Our Blog
Resources and insights
The latest industry news, interviews, technologies, and resources.
Why Red Team Should Learn Blue Team Skills
Blue team skills can benefit a penetration tester with sharper offensive capabilities, stronger collaboration with defenders, and more career versatility.
Course Retirements: Windows & Linux Privilege Escalation for Beginners
Starting on May 7, 2025, the Windows and Linux Privilege Escalation for Beginners courses in TCM Security Academy, will no longer be available as part of the All-Access Membership. Why Were The Courses Retired? We are constantly evaluating our courses for improvements...
How To Pass The PORP Certification Exam
The Practical OSINT Research Professional exam isn’t about memorization but about skill. Here are some tips and tricks to prepare you to pass.
Projects to Land Your First Cybersecurity Job
Gaining experience in cybersecurity before landing a job can be tricky. However, side projects are an excellent way to gain experience and impress recruiters.
Find and Exploit Server-Side Template Injection (SSTI)
Server-Side Template Injection (SSTI) is an attack that allows an attacker to inject malicious input into a templating engine, leading to code execution on the server. While this vulnerability can be quite impactful, understanding and exploiting it requires a good...
Find and Exploit Blind SSRF with Out-of-Band (OOB) Techniques
Server-Side Request Forgery (SSRF) is a vulnerability that let’s an attacker have a server make requests on their behalf. Typically this can allow the attacker to reach internal resources that would otherwise be unavailable. Whilst the typical SSRF is dangerous...
XPath Injection: A Beginners Guide
Overview XPath Injection, akin to other common injection attacks, specifically targets vulnerabilities within an application's user input processing system. But what sets XPath Injection apart is its exploitation of XPath queries. The fallout? Unauthorized access to...
Understanding, Detecting, and Exploiting SSRF
SSRF has emerged as a significant threat to web security. We discuss how to identify it, verify its presence, and responsibly exploit it for security testing.
Start your Journey with Bug Bounty
Bug bounty programs are an opportunity for anyone to identify vulnerabilities in a company’s software or infrastructure and get rewarded for their discoveries.
Stay Ahead of Cyber Threats
Get expert insights on the latest penetration testing strategies, emerging vulnerabilities, and cybersecurity best practices—straight to your inbox.
Loading form...
We care about your data in our privacy policy.








