News digests, tutorials, tool reviews and articles — always with sources.
Microsoft has detailed a new social-engineering campaign called TerminalFix that lures victims with a spoofed Cloudflare CAPTCHA page and
Pharmaceutical distribution giant McKesson has confirmed a security incident after attackers gained unauthorized entry into some of its third-party
NNS CTF 2026, run by the Norwegian team Norske Nøkkelsnikere, kicks off September 4 as a jeopardy-style competition spanning web, crypto,
A newly detailed flaw in Ceph, the open-source distributed storage platform, affects versions before 20.2.4 and 19.2.6, letting an attacker
Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes — including WPMU DEV
CSAW CTF's 2026 qualification round is an entry-level jeopardy competition built for undergraduates just getting started in security, with challenges
A newly published flaw, CVE-2026-47856, affects how Spring Integration's JSON-to-object conversion picks a deserialization target class — it trusts a
Connect to a remote service, pack addresses, and find buffer offsets with cyclic patterns — pwntools removes the boilerplate around a pwn exploit.
The U.S. Treasury Department has imposed new sanctions on Iranian hackers tied to breaches of critical infrastructure, part of a broader
Iran Tech Olympics CTF 2026 is running as a joint event with ASIS CTF Quals 2026, combining the two competitions into one jeopardy-style
A newly disclosed flaw in the libwebsockets 4.5.0 library allows an out-of-bounds write in its CBOR recording function, reachable by a
CISA has added a maximum-severity flaw in Oracle HTTP Server and WebLogic Server, tracked as CVE-2026-21962 with a perfect 10.0 CVSS score
Suggest content for the blog in the Discord.
Join CTFdojo Discord