>_ Blog

News digests, tutorials, tool reviews and articles — always with sources.

News CVE & Vulnerabilities 2026-09-03

CVE-2026-67394 — OS Command Injection in Plesk for Linux Enables Root Privilege Escalation

A newly disclosed vulnerability in Plesk for Linux, the widely used hosting control panel, lets a customer or reseller with shell access

News CTF & Competitions 2026-09-03

PwnSec CTF 2026

PwnSec CTF is back for its third edition, an online jeopardy-style event beginning September 12, 2026. Organizers say the challenge set

News Cybersecurity 2026-09-03

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Security researchers at Manifold Security found eight flaws spanning seven command-line AI coding assistants, including Claude, Codex, and

News CVE & Vulnerabilities 2026-09-02

CVE-2026-77956 — Code Injection in ash_ai Enables Unauthenticated Code Execution

A newly published CVE describes a code-injection flaw in ash_ai, an AI toolkit built on the Elixir Ash framework, that lets an

News CTF & Competitions 2026-09-02

K17 CTF 2026

UNSW's Security Society is running K17 CTF 2026, an online jeopardy-style contest starting September 11 that mixes approachable challenges

News Cybersecurity 2026-09-02

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Security researchers at watchTowr report that attackers are already abusing a critical JFrog Artifactory vulnerability just days after a

News CVE & Vulnerabilities 2026-09-01

CVE-2026-75759 — Improper Signature Verification in oidcc Enables User Impersonation

A newly disclosed flaw in erlef's oidcc, an Elixir OpenID Connect library, lets an unauthenticated attacker impersonate any user by sending

News CTF & Competitions 2026-09-01

SUNCTF 2026

Sunway Cybersecurity Club is hosting the third edition of SunCTF, a jeopardy-style competition spanning crypto, web exploits, binary pwn

News Cybersecurity 2026-09-01

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Incident responders at Sygnia say the China-linked espionage group Fire Ant has widened a long-running campaign that once focused on VMware

Tutorial Web 2026-08-31

Intercepting and Modifying Requests with Burp Suite

Capture a request in Burp Suite's Proxy, edit it, and replay it with Repeater — the core workflow behind most web CTF challenges.

News CVE & Vulnerabilities 2026-08-31

CVE-2026-16259 — Uix UserCenter Hardcoded Token Key Enables Admin Takeover

A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its

News CTF & Competitions 2026-08-31

TFC CTF 2026

The Few Chosen are running the sixth edition of TFC CTF on September 5-6, 2026, a jeopardy-style event built entirely in-house by the

Got a source, tutorial or tool to suggest?

Suggest content for the blog in the Discord.

Join CTFdojo Discord