RSSAmplifier

Blog

hetmehta.com

Cybersecurity research, and personal experiences by Het Mehta.

hetmehta.comRSS feed ↗16 posts

Latest posts

Breaking Down GreenPlasma and YellowKey: Windows Trust Boundaries Doing Windows Things

A beginner-friendly technical breakdown of GreenPlasma and YellowKey, two Nightmare-Eclipse Windows disclosures involving CTFMON, Object Manager abuse, WinRE, BitLocker, and the eternal comedy of Windows trusting itself too much.

Breaking Down CVE-2026-25049: How TypeScript Types Failed n8n's Security

Deep technical analysis of CVE-2026-25049: How type confusion bypassed n8n's security patch and why TypeScript types aren't runtime security boundaries

A Rationalist Drinks Diet Coke

A pretty honest take on why a cybersecurity nerd keeps Diet Coke around science, ritual, and a cold can between hacks.

This Isn’t Advice

A raw, personal collection of principles and actions I’m trying to live by in a world of distractions and digital noise.

WTF is SOC 2 Compliance?

Let’s break down SOC 2 compliance like you're five — but with real-world examples, honest advice, and a no-BS approach to what this audit actually means for your product or startup.

Understanding MCP Security: Protecting the Context Layer in AI Systems

A deep dive into Model Context Protocol security, exploring vulnerabilities, defense mechanisms, and best practices for developers building safer AI systems.

PowerShell for Hackers: Exploitation Essentials

A red teamer’s guide to PowerShell for post-exploitation: enum, privesc, persistence, and C2

The Ultimate Guide to the SOC: Cybersecurity's Nerve Center Explained

Everything you need to know about Security Operations Centers (SOCs) – why they exist, how they function, their tools, models, maturity, and implementation. A definitive resource.

Advanced Techniques for Bypassing Modern Web Application Firewalls

Explore advanced WAF bypass techniques including obfuscation, encoding, parameter pollution, and CDN flaws to evade modern detection systems and exploit critical web vulnerabilities.

Absurdism in Modern Life: Finding Meaning in the Meaningless

Feeling lost in the search for meaning? Exploring how to find your own 'point' even when the universe doesn't give easy answers, especially in our fast-paced modern world.

Hacking Your Brain: Can We Enhance Intelligence?

Exploring various methods of 'brain hacking' from lifestyle changes and cognitive training to nootropics and technology, discussing their effectiveness, scientific backing, and ethical implications.

JSON Interoperability Vulnerabilities: A Deep Dive

Exploring JSON interoperability vulnerabilities, including duplicate keys, key collisions, serialization quirks, and floating-point representation errors.

Hacking AI: Exploiting OWASP Top 10 for LLMs

A deep dive into the security vulnerabilities of LLMs as outlined in OWASP’s Top 10, with real-world attack scenarios, exploitation techniques, and mitigation strategies.

Cybersecurity Compliance in 2025

The regulatory landscape surrounding cybersecurity is becoming increasingly complex and stringent.

The Philosophy of Time – Lessons from Seneca

Exploring Seneca's philosophy on time, its fleeting nature, and how we can use it wisely in our modern lives.

Why Does Life Suck in 2025?

A deep dive into why 2025 feels like a struggle, from inflation and job markets to social media and AI taking over everything.