News digests, tutorials, tool reviews and articles — always with sources.
Incident responders at Sygnia say the China-linked espionage group Fire Ant has widened a long-running campaign that once focused on VMware
Capture a request in Burp Suite's Proxy, edit it, and replay it with Repeater — the core workflow behind most web CTF challenges.
A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its
The Few Chosen are running the sixth edition of TFC CTF on September 5-6, 2026, a jeopardy-style event built entirely in-house by the
Microsoft has detailed a new social-engineering campaign called TerminalFix that lures victims with a spoofed Cloudflare CAPTCHA page and
Pharmaceutical distribution giant McKesson has confirmed a security incident after attackers gained unauthorized entry into some of its third-party
NNS CTF 2026, run by the Norwegian team Norske Nøkkelsnikere, kicks off September 4 as a jeopardy-style competition spanning web, crypto,
A newly detailed flaw in Ceph, the open-source distributed storage platform, affects versions before 20.2.4 and 19.2.6, letting an attacker
Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes — including WPMU DEV
CSAW CTF's 2026 qualification round is an entry-level jeopardy competition built for undergraduates just getting started in security, with challenges
A newly published flaw, CVE-2026-47856, affects how Spring Integration's JSON-to-object conversion picks a deserialization target class — it trusts a
Connect to a remote service, pack addresses, and find buffer offsets with cyclic patterns — pwntools removes the boilerplate around a pwn exploit.
Suggest content for the blog in the Discord.
Join CTFdojo Discord