- LLMHaxor Updateby Geoff Walton on September 3, 2026 at 4:00 am
<p>Today I am sharing some updates on a tool I created from an earlier time — before Burp Suite included native AI testing enhancements and before an almost explosive growth of open-source AI tooling and testing frameworks…</p>
- waf-fu, or Some Log Replay Nonsenseby Lilly Mayo on September 1, 2026 at 4:00 am
<p>AWS WAF logs are keeping receipts, including your session tokens. In this blog, we walk through the risk of default WAF logging configurations and the tool built to pull, analyze, and replay what gets left behind.</p>
- SpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waitingby Larry Spohn on August 25, 2026 at 4:00 am
<p>SpooNMAP used to hand you a list of open ports; the latest update tells you which ones actually matter. In this blog, we detail the new automated findings reporting, LLM detection, and performance improvements.</p>
- We’ve Seen This Movie: The OT/IT Technology Divideby Rockie Brockway on August 18, 2026 at 4:00 am
<p>Manufacturing knows what happens when IT and OT divide; AI governance is an unexpected chance to do it differently. In this blog, we walk through a unified governance model that bridges both before bad habits set in.</p>
- AI Offense is Not Noclip Modeby Justin Elze on August 13, 2026 at 4:00 am
<p>AI doesn’t let attackers walk through walls, but it makes finding the cracks more efficient. In this blog, we cut through the hype and explain what AI-driven offense really looks like and why hard controls still work.</p>
- A Vault With No Treasure – CMMC Level 2 Compliance for Subcontractors With No CUIby Chris Camejo on August 11, 2026 at 4:00 am
<p>This blog post should not exist, but it does. In this blog, we detail the improper CMMC Level 2 flow-down problem and the most cost-effective path to compliance if pushing back isn’t an option.</p>
- The Art of Hunting Azure Cloud Secretsby Edwin David on August 6, 2026 at 4:00 am
<p>The difference between a standard cloud test and a subscription takeover? Finding the right secrets. In this blog, we introduce two open-source tools for hunting Azure secrets that probably shouldn’t be there.</p>
- TLS Encryption and Complianceby Chris Camejo on August 4, 2026 at 4:00 am
<p>Transport Layer Security: the compliance checkbox that’s harder to get right than it looks. In this blog, we cover the most common TLS misconfigurations and what organizations need to know to meet the standard.</p>
- CCPA Update: Cybersecurity Requirements (Part 2)by Chris Camejo on July 24, 2026 at 4:00 am
<p>Confirmed you’re in scope for CCPA? Now comes the cybersecurity audit requirement. In Part 2 of this blog series, we cover what it entails, the phased timeline, and the penalties for non-compliance.</p>
- CCPA Update: Who’s In Scope (Part 1)by Chris Camejo on July 23, 2026 at 4:00 am
<p>California updated CCPA… again. Before you do anything else, does it apply to you? In Part 1 of this blog series, we clarify who falls under scope, what data is covered, and how enforcement works.</p>
TrustedSec
We are an ethical website cyber security team and we perform security assessments to protect our clients.




