Please download one of these browsers:
Keep your browser version up-to-date for a fast, secure, web experience.
Gathering and analyzing publicly available data for cybersecurity and threat intelligence.
Identifying and defending against manipulation-based cyber threats.
This course is designed for those looking to gain skills related to penetration testing web applications.
In this series, Daniel and Brad will take a look at what a pentesting engagement looks like through the lens of Brad's experience as a pentester.
To become a well-rounded Ethical Hacker and/or Penetration Tester, not only must you be familiar with the appropriate tools and techniques, but you must also craft your methodology for applying said skills.
PenTest+ assesses the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
The Linux Essentials certification from the Linux Professional Institute is designed to showcase your foundation skills in working with the Linux operating system.
The Linux in the Cloud series focuses on implementing the Linux operating system in a virtualized environment.
The Linux Security Techniques series introduces the viewers to the various security features found in modern Linux distributions.
Embark on your journey into the dynamic world of cybersecurity with our introductory course tailored for aspiring red team members or advanced penetration testers. Designed for those new to the realm of Antivirus (AV) and Endpoint Detection and Response (EDR) evasions.
This course is designed to teach you about the 2021 version of the OWASP Top 10 Web Application Vulnerabilities. The OWASP Top 10 is a list of the most critical security risks to web applications, and it is widely used by organizations to improve their web application security.
The proliferation of IoT devices, both at home and in the office, has significantly expanded the attack vectors for bad actors trying to gain a foothold on your network. Learn to pentest them today!
James Kettle of PortSwigger reveals sophisticated web race condition exploits, demonstrating how attackers can manipulate state machines and create backdoors through precise timing attacks.
Security researcher Nemo examines UPI's security architecture, revealing critical vulnerabilities in mobile number verification and offering recommendations to strengthen India's digital payment ecosystem.
Kirils Solovjovs of Possible Security exposes novel methods for intercepting phone calls through PSTN vulnerabilities, demonstrating how attackers can exploit SS7 protocols and call routing mechanisms.
Arpan Jati reveals critical vulnerabilities in Xilinx's Zynq-7000 SoC platform, demonstrating RSA authentication bypass and encrypted bitstream recovery techniques that impact critical infrastructure security.
Dive into the world of MinIO security as we uncover and exploit an information disclosure vulnerability, gaining access to sensitive data.
Christophe Seigneur of Toray Carbon Fibers Europe shares insights from implementing a pragmatic pentesting program at Toray Industries, covering strategic communication, quick wins and SOC/EDR effectiveness evaluation.
This lab provides hands-on experience exploiting CVE-2023-42793, a critical vulnerability in JetBrains TeamCity. Learn to gain unauthorized access, escalate privileges, and execute arbitrary code on a vulnerable server.
The Linux Fundamentals for Certification learning path provides essential Linux operating system skills and prepares you for entry-level Linux certification exams. You'll master core command-line operations and fundamental system administration concepts.
Anders Björklund of Martin & Servera demonstrates converting penetration test findings into quantified business risk using NIST CSF 2.0 frameworks.
Anthony Pillitiere of Horizon3.ai covers prioritizing exploitable weaknesses using likelihood and impact, validating security controls through autonomous offensive engagements, and shifting to continuous attack simulation.
Trend Micro's senior threat researcher Nitesh Surana reveals critical vulnerabilities in Azure Machine Learning services, demonstrating how attackers can compromise ML workspaces.
John Lambert from Microsoft Security Research explores proactive threat detection strategies, advanced hunting techniques, and creative tactics for leveraging honeypot systems to enhance cybersecurity defenses.
Joey Fontiveros, Acting Regiment Commander of the Philippines Army, shares insights on building cyber defense capabilities and countermeasures in an increasingly sophisticated threat landscape.
Jasper van Woudenberg and Rajesh Velegalati of Keysight demonstrate how voltage fault injection manipulates edge AI perception and how LLM agents can automate the attack, making neural accelerators a serious hardware security risk.
Roman Korkikian demonstrates how a $2,000 power side-channel setup breaks the root of trust in a commercial TPM, extracting ECDH private keys from a device certified to protect them against physical attack.
Scott Sheahan reverse engineers the electronic security architecture of a 2025 Indian Scout Bobber, demonstrating how to bypass its immobilizer and start the bike without a key through CAN bus analysis and protocol exploitation.
Jakub Szefer presents experimental research on cross-talk vulnerabilities in cloud-based quantum computers, demonstrating how qubit interactions on shared hardware enable interference and information leakage between users.
Guanxing Wen of CertiK presents a full compromise of the dGEN1 Ethereum phone - from BootROM misconfiguration and in-memory boot chain patching to private key extraction and pre-activation airdrop theft.
Hash Salehi of RECESSIM explains how a $70 surplus power supply and a simple PicoEMP modification achieves ChipShouter-class fault injection performance at roughly $250 total - with open-source design files and live benchmark results.
Nathan Nye and Philippe Teuwen reveal how relay attacks, partial key overwrites and EEPROM tearing weaken 3DES and AES protections in MIFARE Ultralight and NTAG DNA tags - with real-world findings from hospitality deployments.
Joe Grand, Lionel Riviere, Domenic Forte and Dan Grosu walk through live fault injection attacks on a modern automotive chip across three cost tiers and ask why the defenses that exist are not yet shipping in production devices.
Pentera's Ramon Lucini challenges the CTEM status quo with real-world attack examples and a practical model connecting continuous validation, cross-tool correlation and AI-guided remediation to close actual exposure gaps.
Kandi Abhishek Reddy and Alla Vamsi Krishna examine CVE-2025-21533, a VirtualBox speculative execution flaw that exposes sensitive data via cache-based side channels, and what it means for virtualization security.
Adobe's Kamalpreet Khurana exposes how legacy SOAP systems still fuel critical vulnerabilities in 2026, walking through a real zero-day XXE discovery and offering practical mitigations for teams that can't retire their SOAP infrastructure.
Rakesh Seal unveils a zero-day TLS covert channel that exfiltrates data by permutating handshake parameters, bypassing multiple leading firewalls with no anomalous footprints, in IEEE award-winning research disclosed to CISA, GSMA and 100+ vendors.
Priyanshu Sharma of MIT Pune walks through a five-step driver vulnerability pipeline that moves beyond fuzzing to produce consistent zero-day discoveries.
Rishav Raj and Rajkumar Rathod of FIS demo VISTA, an open-source Burp Suite extension that integrates LLM reasoning into penetration testing workflows without replacing human judgment.
Maor Abutbul of CyberArk Labs demonstrates how QUIC's multiplexing can be weaponized for race conditions and fuzzing via QuicDraw - an open-source HTTP/3 security testing tool.
Ashish Kataria of Synacor examines how modern sanitization pipelines can inadvertently introduce XSS vulnerabilities through structural mutations, namespace confusion and multi-stage parser mismatches.
Jakkaraju Varshith and Vivek Joshi of Rashtriya Raksha University demonstrate how POSIX-based self-deletion and stealth injection bypass Windows 11 25H2 security controls, with detection guidance for blue teams.
Gurjot Singh, Vipin Venu and Arjun V of Innspark Solutions expose a BLE vulnerability class that lets any nearby attacker send commands to unprotected smartwatches - no pairing, no authentication required.
SoYeon Kim, Hea-Eun Moon and Sang-tae Woo of NSHC share lessons from organizing ACDC 2025, Korea's first AI security CTF, covering challenge design, unintended AI-powered solutions and format pitfalls.
Sebastien Lecocq, director of Cyber Security at Decathlon Digital, examines how organizations can effectively implement bug bounty programs to enhance security through ethical hacking and continuous testing.
Security researcher Dennis Giese exposes critical vulnerabilities in Digilog electronic locks, demonstrating rapid PIN extraction and master key cloning techniques that threaten shared-space security systems.
Join Kaspersky's Stephan Gerling as he explores critical vulnerabilities in EV charging infrastructure, from physical security to OCPP protocol weaknesses and payment system vulnerabilities.
Dillon Franke of Mandiant/Google demonstrates advanced techniques for identifying IPC vulnerabilities in macOS, covering sandbox-allowed communications and mutation-based fuzzing methodologies.
Security engineer Jaden Furtado reveals critical vulnerabilities in modern railway systems, examining control systems, mobile applications and supply chain security concerns in railway infrastructure.
HAXXIN's Peter Geissler demonstrates advanced printer exploitation techniques, covering firmware analysis, privilege escalation and custom debugging tools for embedded platforms.
Join industry experts Jan Tilo Kirchhoff, Andreas Bogk, Diana Nadeborn and Michał Kowalczyk for an insightful discussion on legal frameworks, recent cases and strategies for responsible vulnerability disclosure across Europe.
Mojalefa Mofammere of Assupol and Corradino Corradi of MTN examine the AI arms race in cybersecurity, exploring how defensive AI can counter offensive AI threats while assessing strategic and ethical implications.
1 2 Next