- CMMC is (Not) Cancelledby Chris Camejo on July 16, 2026 at 4:00 am
<p>Word is out that the Department of War (DoW) has suspended the rollout of CMMC Phase II. However, contractors working on CMMC compliance should not abandon their CMMC plans: Although the audit requirement is suspended,…</p>
- Pandora’s Container Part 1: Unpacking Azure Container Securityby Justin Mahon on July 14, 2026 at 4:00 am
<p>Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting registries, token keys, and container instances in Azure.</p>
- Vulnify: Giving Your Agents a CVE Brainby Brandon McGrath on July 9, 2026 at 4:00 am
<p>The CVE brain your AI agent has been missing. In this blog, we introduce Vulnify, an open-source tool that stitches eight authoritative vulnerability databases into a single offline source of truth for CVE intelligence.</p>
- Welcoming ObfusGitby Kevin Haubris on July 7, 2026 at 4:00 am
<p>What if your public repo could stay out of AI training data without changing how you commit? In this blog, we introduce ObfusGit, a Python tool that obfuscates your public copy while your local repo stays untouched.</p>
- Inheriting the Receipts: Securing the AI Your Company Already Adoptedby Rockie Brockway on July 2, 2026 at 4:00 am
<p>The work is not new. The speed is. In this blog, we’re outlining how existing security pillars apply to the AI your organization has already adopted; no new doctrine, new team, or new budget line required.</p>
- Large Workflows with Local LLMsby Kevin Haubris on June 25, 2026 at 4:00 am
<p>As it turns out, local LLMs have a few opinions about large workflows. In this blog, we walk through the scaling challenges of local LLMs and the custom Python library built to wrangle them.</p>
- Modern Web Application Content Discoveryby Luke Bremer on June 18, 2026 at 4:00 am
<p>Staring at a web app with no links and no navigation? In this blog, we break down modern content discovery, from forced browsing and web crawling to Google dorking and GitHub recon.</p>
- JQ for Hackersby Justin Bollinger on June 16, 2026 at 4:00 am
<p>Grey-bearded hackers and sysadmins still reaching for cut and CSV files, this one’s for you. In this blog, we break down jq and why it’s time to embrace JSON.</p>
- JS-Tap v3: Endpoint Post-Exploitation With JavaScript Implantsby Drew Kirkpatrick on June 12, 2026 at 4:00 am
<p>JavaScript escaped the browser. JS-Tap v3 followed it. In this blog, we introduce three new beacons targeting the Electron apps, browser extensions, and Node runtimes running on corporate workstations.</p>
- Hardening Intune: The Implementation Guideby Carlos Perez on June 11, 2026 at 4:00 am
<p>Now that we’ve identified the blind spot, here’s how to fix it. In Part 2 of our blog series, we deliver a phase-based implementation guide to hardening Microsoft Intune across 11 critical controls.</p>
TrustedSec
We are an ethical website cyber security team and we perform security assessments to protect our clients.




