News digests, tutorials, tool reviews and articles — always with sources.
A newly disclosed vulnerability in Plesk for Linux, the widely used hosting control panel, lets a customer or reseller with shell access
PwnSec CTF is back for its third edition, an online jeopardy-style event beginning September 12, 2026. Organizers say the challenge set
Security researchers at Manifold Security found eight flaws spanning seven command-line AI coding assistants, including Claude, Codex, and
A newly published CVE describes a code-injection flaw in ash_ai, an AI toolkit built on the Elixir Ash framework, that lets an
UNSW's Security Society is running K17 CTF 2026, an online jeopardy-style contest starting September 11 that mixes approachable challenges
Security researchers at watchTowr report that attackers are already abusing a critical JFrog Artifactory vulnerability just days after a
A newly disclosed flaw in erlef's oidcc, an Elixir OpenID Connect library, lets an unauthenticated attacker impersonate any user by sending
Sunway Cybersecurity Club is hosting the third edition of SunCTF, a jeopardy-style competition spanning crypto, web exploits, binary pwn
Incident responders at Sygnia say the China-linked espionage group Fire Ant has widened a long-running campaign that once focused on VMware
Capture a request in Burp Suite's Proxy, edit it, and replay it with Repeater — the core workflow behind most web CTF challenges.
A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its
The Few Chosen are running the sixth edition of TFC CTF on September 5-6, 2026, a jeopardy-style event built entirely in-house by the
Suggest content for the blog in the Discord.
Join CTFdojo Discord