Sedric Louissaint disclosed an improper export of Android application components in the ASUS Router App (CVE-2026-12960), letting a co-located app trigger unintended actions.
The seven interview rounds cybersecurity hiring uses, how to prepare for the specific role instead of the whole field, how to answer technical questions, and what to say when you do not know.
What Security+, CISSP, CEH, CCSP, and CISM actually do for a career: how they affect hiring and salary, what they cost in time and money, and why renewal is the point.
How mobile malware lands on a device through malicious app store listings, smishing, and OS flaws. Covers xHelper, Pegasus, and EventBot, plus the MDM and user controls that help.
Session cookies, JSON Web Tokens, Single Sign-On, and OAuth 2.0 in plain English: how each one works, where it fits, what it costs you, and code examples for implementing it.
Why real estate draws attackers: high-value wire transfers and thin defenses. Covers phishing, ransomware, business email compromise, deed fraud, and the controls that stop them.
A walk through OWASP's LLM AI Cybersecurity and Governance Checklist: setting an LLM strategy, the five deployment scopes, and the controls to have in place before you ship.
All ten OWASP Top 10 risks for LLM applications, from prompt injection to model theft, each with attack scenarios and mitigations, mapped onto a typical LLM application data flow.
CVE-2023-4966: a buffer overflow in Citrix ADC and Gateway that lets unauthenticated attackers run code on the appliance. How the flaw works, who it exposes, and what to patch.
A University of Minnesota study tied ransomware to 42 to 67 Medicare patient deaths between 2016 and 2021. How Black Basta hit hospitals and what the outages did to patient care.
No bootcamp can guarantee a cybersecurity job. What a quality program actually owes you, what stays your responsibility as a student, and how to read a placement promise before you pay.
AI is fast at triage and prediction but struggles with false positives and novel attacks, and it is a target itself. Why it reshapes cybersecurity roles rather than replacing them.
How Scattered Spider used a vishing call to the help desk to take MGM's Okta and Azure environments, then deployed ALPHV ransomware. The attack chain, the response, and the lessons.
Six myths that get organizations breached, from 'small businesses are not targets' to 'a strong password is enough', each answered with what actually holds up in practice.
What the SUSOS Cybersecurity Mentorship and Training Program offers newcomers and working practitioners: foundations, hands-on labs, cert prep, one-on-one mentorship, and networking.
Six shifts reshaping defense: AI-driven detection, more sophisticated attacks, cyber hygiene, remote work, privacy regulation like GDPR and CCPA, and security awareness training.
Ransomware-as-a-Service rents prebuilt kits for a cut of the payout, putting campaigns within reach of low-skill attackers. The DarkSide hit on Colonial Pipeline shows what changed.
Two penetration tests, two APIs with no authorization checks. One handed out HIPAA protected medical records. The other handed out live debit and credit card data.
CVE-2020-5148: SonicWall's SSO Agent probes workstations over NETAPI and WMI without validating them, leaking the Domain Admin NTLM hash to anyone who can route traffic through the UTM.
CVE-2021-26837: the SearchTextbox parameter in HelpSystems DeliverNow is injectable, and the database runs as sysadmin. Found by Sedric Louissaint on an internal penetration test.
CVE-2021-3262: a blind SQL injection in the editOEN parameter of TripSpark VEO Transportation, a student busing system, found by Sedric Louissaint on an external penetration test.
Sedric Louissaint3 min read
Get new posts by email
Career guidance and vulnerability research, straight to your inbox. No spam, unsubscribe anytime.