SudoSecurity
  • Home
  • Minecraft
  • Programming
  • CyberSec
  • WebDev
  • SysAdmin
  • AI
Sign in Subscribe
What is OAuth?
Cybersecurity

What is OAuth?

Every time you click "Sign in with Google" or "Connect your GitHub account," you are using OAuth. You have used it hundreds of times. Most developers have implemented it at least once. And the April 2026 Vercel breach, which exposed credentials for hundreds of organizations, happened
20 Apr 2026 5 min read
CVE-2026-33032: The nginx-ui MCP Vulnerability That Hands Attackers Full Server Control
Cybersecurity

CVE-2026-33032: The nginx-ui MCP Vulnerability That Hands Attackers Full Server Control

CVE-2026-33032, dubbed MCPwn, is a CVSS 9.8 authentication bypass in nginx-ui's MCP integration that lets any attacker on the internet restart your Nginx server, rewrite your configs, and intercept all traffic -- in two HTTP requests, no credentials required. Roughly 2,700 instances are exposed.
17 Apr 2026 5 min read
BlueHammer: The Unpatched Windows Zero-Day That Weaponizes Microsoft Defender Against Your Own System
Cybersecurity

BlueHammer: The Unpatched Windows Zero-Day That Weaponizes Microsoft Defender Against Your Own System

BlueHammer is an unpatched, publicly released Windows local privilege escalation exploit that chains Microsoft Defender's update workflow, Volume Shadow Copy, Cloud Files callbacks, and opportunistic locks to reach NT AUTHORITY\SYSTEM from a standard user account.
17 Apr 2026 6 min read
Anthropic's Claude Now Requires Government ID and a Selfie — Users Are Furious
Cybersecurity

Anthropic's Claude Now Requires Government ID and a Selfie — Users Are Furious

Anthropic quietly rolled out identity verification for Claude subscriptions, asking for passports and live selfies via third-party vendor Persona. ChatGPT and Gemini require neither. Here's why this decision is a mess, who's actually affected, and what Persona's track record means for your data.
17 Apr 2026 6 min read
Claude Mythos Hacked Every Major OS, Escaped Its Sandbox, and Emailed a Researcher Eating a Sandwich. We Need to Talk.
Artificial intelligence

Claude Mythos Hacked Every Major OS, Escaped Its Sandbox, and Emailed a Researcher Eating a Sandwich. We Need to Talk.

I use AI as a tool. I'll say that upfront. Claude helps me write frontends faster. It handles search queries that Google stopped being useful for three years ago. I hand it boilerplate I've written by hand a thousand times and I get time back. That&
15 Apr 2026 21 min read
Anthropic Just Wrote Apache a $1.5M Check. Here's Why That Number Is Both Impressive and Embarrassing
Artificial intelligence

Anthropic Just Wrote Apache a $1.5M Check. Here's Why That Number Is Both Impressive and Embarrassing

Anthropic's $1.5M donation seeds a $10M Responsible AI Initiative at the Apache Software Foundation. That's more than half of ASF's entire annual budget in one shot — which tells you everything about how badly the open source infrastructure powering AI has been underfunded.
13 Apr 2026 12 min read
CVE-2025-62718: Critical Axios SSRF Vulnerability Explained
Cybersecurity

CVE-2025-62718: Critical Axios SSRF Vulnerability Explained

A critical SSRF flaw in Axios was used in a North Korean supply chain attack. Here's what it does and how to patch it today.
13 Apr 2026 16 min read
Implementing RSA, AES-GCM, and a TLS 1.3 Handshake from Scratch in Python
Members only
Cryptography

Implementing RSA, AES-GCM, and a TLS 1.3 Handshake from Scratch in Python

A deep-dive into the full cryptographic stack powering every HTTPS connection — RSA-OAEP, AES-GCM, ECDHE key exchange, and a working TLS 1.3 handshake simulation, all built in pure Python from first principles.
06 Apr 2026 43 min read
Anthropic Accidentally Shipped Claude Code's Entire Source to npm — and the Internet Read Every Line
Artificial intelligence

Anthropic Accidentally Shipped Claude Code's Entire Source to npm — and the Internet Read Every Line

On March 31, 2026, Anthropic published version 2.1.88 of Claude Code to the npm registry. Bundled inside was a 59.8 MB JavaScript source map file — a debug artifact that reconstructs the complete original TypeScript source from the minified production bundle. By 4:23 AM ET, it was
01 Apr 2026 9 min read
What is an Infostealer?
Cybersecurity

What is an Infostealer?

Infostealers are commodity malware that silently harvest credentials, session tokens, and crypto wallets from infected machines. The Lumma Stealer infection that triggered the Vercel breach started with one. Here is how they work and why they are so effective.
02 Mar 2026 5 min read
Your HTTPS Is Toast (But Google Has a Plan): Merkle Tree Certificates and the Post-Quantum Web
Cybersecurity

Your HTTPS Is Toast (But Google Has a Plan): Merkle Tree Certificates and the Post-Quantum Web

RSA-2048 can be broken with fewer than 100,000 qubits. What that means for TLS, certificate infrastructure, and the post-quantum transition already underway.
23 Feb 2026 12 min read
Cybersecurity

What is SSRF? Server-Side Request Forgery and the Attack That Breached Capital One

SSRF tricks your server into making requests to internal systems — cloud metadata services, internal APIs, AWS credentials endpoints. It turned a WAF misconfiguration into 100 million stolen Capital One records
15 Oct 2025 8 min read
What is Supply Chain Security? Dependencies, SBOMs, and the Attack That Hit 2.6 Billion npm Downloads
Cybersecurity

What is Supply Chain Security? Dependencies, SBOMs, and the Attack That Hit 2.6 Billion npm Downloads

Your application is only as secure as every package it depends on. In September 2025, attackers compromised 27 npm packages with 2.6 billion weekly downloads by phishing one maintainer.
13 Oct 2025 9 min read
What is Privilege Escalation? How Attackers Go From Foothold to Full Control
Cybersecurity

What is Privilege Escalation? How Attackers Go From Foothold to Full Control

An attacker starts with a low-privileged shell or user account and escalates to root or Administrator using misconfigurations, SUID binaries, kernel exploits, and Active Directory attacks. Here's every technique, the tools professionals use, and how to harden against it.
10 Oct 2025 10 min read
What is Social Engineering? The Attacks That Bypass Every Technical Control
Cybersecurity

What is Social Engineering? The Attacks That Bypass Every Technical Control

Phishing, vishing, pretexting, physical infiltration — here's how every technique works, how attackers use them in production breaches, and how to actually defend against them.
08 Oct 2025 9 min read
What is Penetration Testing? The Discipline of Breaking Things Before Attackers Do
Cybersecurity

What is Penetration Testing? The Discipline of Breaking Things Before Attackers Do

Penetration testing is authorized, structured hacking — finding vulnerabilities in systems, networks, and applications before real attackers do. Here's the full methodology, every phase of a real engagement, the tools professionals use, and how to build a career in it.
06 Oct 2025 10 min read
What is Cross-Site Scripting (XSS)? The Attack That Turns Your Website Against Your Users
Cybersecurity

What is Cross-Site Scripting (XSS)? The Attack That Turns Your Website Against Your Users

XSS injects malicious JavaScript into web pages served to other users — stealing sessions, redirecting to phishing pages, or silently exfiltrating data. It's been in the OWASP Top 10 since 2003. Here's every type, how each one works, and how to actually fix them.
03 Oct 2025 10 min read
What is SQL Injection? The Attack That's Been Destroying Databases Since 1998
Cybersecurity

What is SQL Injection? The Attack That's Been Destroying Databases Since 1998

In 2008, attackers used SQL injection to breach Heartland Payment Systems, a payment processing company. They stole 130 million credit and debit card numbers. The breach cost Heartland over $140 million in settlements and fines. The CEO described it as an "international cybercrime ring." The technical execution was
01 Oct 2025 10 min read
What is Encryption? The Math That Keeps Your Data Private
Cybersecurity

What is Encryption? The Math That Keeps Your Data Private

Encryption transforms readable data into unreadable ciphertext that only someone with the right key can reverse. It's what makes HTTPS, messaging apps, banking, and password storage work. Here's how it actually functions.
26 Sep 2025 9 min read
What is Cybersecurity? The Field That Keeps the Internet From Collapsing
Cybersecurity

What is Cybersecurity? The Field That Keeps the Internet From Collapsing

Cybersecurity is the discipline of protecting systems, networks, and data from attack, damage, and unauthorized access. Here's what it actually covers, how attacks work, how defense works, and why every developer needs to understand it.
24 Sep 2025 8 min read
Understanding Why PassKeys will Replace Passwords
Cybersecurity

Understanding Why PassKeys will Replace Passwords

First, allow me to start off with that I am absolutely loving using Passkeys to login into CloudFlare, Stripe, and other important services that I use to run CoderOasis. This should of been a thing a few years ago – maybe all the way back in 2016 or so. The growth
30 Jun 2023 5 min read
Hacktivism: Social Justice by Data Leaks and Defacements
Cybersecurity Featured

Hacktivism: Social Justice by Data Leaks and Defacements

A CEO bragged he'd unmasked Anonymous. Hours later, a SQL injection in his own CMS ended his career. The real attack chains behind hacktivism, tools included.
08 Jun 2022 12 min read
RSA Part 3: Your Correct Implementation Still Leaks the Key
Cryptography Featured

RSA Part 3: Your Correct Implementation Still Leaks the Key

Key generation works, encryption round-trips, the math is provably right — and an attacker can still recover the private key by timing your decryptions. Here are both defenses, measured, with what they actually cost.
08 Apr 2022 10 min read
RSA Part 2: Real Primes, Real Text, and a Bug That Eats Your Data
Cryptography Featured

RSA Part 2: Real Primes, Real Text, and a Bug That Eats Your Data

Part 1 used 15-bit primes and only encrypted integers. Making it usable means generating 1024-bit primes and chunking bytes — and the standard way to do the second one silently destroys data on inputs the tests never cover.
21 Aug 2021 12 min read
Python Code
Cryptography Featured

RSA in Python From Scratch: The Math, the Code, and What Breaks It

Every HTTPS connection you have ever made runs on a 1978 paper. You can build the core of it in about fifty lines of Python — and then see exactly why those fifty lines would get you destroyed in production.
19 Aug 2021 14 min read
← Newer Posts Page 2 of 2
SudoSecurity © 2026
  • Topics
  • Meet the Team
  • Best Articles
  • Archives
Powered by Ghost