted LLMs for Offensive Security2026-04-14TrueTrue
IAM the Captain Now – Hijacking Azure Identity Access2026-04-09TrueTrue
Building a Detection Foundation: Part 5 - Correlation in Practice2026-04-07TrueTrue
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found2026-03-19TrueTrue
LnkMeMaybe - A Review of CVE-2026-251852026-03-13TrueTrue
Building a Detection Foundation: Part 1 - The Single-Source Problem2026-03-06TrueTrue
Notepad++ Plugins: Plug and Payload2026-02-19TrueTrue
Keys to JWT Assessments - From a Cheat Sheet to a Deep Dive2026-02-05TrueTrue
LDAP Channel Binding and LDAP Signing2026-01-29TrueTrue
Adventures in Primary Group Behavior, Reporting, and Exploitation2026-01-22TrueTrue
Abusing Windows Built-in VPN Providers2025-12-16TrueTrue
CORS Findings: Another Way to Comprehend2025-12-15TrueTrue
Hack-cessibility: When DLL Hijacks Meet Windows Helpers2025-11-25TrueTrue
Detecting Active Directory Password-Spraying with a Honeypot Account2025-10-17TrueTrue
Skimming Credentials with Azure's Front Door WAF2025-10-14TrueTrue
Hiding in the Shadows: Covert Tunnels via QEMU Virtualization2025-10-02TrueTrue
Dragging Secrets Out of Chrome: NTLM Hash Leaks via File URLs2025-09-25TrueTrue
WSUS Is SUS: NTLM Relay Attacks in Plain Sight2025-09-19TrueTrue
Red Alert: Massive cyber wire fraud attacks on US Companies2025-08-07TrueTrue
The Backup Paradigm Shift: Moving Toward Attack Response Systems2025-08-06TrueTrue
Attacks on the Rise Through Office 3652025-08-06TrueTrue
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-422782025-08-04TrueTrue
Let's Clone a Cloner - Part 3: Putting It All Together2025-07-31TrueTrue
Azure's Front Door WAF WTF: IP Restriction Bypass2025-07-10TrueTrue
CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe2025-07-08TrueTrue
Full Disclosure, GraphGhost: Are You Afraid of Failed Logins?2025-07-03TrueTrue
Abusing Chrome Remote Desktop on Red Team Operations: A…2025-07-01TrueTrue
Achieving Passive User Enumeration with OneDrive2025-06-30TrueTrue
OneDrive to Enum Them All2025-06-30TrueTrue
Bypassing Virtualization and Sandbox Technologies2025-06-20TrueTrue
Attacking JWT using X509 Certificates2025-06-17TrueTrue
Hunting Deserialization Vulnerabilities With Claude2025-06-12TrueTrue
Red Team Gold: Extracting Credentials from MDT Shares2025-05-20TrueTrue
Office 365 - Advanced Threat Protection (ATP): Features and Shortfalls2025-04-25TrueTrue
Discovering the Anti-Virus Signature and Bypassing It2025-04-25TrueTrue
Threat Hunting - Outbound RDP Surprises2025-04-25TrueTrue
Malicious Macros for Script Kiddies2025-04-25TrueTrue
Critical Guidance on the CVE 2022-22965 (Spring4Shell) Vulnerability2025-04-25TrueTrue
CVE-2022-24696 - Glance by Mirametrix Privilege Escalation2025-04-25TrueTrue
WMI Providers for Script Kiddies2025-04-25TrueTrue
Diving into Pre-Created Computer Accounts2025-04-25TrueTrue
Practical OAuth Abuse for Offensive Operations – Part 12025-04-25TrueTrue
How Far Should You Let Penetration Testers Go?2025-04-22TrueTrue
Kubernetes for Pentesters: Part 12025-04-08TrueTrue
EKUwu: Not just another AD CS ESC2025-03-27TrueTrue
Offensively Groovy2025-03-27TrueTrue
Spec-tac-ula Deserialization: Deploying Specula with .NET2025-03-27TrueTrue
Malware Series: Process Injection Mapped Sections2025-03-27TrueTrue

1–50 of 299