We Went on a SharePoint Expedition, and Here’s What We Found
Of the nearly 30,000 public facing SharePoint portals we found, approximately 3,300 are self-hosted meaning they are vulnerable to the critical CVE-2026-50522.
Of the nearly 30,000 public facing SharePoint portals we found, approximately 3,300 are self-hosted meaning they are vulnerable to the critical CVE-2026-50522.
Principal Pentester Scottie Cole continues his NetExec series with nxcdb, the database that automatically stores key info like hosts and creds while you hack.
Enumerating webpages during an internal network pentest can be a large task, but GoWitness makes it easy to focus on high value webpages. Learn how it works.
The new critical Microsoft Defender exploit, RoguePlanet (CVE-2026-50656), is confirmed active in the wild. Learn what it is and how to protect your network.
Endpoint security detects many malicious files created with pentest tools, but pentesters can sometimes bypass this by rebuilding source code. Learn how here.
BloodHound’s Community Edition has everything a penetration tester needs to enumerate relationships in a domain in order to gain more access, even Domain Admin.
With current local privilege escalation exploits like Copy Fail and Dirty Frag active in the wild, harden your defenses to halt attacks even before patching.
Now that CrackMapExec is no more, how is a pentester to rapidly test credentials, enumerate assets, spray passwords, and more? Learn the basics of NetExec here.
CVE-2026-0300 is a critical buffer overflow vulnerability in Palo Alto’s PAN-OS software. Discover if you are affected and what to do now.
CVE-2026-31431, dubbed Copy Fail, allows privilege escalation to root on Linux distros missing the latest kernel patches. Learn what to do in this blog.
Raxis Lead Penetration Tester Nathan Anderson continues our Cool Tool Series with SCP for data exfiltration on internal network pentests and red teams.
Lead Penetration Ryan Chaplin explains how to protect your network against CVE-2026-24061 and CVE-2026-32746, two critical Telnet flaws released this year.
28 posts in Networks.