Everyone Has A Plan Until They Get Punched In The SonicWall
Why any organization with a public IP has to plan for un-patchable zero-day exploitation, not just targeted attacks.
Writing on security, technology, and related topics.
Why any organization with a public IP has to plan for un-patchable zero-day exploitation, not just targeted attacks.
Taking a 'safely' disclosed WordPress RCE most of the way to a full unauthenticated exploit chain with public research, a patch diff, and an LLM, and the rest with a public PoC.
Consolidating my scattered writing under one roof, without giving up digital ownership.
On consuming valuable ideas from people whose other beliefs you find repugnant, and why avoidance is the choice to be passive.
Enshittification comes for us all.
The misaligned incentives, on both the client and consultant sides, that doom most purple team engagements before they start.
What real-world heists and insider-threat data reveal about who actually breaks into buildings, and what a physical penetration test is worth.
The hidden incentive to make more money, not to reduce risk, that pushes the security industry toward compliance theater.
Why phishing simulations punish employees for a problem they can't solve, and what actually reduces the risk of a successful phish.
A largely unfiltered and slightly refined response to upper management's annoying idealisms.
New research for using `less` as a persistence mechanism.
RSS is supposed to be for the readers, not you.
A collection of legitimate services and how to use them for evil.
A nice way to share without writing an essay.
A collection of blogs/feeds I read on a regular basis.
An introduction to burnout and how to recover from it.
The old internet was better anyway.
Reasons for not using Conduit anymore.
A free guide to free resources for learning exploit development.
...like me.