>_ Blog

News digests, tutorials, tool reviews and articles — always with sources.

News CVE & Vulnerabilities 2026-08-30

CVE-2025-30156 — Ceph CephX Hardcoded IV Enables Cluster Takeover

A newly detailed flaw in Ceph, the open-source distributed storage platform, affects versions before 20.2.4 and 19.2.6, letting an attacker

News Cybersecurity 2026-08-29

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes — including WPMU DEV

News CTF & Competitions 2026-08-29

CSAW CTF Qualification Round 2026

CSAW CTF's 2026 qualification round is an entry-level jeopardy competition built for undergraduates just getting started in security, with challenges

News CVE & Vulnerabilities 2026-08-29

CVE-2026-47856 — Spring Integration Unsafe JSON Deserialization

A newly published flaw, CVE-2026-47856, affects how Spring Integration's JSON-to-object conversion picks a deserialization target class — it trusts a

Tool Pwn 2026-08-26

pwntools: A Python Library for Pwn Challenges

Connect to a remote service, pack addresses, and find buffer offsets with cyclic patterns — pwntools removes the boilerplate around a pwn exploit.

News Cybersecurity 2026-08-26

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The U.S. Treasury Department has imposed new sanctions on Iranian hackers tied to breaches of critical infrastructure, part of a broader

News CTF & Competitions 2026-08-26

Iran Tech Olympics CTF 2026

Iran Tech Olympics CTF 2026 is running as a joint event with ASIS CTF Quals 2026, combining the two competitions into one jeopardy-style

News CVE & Vulnerabilities 2026-08-26

CVE-2026-78161 — libwebsockets CBOR Out-of-Bounds Write

A newly disclosed flaw in the libwebsockets 4.5.0 library allows an out-of-bounds write in its CBOR recording function, reachable by a

News Cybersecurity 2026-08-25

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

CISA has added a maximum-severity flaw in Oracle HTTP Server and WebLogic Server, tracked as CVE-2026-21962 with a perfect 10.0 CVSS score

News CTF & Competitions 2026-08-25

BlackHat MEA CTF Qualification 2026

Registration is now open for the qualifying round of the Black Hat MEA Capture The Flag competition, organized by Saudi Arabia's SAFCSP

News CVE & Vulnerabilities 2026-08-25

CVE-2026-78050 — Comfast CF-N1-S Stack Overflow

A stack-based buffer overflow has been found in Comfast CF-N1-S wireless routers running firmware 2.6.0.1, located in the NTP timezone

News Cybersecurity 2026-08-24

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point researchers found that Microsoft Defender's own boot-time cleanup driver, BTR.sys, can be abused to perform kernel-level file and registry changes

Got a source, tutorial or tool to suggest?

Suggest content for the blog in the Discord.

Join CTFdojo Discord