RSSAmplifier

Blog

Security Café

Security Research and Services

securitycafe.roRSS feed ↗10 posts

Latest posts

Weaponizing SMB Shares to Steal Domain Credentials

In internal penetration tests and red team engagements, an account with write privileges over an SMB share can be your best bet to go further Continue reading

When AI Understands Code: Prompt Injection to RCE

This is part 1 of a multi-part series exploring the intersection of artificial intelligence and cybersecurity. As AI systems become increasingly powerful and deeply integrated Continue reading

Mobile Pentesting 101 – The Death of ADB Backup: Modern Data Extraction in 2026

For a long time, the adb backup command was the “Swiss Army Knife” for mobile pentesters. It allowed us to pull the private /data/data/ folder Continue reading

Mobile Pentesting 101: How to Pull APKs from Work Profile – A Real-World Intune Challenge

Introduction During a recent mobile application penetration test, I encountered a challenging scenario that many mobile security testers face nowadays: extracting APKs from applications installed Continue reading

Azure CloudQuarry: Searching for secrets in Public VM Images

After the initial investigation entitled “AWS CloudQuarry: Digging for secrets in Public AMIs” was finalized, we continued with the same idea on Azure in order Continue reading

Chained Vulnerabilities in Web Applications

Introduction Vulnerability chaining, also known as exploit chaining, is the process of combining multiple vulnerabilities to achieve a more significant or impactful attack. In complex Continue reading

Mobile Pentesting 101: How to Install Split APKs

In modern mobile app development, split APKs are becoming increasingly common. They divide a large app into smaller packages, allowing for more efficient downloads and installations, especially on devices with limited storage. For mobile penetration testers, understanding and working with split APKs is essential. Continue reading

Red Team Finds A Way – (IN)Secure By Design

In our previous post, Red Team Finds A Way – Exploiting The Human Factor, we explored how the human element can often be the weakest Continue reading

AWS vs Azure: A “Secure by default” comparison

Whether you are in charge of deciding what Cloud solution to choose for your organization or you are a Security Professional trying to decide what Continue reading

An ex psychologist’s journey into Cyber Security

How it all started What if I told you that the machines with 99 percentage fail chance wouldn’t do it… but a human with 1 Continue reading