What if we told you that just a single HTML tag could quietly reroute a user’s CSS, JavaScript, images, and even their form submissions to a server that we control, but without any #XSS?
Enter Base Tag Injection. Watch this video by Alex (@appSecExp) to see exactly how it works.…
Looking for a resource to learn #PowerShell?
Andrew Prince's got you: youtu.be/GyvEMcMh3rc
Today's video serves as a primer into the powerful and versatile Windows framework. Add it to your skillset today by watching this quick course, and go even further with the cheat…
Studying for cybersecurity might seem intense, and it's hard to work up the motivation when you're busy as is. But what if we told you, it wasn't about motivation?
Today, Alex (@appSecExp) has some tips to share about how to fit #cybersecurity studying in, even when you have a…
𝗣𝗶𝗰𝘁𝘂𝗿𝗲 𝘁𝗵𝗶𝘀: You’re installing a popular #JavaScript library. Shortly after installation, you discover it has been stealing your secrets, mining crypto, or opening a backdoor on your machine.
This is just how supply chain attacks often unfold in the Node.js…
Alex (@appSecExp) is in Portugal as part of the "Hack the Planet" series from Matosinhos.tech, taking the conversation from livestream to real life! He'll be tackling AI & Web App pentesting at this event.
We're very proud when TCM Security members step into the…
If you are bored you can always:
- Build your own operating system
- Build your own game engine
- Build your database
- Build your compiler
- Build your virtual machine
- Build your web server
𝗪𝗮𝗻𝘁 𝗮 𝗺𝗼𝗿𝗲 𝘀𝗲𝗰𝘂𝗿𝗲 𝗪𝗼𝗿𝗱𝗣𝗿𝗲𝘀𝘀 𝘀𝗶𝘁𝗲? Alex's got you! Today we are covering something different: How to build a secure WordPress site. A few of you have asked about this, and we hope this video helps! Discover how to keep things up to date with hardening…
Developers, tired of DOM XSS in your web applications? 😩 We were too. See how we refactored our code to solve Trusted Types violations in Gmail & AppSheet. Your guide to a safer web is here!
bughunters.google.com/blog/585078655…
Cybersecurity professionals face constant stress, high expectations, and endless demands. This is a toxic mix that can lead to burnout. But burnout isn’t simply about feeling stressed or overworked; it's a chronic condition that can leave you feeling drained, disengaged, and…
Roses are red, violets are blue. We have a new cert coming out in the next few weeks - what is it, do you have a clue? 💝
See our existing (and well-loved) certifications here! tcm.rocks/certs-x
Have you heard of Cookie Jar Overflows? This classic yet under-discussed technique allows attackers to remove cookies from a target user and replace them with their own. Combined with vulnerabilities like session fixation, it can have serious impacts, including account takeovers.…
174 Followers 91 FollowingDeveloper, Creator, Security Tester. Follow me and learn from my experiences across all IT tools and technologies via tutorials and reviews.
961 Followers 3K FollowingAll opinions are my own unless I borrowed them from someone else.
Founder & Queen of Details @AppSec_Village
Head of Field/Channel Marketing, EMEA @Penterasec
1K Followers 198 FollowingDuring your time as a student we embraced many opportunities together. Now you’re ready to take on new challenges, the Alumni Association is still here for you.
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
262 Followers 2K FollowingCyber Futurologist, Rustacean, interested in the nuts and bolts of things, in truth, only atoms and void. E1b1b1a1b1a6a1c~
Mastodon:@[email protected]
169 Followers 1K FollowingAfter welding & fitting pipe for 20+ yrs, I've been studying daily to become a Penetration Tester and help companies secure their networks by identifying vulns.
58 Followers 62 Followingshe/her. AppSec Engineer. International Speaker. Occasional blogger. Choose happiness. Making security less daunting with a smile ;) Opinions my own.
3K Followers 513 FollowingHacker | I try to hack things, or whatever. Memes are my own and represent my employer (me) | Formerly @microsoft & BB triage
386 Followers 1K FollowingA driven consultant who wants the best for the customer. #oscp #pnpt #oswp #eCPPTv2 #LPTMaster #vmware #vExpert #storage #cehmaster #ITArchitect #OneGate