>_ Blog

News digests, tutorials, tool reviews and articles — always with sources.

News Cybersecurity 2026-09-01

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Incident responders at Sygnia say the China-linked espionage group Fire Ant has widened a long-running campaign that once focused on VMware

Tutorial Web 2026-08-31

Intercepting and Modifying Requests with Burp Suite

Capture a request in Burp Suite's Proxy, edit it, and replay it with Repeater — the core workflow behind most web CTF challenges.

News CVE & Vulnerabilities 2026-08-31

CVE-2026-16259 — Uix UserCenter Hardcoded Token Key Enables Admin Takeover

A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its

News CTF & Competitions 2026-08-31

TFC CTF 2026

The Few Chosen are running the sixth edition of TFC CTF on September 5-6, 2026, a jeopardy-style event built entirely in-house by the

News Cybersecurity 2026-08-31

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has detailed a new social-engineering campaign called TerminalFix that lures victims with a spoofed Cloudflare CAPTCHA page and

News Cybersecurity 2026-08-30

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft

Pharmaceutical distribution giant McKesson has confirmed a security incident after attackers gained unauthorized entry into some of its third-party

News CTF & Competitions 2026-08-30

NNS CTF 2026

NNS CTF 2026, run by the Norwegian team Norske Nøkkelsnikere, kicks off September 4 as a jeopardy-style competition spanning web, crypto,

News CVE & Vulnerabilities 2026-08-30

CVE-2025-30156 — Ceph CephX Hardcoded IV Enables Cluster Takeover

A newly detailed flaw in Ceph, the open-source distributed storage platform, affects versions before 20.2.4 and 19.2.6, letting an attacker

News Cybersecurity 2026-08-29

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes — including WPMU DEV

News CTF & Competitions 2026-08-29

CSAW CTF Qualification Round 2026

CSAW CTF's 2026 qualification round is an entry-level jeopardy competition built for undergraduates just getting started in security, with challenges

News CVE & Vulnerabilities 2026-08-29

CVE-2026-47856 — Spring Integration Unsafe JSON Deserialization

A newly published flaw, CVE-2026-47856, affects how Spring Integration's JSON-to-object conversion picks a deserialization target class — it trusts a

Tool Pwn 2026-08-26

pwntools: A Python Library for Pwn Challenges

Connect to a remote service, pack addresses, and find buffer offsets with cyclic patterns — pwntools removes the boilerplate around a pwn exploit.

Got a source, tutorial or tool to suggest?

Suggest content for the blog in the Discord.

Join CTFdojo Discord