Please download one of these browsers:
Keep your browser version up-to-date for a fast, secure, web experience.
The Cisco Certified DevNet Associate (200-901) show is produced to help the software developer, networking professional and IT professional to achieve the latest Cisco certification offer, the Cisco Certified DevNet Associate certification.
Dive into the world of MinIO security as we uncover and exploit an information disclosure vulnerability, gaining access to sensitive data.
Learn about types of vulnerabilities, the exploits that can occur from those vulnerabilities, and the programming practices that will help prevent exploitation in an application!
In this series, we are going to take a look at programming using the Python programming language. If you have tried to start before and just spun your wheels, then you should give it a try again.
James Kettle of PortSwigger reveals sophisticated web race condition exploits, demonstrating how attackers can manipulate state machines and create backdoors through precise timing attacks.
Veracode CISO Sohail Iqbal provides guidance on prioritizing software security and effectively communicating metrics to board members.
This course is designed to teach you about the 2021 version of the OWASP Top 10 Web Application Vulnerabilities. The OWASP Top 10 is a list of the most critical security risks to web applications, and it is widely used by organizations to improve their web application security.
Fred Harris, Matanda Doss and Patrice Boffa examine emerging attack patterns targeting financial services' revenue-generating digital assets.
Industry leaders Matanda Doss, Susan Koski, William Beer and Paul Leonhirth discuss cloud adoption challenges, API security and AI-powered fraud detection in financial services cybersecurity.
Security researcher Nemo examines UPI's security architecture, revealing critical vulnerabilities in mobile number verification and offering recommendations to strengthen India's digital payment ecosystem.
Trend Micro's senior threat researcher Nitesh Surana reveals critical vulnerabilities in Azure Machine Learning services, demonstrating how attackers can compromise ML workspaces.
Master container security in our Vulnerable Erlang course! Exploit CVE-2025-32433, deploy vulnerable Docker containers, detect threats with Sysdig Falco, and secure systems. Ideal for security professionals, DevSecOps, and pentesters.
Apple Certified Support Professional (ACSP) certification confirms the candidate's understanding of macOS's core functionality as well as having the ability to configure key services, perform basic troubleshooting, and support multiple users with essential macOS capabilities.
Version control is a cryptic yet essential part of a software development team. Git is a distributed version control system that allows collaboration and management of large scale software products (as well as other types of projects)
PenTest+ assesses the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
This course is designed for those looking to gain skills related to penetration testing web applications.
Tal Kollender highlights how human errors and default settings lead to 80% of ransomware attacks. Discover the risks of manual remediation and how automation can reduce misconfigurations, shrinking the attack surface and enhancing network protection.
An application security engineer is a specialist in the field of information technology (IT), whose primary focus is to safeguard software applications from potential threats and breaches. They are the bridge between security and development, ensuring that applications are designed, developed, and deployed in a secure manner.
Learn from Christophe Barel about securing supply chains, adopting shift-left strategies, and managing open-source risks. Explore frameworks for secure coding, automated security-by-design, and faster detection and remediation of supply chain attacks.
Visagan Subburayalu, Dr. Vishal Saraswat and Amol Naik debate who owns AI-generated code security and how organizations can balance developer velocity with accountability, guardrails and human-in-the-loop controls.
Sonya Moisset of Snyk breaks down the security risks of AI-assisted engineering - from slopsquatting to weaponized agents - and shares a five-layer playbook to secure your AI-powered software development life cycle.
Denis Maligin of Chainguard examines how open-source supply chain attacks reach production environments and how zero-CVE images and software bills of materials address the Cyber Resilience Act.
Daniella Drori traces AppSec's evolution from siloed, alert-heavy scanners to context-aware security, showing how cross-scanner correlation and AI-aware tooling close the gap between what gets detected and what actually gets fixed.
Adobe's Kamalpreet Khurana exposes how legacy SOAP systems still fuel critical vulnerabilities in 2026, walking through a real zero-day XXE discovery and offering practical mitigations for teams that can't retire their SOAP infrastructure.
Rishav Raj and Rajkumar Rathod of FIS demo VISTA, an open-source Burp Suite extension that integrates LLM reasoning into penetration testing workflows without replacing human judgment.
Ashish Kataria of Synacor examines how modern sanitization pipelines can inadvertently introduce XSS vulnerabilities through structural mutations, namespace confusion and multi-stage parser mismatches.
SoYeon Kim, Hea-Eun Moon and Sang-tae Woo of NSHC share lessons from organizing ACDC 2025, Korea's first AI security CTF, covering challenge design, unintended AI-powered solutions and format pitfalls.
Dillon Franke of Mandiant/Google demonstrates advanced techniques for identifying IPC vulnerabilities in macOS, covering sandbox-allowed communications and mutation-based fuzzing methodologies.
Capt. Felix Mohan of CISO Cybersecurity addresses vulnerabilities in LLMs, focusing on security controls, ethical guidelines, and risk assessments.
Yogeshwaran Sivasubramanian highlights the growing frequency of security breaches due to inadequate secure coding practices among developers.
Sabrina Jensen explores how proactive security strategies build stakeholder confidence, enhance flexibility and contribute to resilient decision-making for long-term success.
Henk-Jan van der Molen explains why market dominance creates ecosystem vulnerabilities, uses Python simulations to demonstrate how software diversity limits attack spread, and discusses how profitable monoculture attacks fund criminal research.
Tim Hill provides practical guidance on navigating New York's 23 NYCRR 500 cybersecurity regulations, offering strategies for financial institutions to achieve compliance while modernizing their security infrastructure.
Andrew Huang of Sutajio Ko-usagi examines practical ways to verify silicon integrity using infrared inspection and open design principles.
Moritz Abrell of SySS GmbH discusses how Bluetooth flaws and firmware weaknesses in a popular sports watch enable wireless attacks, account takeover and data exposure.
Theresa Lanowitz of LevelBlue presents 2025 research on AI attack preparation, software supply chain management and risk mitigation strategies for healthcare innovation.
Pierre Martin and Rémi Matasse of Synacktiv explain how Livewire's unmarshalling logic can be weaponized into stealthy remote command execution when Laravel app keys are exposed.
Pascal Beyer of Fraunhofer FKIE explores how deterministic snapshot fuzzing in emulated environments reveals deep OS and RDP vulnerabilities, advancing targeted security analysis techniques.
Mickey Jin breaks down a race-condition vulnerability Apple once deemed unexploitable, showing how it enabled sandbox escapes and TCC bypasses, why early patches failed, and what finally worked.
Lukas Bernhard explores custom intermediate representations for semantic-aware mutations that penetrate compiler optimization paths, GPU process sandboxing weaknesses, and fuzzing vendor GPU stacks without source access.
Simon Gerst of Asymmetric Research covers bounded model checking for V8's C++ code, floating-point edge cases in range analysis that create security vulnerabilities, and automated JavaScript proof-of-concept generation from symbolic counterexamples.
Dr. Sharique Raza of UAE Financial Institutions UAE explores zero trust principles and regional cybersecurity regulations. Learn practical approaches to align with UAE and Saudi frameworks while strengthening your organization's security posture.
Ravindra Ramnani from Elastic demonstrates how AI-powered security analytics accelerates threat detection and response, improving alert triage and investigations through automation.
Aseem Jakhar, Nolen Johnson, Nir Tasher, Jason Meltzer and Tamara Schmitz examine how security research drives hardware risk decisions, timelines and supply chain accountability.
Sergey Bratus of Dartmouth College unpacks how formal, exploit-aware methods can harden software trust by treating vulnerabilities as computational phenomena.
Join Lynn Peachey in a three part series on Cybersecurity Insurance. Part 1 is an introductory exploration of the growing ransomware threat and the role of cybersecurity insurance. Part 2 is an exploration of the cyber insurance vendor's incident response process and finally part 3 is an exploration of risks and trends in cyber insurance.
Yadhu Krishna M. of CRED outlines practical frameworks for reducing software supply chain risk using SBOM-driven visibility and dependency ownership mapping that aligns security priorities with engineering workflows.
Sebastian Neef of the Technical University of Berlin presents PHUZZ, a coverage-guided fuzzing framework that uncovers zero-day vulnerabilities in PHP applications beyond traditional web scanners.
Michael Hendrickx of Microsoft presents Project Dusseldorf, an out-of-band platform that detects blind application vulnerabilities using DNS and HTTP signals at cloud scale.
Yashodhan Vivek Mandke of MIT World Peace University explains how reversing deep learning models exposes architecture, tensors and weights that can be exploited or defended at the mathematical core.
1 2 Next