TrustedSec

  • CMMC is (Not) Cancelled
    by Chris Camejo on July 16, 2026 at 4:00 am

    <p>Word is out that the Department of War (DoW) has suspended the rollout of CMMC Phase II. However, contractors working on CMMC compliance should not abandon their CMMC plans: Although the audit requirement is suspended,…</p>

  • Pandora’s Container Part 1: Unpacking Azure Container Security
    by Justin Mahon on July 14, 2026 at 4:00 am

    <p>Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting registries, token keys, and container instances in Azure.</p>

  • Vulnify: Giving Your Agents a CVE Brain
    by Brandon McGrath on July 9, 2026 at 4:00 am

    <p>The CVE brain your AI agent has been missing. In this blog, we introduce Vulnify, an open-source tool that stitches eight authoritative vulnerability databases into a single offline source of truth for CVE intelligence.</p>

  • Welcoming ObfusGit
    by Kevin Haubris on July 7, 2026 at 4:00 am

    <p>What if your public repo could stay out of AI training data without changing how you commit? In this blog, we introduce ObfusGit, a Python tool that obfuscates your public copy while your local repo stays untouched.</p>

  • Inheriting the Receipts: Securing the AI Your Company Already Adopted
    by Rockie Brockway on July 2, 2026 at 4:00 am

    <p>The work is not new. The speed is. In this blog, we’re outlining how existing security pillars apply to the AI your organization has already adopted; no new doctrine, new team, or new budget line required.</p>

  • Large Workflows with Local LLMs
    by Kevin Haubris on June 25, 2026 at 4:00 am

    <p>As it turns out, local LLMs have a few opinions about large workflows. In this blog, we walk through the scaling challenges of local LLMs and the custom Python library built to wrangle them.</p>

  • Modern Web Application Content Discovery
    by Luke Bremer on June 18, 2026 at 4:00 am

    <p>Staring at a web app with no links and no navigation? In this blog, we break down modern content discovery, from forced browsing and web crawling to Google dorking and GitHub recon.</p>

  • JQ for Hackers
    by Justin Bollinger on June 16, 2026 at 4:00 am

    <p>Grey-bearded hackers and sysadmins still reaching for cut and CSV files, this one’s for you. In this blog, we break down jq and why it’s time to embrace JSON.</p>

  • JS-Tap v3: Endpoint Post-Exploitation With JavaScript Implants
    by Drew Kirkpatrick on June 12, 2026 at 4:00 am

    <p>JavaScript escaped the browser. JS-Tap v3 followed it. In this blog, we introduce three new beacons targeting the Electron apps, browser extensions, and Node runtimes running on corporate workstations.</p>

  • Hardening Intune: The Implementation Guide
    by Carlos Perez on June 11, 2026 at 4:00 am

    <p>Now that we’ve identified the blind spot, here’s how to fix it. In Part 2 of our blog series, we deliver a phase-based implementation guide to hardening Microsoft Intune across 11 critical controls.</p>

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.