Please download one of these browsers:
Keep your browser version up-to-date for a fast, secure, web experience.
The Certified Ethical Hacker(CEH) v12 course is designed to give the student a foundational knowledge base and skillset to be an asset to their current organization as a security analyst, or to become an effective member of a security team engaged in offensive security testing and vulnerability assessments.
Tal Kollender highlights how human errors and default settings lead to 80% of ransomware attacks. Discover the risks of manual remediation and how automation can reduce misconfigurations, shrinking the attack surface and enhancing network protection.
This course is designed for those looking to gain skills related to penetration testing web applications.
In this series, Daniel and Brad will take a look at what a pentesting engagement looks like through the lens of Brad's experience as a pentester.
To become a well-rounded Ethical Hacker and/or Penetration Tester, not only must you be familiar with the appropriate tools and techniques, but you must also craft your methodology for applying said skills.
PenTest+ assesses the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
ICS SCADA and IIoT Vulnerabilities discusses the components of ICS, SCADA, and IIoT systems their vulnerabilities and threats.
This course will acquaint learners with the new Windows Terminal Application.
This course is for anyone wanting to learn how to write PowerShell scripts to automate tasks.
The Linux Command Line show is designed to introduce viewers to working on Linux based computers using only the command line interface. This is considered the first step in learning BASH scripting as most scripts are made up of a series of CLI commands.
In this series, Daniel and Don walk you through the fundamentals of bash scripting in the Linux operating system. Watch here as they take you through the fundamentals like: Script file formats, running scripts, working with variables, performing arithmetic, conditional statements, loops, presenting data, taking user input, and script control.
In this series, Daniel and Justin take a look at some of the more advanced scripting practices. Here they will empower your scripts by taking advantage of things like Functions, Libraries, creating graphical elements, sed (Stream EDitor), gawk, and Regular Expression.
The Linux in the Cloud series focuses on implementing the Linux operating system in a virtualized environment.
Becoming a Linux Power User is a technical skills course designed to elevate viewers to "Power User" status.
The Linux Security Techniques series introduces the viewers to the various security features found in modern Linux distributions.
Embark on your journey into the dynamic world of cybersecurity with our introductory course tailored for aspiring red team members or advanced penetration testers. Designed for those new to the realm of Antivirus (AV) and Endpoint Detection and Response (EDR) evasions.
This course is designed to teach you about the 2021 version of the OWASP Top 10 Web Application Vulnerabilities. The OWASP Top 10 is a list of the most critical security risks to web applications, and it is widely used by organizations to improve their web application security.
The proliferation of IoT devices, both at home and in the office, has significantly expanded the attack vectors for bad actors trying to gain a foothold on your network. Learn to pentest them today!
In the US, NIST is the de-facto standard for security, compliance and privacy. If you are doing business with the US federal government, manage critical infrastructure, or maintain personally identifiable information (PII), you must be compliant with NIST standards. NIST provides the Cybersecurity Framework (CSF) and Risk Management Framework (RMF) to guide organizations on securing their infrastructure, systems, and data.
The Working with SSH show aims to remove the intimidation of using the Secure Shell protocol on your network. SSH allows for encrypting network communications to protect from eavesdropping and man-in-the-middle attacks. This series demonstrates how to configure and use SSH to securely manage your systems.
James Kettle of PortSwigger reveals sophisticated web race condition exploits, demonstrating how attackers can manipulate state machines and create backdoors through precise timing attacks.
Security researcher Nemo examines UPI's security architecture, revealing critical vulnerabilities in mobile number verification and offering recommendations to strengthen India's digital payment ecosystem.
Kirils Solovjovs of Possible Security exposes novel methods for intercepting phone calls through PSTN vulnerabilities, demonstrating how attackers can exploit SS7 protocols and call routing mechanisms.
Dive into the world of MinIO security as we uncover and exploit an information disclosure vulnerability, gaining access to sensitive data.
This lab provides hands-on experience exploiting CVE-2023-42793, a critical vulnerability in JetBrains TeamCity. Learn to gain unauthorized access, escalate privileges, and execute arbitrary code on a vulnerable server.
The Linux Fundamentals for Certification learning path provides essential Linux operating system skills and prepares you for entry-level Linux certification exams. You'll master core command-line operations and fundamental system administration concepts.
Jasper van Woudenberg and Rajesh Velegalati of Keysight demonstrate how voltage fault injection manipulates edge AI perception and how LLM agents can automate the attack, making neural accelerators a serious hardware security risk.
Joe Grand of Grand Idea Studio walks through the full reverse engineering of a real hardware implant discovered inside a Ledger Nano X - exposing how a supply chain attack on a cryptocurrency wallet works in the wild.
Roman Korkikian demonstrates how a $2,000 power side-channel setup breaks the root of trust in a commercial TPM, extracting ECDH private keys from a device certified to protect them against physical attack.
Edoardo Mantovani walks through the complete defeat of MediaTek Wi-Fi firmware encryption across Wi-Fi 6, 6E and 7 - from driver analysis and ROM dumping to breaking AES protection and integrity checks.
Sébastien Dudek of Penthertz walks through real 5G security assessments at every layer - from radio encryption failures and null cipher abuse to 5G core API exploitation and CAMARA endpoint vulnerabilities enabling surveillance and fraud.
Will Eatherton of Cisco examines why hardware reliability has become strategically critical in the AI era, covering defensive design, observability at hyperscaler scale and lessons from access to Anthropic's Mythos model.
Scott Sheahan reverse engineers the electronic security architecture of a 2025 Indian Scout Bobber, demonstrating how to bypass its immobilizer and start the bike without a key through CAN bus analysis and protocol exploitation.
Jakub Szefer presents experimental research on cross-talk vulnerabilities in cloud-based quantum computers, demonstrating how qubit interactions on shared hardware enable interference and information leakage between users.
Guanxing Wen of CertiK presents a full compromise of the dGEN1 Ethereum phone - from BootROM misconfiguration and in-memory boot chain patching to private key extraction and pre-activation airdrop theft.
Hash Salehi of RECESSIM explains how a $70 surplus power supply and a simple PicoEMP modification achieves ChipShouter-class fault injection performance at roughly $250 total - with open-source design files and live benchmark results.
Sultan Qasim Khan of Tetrel Security analyzes Bluetooth Channel Sounding's security landscape, covering distance manipulation attacks, EDLC and multipath exploits, and a survey of vendor implementation resilience.
Nathan Nye and Philippe Teuwen reveal how relay attacks, partial key overwrites and EEPROM tearing weaken 3DES and AES protections in MIFARE Ultralight and NTAG DNA tags - with real-world findings from hospitality deployments.
Marcus Richerson, James DeLuccia and Aaron Guzman walk through a supply chain firmware implant from three perspectives - builder, assessor and product security team - and ask why hardware security still has no equivalent of EDR.
Joe Grand, Lionel Riviere, Domenic Forte and Dan Grosu walk through live fault injection attacks on a modern automotive chip across three cost tiers and ask why the defenses that exist are not yet shipping in production devices.
Pentera's Ramon Lucini challenges the CTEM status quo with real-world attack examples and a practical model connecting continuous validation, cross-tool correlation and AI-guided remediation to close actual exposure gaps.
Kandi Abhishek Reddy and Alla Vamsi Krishna examine CVE-2025-21533, a VirtualBox speculative execution flaw that exposes sensitive data via cache-based side channels, and what it means for virtualization security.
Adobe's Kamalpreet Khurana exposes how legacy SOAP systems still fuel critical vulnerabilities in 2026, walking through a real zero-day XXE discovery and offering practical mitigations for teams that can't retire their SOAP infrastructure.
Rakesh Seal unveils a zero-day TLS covert channel that exfiltrates data by permutating handshake parameters, bypassing multiple leading firewalls with no anomalous footprints, in IEEE award-winning research disclosed to CISA, GSMA and 100+ vendors.
Priyanshu Sharma of MIT Pune walks through a five-step driver vulnerability pipeline that moves beyond fuzzing to produce consistent zero-day discoveries.
Rishav Raj and Rajkumar Rathod of FIS demo VISTA, an open-source Burp Suite extension that integrates LLM reasoning into penetration testing workflows without replacing human judgment.
Maor Abutbul of CyberArk Labs demonstrates how QUIC's multiplexing can be weaponized for race conditions and fuzzing via QuicDraw - an open-source HTTP/3 security testing tool.
Ashish Kataria of Synacor examines how modern sanitization pipelines can inadvertently introduce XSS vulnerabilities through structural mutations, namespace confusion and multi-stage parser mismatches.
Jakkaraju Varshith and Vivek Joshi of Rashtriya Raksha University demonstrate how POSIX-based self-deletion and stealth injection bypass Windows 11 25H2 security controls, with detection guidance for blue teams.
Gurjot Singh, Vipin Venu and Arjun V of Innspark Solutions expose a BLE vulnerability class that lets any nearby attacker send commands to unprotected smartwatches - no pairing, no authentication required.
1 2 Next