29 July 2026 · 6 min read
What happens to your email address after a data breach? We tracked 150 days of phishing on two aliases known only to Odido and Tele2.
17 July 2026 · 4 min read
wp2shell (CVE-2026-63030 and CVE-2026-60137) is a pre-auth RCE in WordPress core. Read what is going on and how to secure your WordPress site now.
12 June 2026 · 5 min read
Hackify discovered CVE-2026-32210, a critical Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 (online) that allowed a logged-in user's OAuth token to be stolen and reused against the Power Platform API.
6 March 2026 · 7 min read
How do Potato attacks work in Windows, and how do attackers abuse SeImpersonatePrivilege to gain SYSTEM privileges? Read how to detect and prevent this.
6 February 2025 · 4 min read
In-depth CRTP review: our experience with the Certified Red Team Professional course from Altered Security, the 24-hour exam and tips to pass.