Skip to content

The SUSOS blog

Career guidance and vulnerability research, from people doing the work.

Practical guidance for breaking into cybersecurity and leveling up, plus the CVEs we've disclosed and what they taught us.

Career Coaching

How to Ace Cybersecurity Job Interviews

The seven interview rounds cybersecurity hiring uses, how to prepare for the specific role instead of the whole field, how to answer technical questions, and what to say when you do not know.

Sedric Louissaint13 min read
Cybersecurity

Are Cybersecurity Certs Worth it?

What Security+, CISSP, CEH, CCSP, and CISM actually do for a career: how they affect hiring and salary, what they cost in time and money, and why renewal is the point.

Sedric Louissaint4 min read
Exploit

The Growing Threat of Mobile Malware

How mobile malware lands on a device through malicious app store listings, smishing, and OS flaws. Covers xHelper, Pegasus, and EventBot, plus the MDM and user controls that help.

Sedric Louissaint4 min read
Cybersecurity

Navigating Cybersecurity in Real Estate: Best Practices

Why real estate draws attackers: high-value wire transfers and thin defenses. Covers phishing, ransomware, business email compromise, deed fraud, and the controls that stop them.

Sedric Louissaint8 min read
Artificial Intelligence (AI)

OWASP LLM AI Cybersecurity & Governance Checklist

A walk through OWASP's LLM AI Cybersecurity and Governance Checklist: setting an LLM strategy, the five deployment scopes, and the controls to have in place before you ship.

Sedric Louissaint4 min read
Artificial Intelligence (AI)

OWASP Top 10: Large Language Models

All ten OWASP Top 10 risks for LLM applications, from prompt injection to model theft, each with attack scenarios and mitigations, mapped onto a typical LLM application data flow.

Sedric Louissaint4 min read
Cybersecurity

Citrix Bleed: Bleeding Organizations Dry: CVE-2023-4966

CVE-2023-4966: a buffer overflow in Citrix ADC and Gateway that lets unauthenticated attackers run code on the appliance. How the flaw works, who it exposes, and what to patch.

Lucas Hansen5 min read
Cybersecurity

Ransomware killed your grandma!

A University of Minnesota study tied ransomware to 42 to 67 Medicare patient deaths between 2016 and 2021. How Black Basta hit hospitals and what the outages did to patient care.

Lucas Hansen5 min read
Cybersecurity

The Reality of Cybersecurity Training and Job Placement

No bootcamp can guarantee a cybersecurity job. What a quality program actually owes you, what stays your responsibility as a student, and how to read a placement promise before you pay.

Lucas Hansen3 min read
Artificial Intelligence (AI)

Will Cybersecurity Be Replaced By AI?

AI is fast at triage and prediction but struggles with false positives and novel attacks, and it is a target itself. Why it reshapes cybersecurity roles rather than replacing them.

Lucas Hansen4 min read
Cybersecurity

MGM Cyberattack: Unveiling the Digital Heist - Ransomware

How Scattered Spider used a vishing call to the help desk to take MGM's Okta and Azure environments, then deployed ALPHV ransomware. The attack chain, the response, and the lessons.

Lucas Hansen6 min read
Cybersecurity

Debunking Cybersecurity Myths: Facts Over Fiction

Six myths that get organizations breached, from 'small businesses are not targets' to 'a strong password is enough', each answered with what actually holds up in practice.

Lucas Hansen3 min read
Cybersecurity

Navigating Cybersecurity Trends

Six shifts reshaping defense: AI-driven detection, more sophisticated attacks, cyber hygiene, remote work, privacy regulation like GDPR and CCPA, and security awareness training.

Lucas Hansen2 min read
CybersecurityCVE-2021-26837

SqlNow: SQL Injection in DeliverNow: CVE-2021-26837

CVE-2021-26837: the SearchTextbox parameter in HelpSystems DeliverNow is injectable, and the database runs as sysadmin. Found by Sedric Louissaint on an internal penetration test.

Sedric Louissaint3 min read

Get new posts by email

Career guidance and vulnerability research, straight to your inbox. No spam, unsubscribe anytime.

Prefer a reader? Subscribe via RSS.