Who is hacked?
Posts
RSS-
Part 2: Understanding and Assessing MCP servers from an AppSec Perspective
Securing MCP in production: Docker/Microsoft gateways, OAuth patterns, proxies, corporate controls, key risks (confused deputy, token passthrough, sessions), and a full checklist.
-
Part 1: Understanding and Assessing MCP servers from an AppSec Perspective
How to review MCP servers from an AppSec angle: scope, source review, prompt/policy checks, Docker + MCP Guardian testing, safe configs, and version pinning.
-
Getting Started with AI Security Testing: Resources for Pentesters and AppSec Professionals
AI is everywhere, and security professionals are increasingly being asked to test AI-powered products. In this post, I share the most useful resources I've found for understanding and...
-
OSCP Preparation: My Experience and Tips for Success
Answers to the questions I get asked most about the OSCP: how I prepared, what the exam itself was like, and the tips that actually helped.
-
Phishing Attack on Telegram: My Experience and Countermeasures
My investigation into a phishing campaign in Telegram.
-
Small investigation: phishing campaign in Spain
My investigation into a phishing campaign in Spain.