# CyberDesserts > CyberDesserts is a skills and knowledge hub for cybersecurity practitioners and students, built on a mission of accessible, hands-on education. Bridging the gap between theoretical knowledge and real-world application. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [The Security Practitioner](https://blog.cyberdesserts.com/about.md) - Hi, I'm Shak - Director of Sales Engineering at Pentera with 20+ years defending organisations against real-world attacks. After helping global companies measure their security posture, I've seen what skills and knowledge actually matter in the field. The CyberDesserts blog is an extension of that… - [AI Security Field Guide: Risk and Defence](https://blog.cyberdesserts.com/ai-security.md) - For most of its history, security has been about protecting two things: the code you run, and the machines you run it on. Applications and endpoints. AI is moving the target. The thing worth attacking is shifting toward the surfaces that AI systems create between the model and everything it can rea… - [Subscribe to Get the Cybersecurity Career Guide (Free)](https://blog.cyberdesserts.com/cybersecurity-career-resources.md) ## Posts - [An AI agent breached Hugging Face. Frontier models refused to investigate](https://blog.cyberdesserts.com/ai-incident-response.md) - An autonomous agent ran the whole attack. The defenders' frontier models refused to analyse it. - [The Vulnerabilities That Never Get a CVE](https://blog.cyberdesserts.com/silent-patching.md) - July 2026 Most vulnerability programmes run on a simple assumption: if a flaw matters, it gets a CVE, and if you watch the CVE feed and patch what appears, you are covered. The research says otherwise. Around 25% of open-source projects fix security bugs silently, without ever filing a CVE or discl… - [LiteLLM Security: Your AI Gateway Is a Secrets Manager. Benchmark It Like One](https://blog.cyberdesserts.com/litellm-security-secrets-manager.md) - July 2026 An AI gateway is a secrets manager wearing a router's clothes. LiteLLM, the most widely adopted of them, runs in production at Netflix, Lemonade and Rocket Money (InfoWorld, 2026), holding every model provider key those teams use behind a single proxy. It should be run at the standard you… - [External Attack Surface Management: Seeing What Attackers Already See](https://blog.cyberdesserts.com/external-attack-surface-management.md) - July 2026 For years, security ran on a simple mental model: build the walls high, dig the moat deep, and defend the perimeter. That model is done. The castle is broken. Cloud, SaaS and agentic tooling moved much of the estate outside the walls, and there is no longer a clean inside and outside to d… - [Your AI Coding Assistant's Config Folder Is a Persistence Surface](https://blog.cyberdesserts.com/ai-coding-assistant-config-persistence.md) - Supply-chain malware started writing into the config files your coding agent reads on every run. Nothing in the usual toolchain is watching that surface. - [The EU AI Act Lands on Your Codebase, Not Just Your Legal Team](https://blog.cyberdesserts.com/eu-ai-act-engineers.md) - July 2026 The EU AI Act for developers and technical teams The EU AI Act describes engineering work. Risk management, logging, human oversight, resilience against attackers: these are build requirements written in legal language, and the people most exposed are the ones who think it belongs to the… - [What Is Scanning My Server? An Internet Scanner Reference](https://blog.cyberdesserts.com/internet-scanner-reference.md) - You found a line in your logs you do not recognise. CensysInspect, Shodan-Pull/1.0, visionheight.com/scan, a banner that says "Hello from Palo Alto Networks". This reference tells you what each one is, and whether it is worth doing anything about. The data comes from three controlled research deplo… - [Quantum Is Breaking Your Cryptography. The Question Is When It Matters.](https://blog.cyberdesserts.com/quantum-exposure-calculator.md) - June 2026 You can settle your organisation's quantum exposure in three numbers, without guessing when a quantum computer will exist. How long your data must stay secret, how long migration takes, and how close the quantum window sits. That arithmetic, run honestly, tells most organisations the work… - [The Agent Control Plane: Security's Third Sprawl](https://blog.cyberdesserts.com/agent-control-plane.md) - June 2026 Every major platform vendor is shipping an agent control plane this year, and most of them are selling it as an entirely new frontier. The entity is new, and engineering the controls to govern something that reasons and acts on its own is a real problem. The discipline those controls draw… - [Claude Code Security Review: CodeGuard vs the Built-in Tools](https://blog.cyberdesserts.com/claude-code-security-review-codeguard.md) - June 2026 Claude Code can review your code for security flaws. Type /security-review and it scans your project for injection, exposed secrets, request-forgery risks and the rest, then hands back findings with severity and file locations. That is the native feature, and on its own it works well. But… - [What is a JA3 Fingerprint? How TLS Client Fingerprinting Works](https://blog.cyberdesserts.com/what-is-a-ja3-fingerprint.md) - Recognise the software behind any encrypted connection from its TLS handshake alone. How JA3 fingerprinting works, how to read one, and what a single hash reveals about shared attacker tooling. - [AndroxGh0st and the limits of TLS fingerprinting](https://blog.cyberdesserts.com/androxgh0st-interlock-ja3-cross-attribution.md) - May 2026 The same scanner toolkit AWS attributed to Interlock ransomware in March 2026 also runs AndroxGh0st credential theft and two other cybercrime campaigns in CyberDesserts research, showing TLS fingerprints alone cannot reliably identify which threat group is behind an attack. AWS attributed… - [Exposed AWS Credentials Are Used in Under 90 Seconds: Findings from AI Infrastructure Research](https://blog.cyberdesserts.com/exposed-credentials-pipeline.md) - Exposed AWS credentials were used against live AWS APIs within 67 seconds of being harvested, faster than CloudTrail delivers the first event to a defender. - [Is npm Safe? A Practitioner Guide to npm Security in 2026](https://blog.cyberdesserts.com/npm-security.md) - May 2026 Is npm safe to use in 2026? Yes, but the threat model has shifted. The risk in 2025-2026 is no longer the obvious malicious package, it is the trust-flow exploit: attackers compromise the developer's implicit trust in the registry, the maintainer, or the dependency tree itself. The defence… - [The Scanners Mapping AI Infrastructure Aren't After Your Model. They're After Your Credentials.](https://blog.cyberdesserts.com/ai-infrastructure-scanning-research.md) - 460 source IPs, 11,643 requests, 72 hours against exposed AI infrastructure. The operators that recognised it were cataloguing; the ones attacking were after credentials that sit on any exposed host. - [Cybersecurity Compliance Career Guide 2026](https://blog.cyberdesserts.com/cybersecurity-compliance-career-guide.md) - May 2026 Most career advice treats compliance as the boring corner of cybersecurity. Twenty years working with enterprise security teams has taught me the opposite. The compliance and framework specialists who can translate audit language into operational reality are some of the most influential pe… - [Is Cybersecurity a Good Career in 2026? The Honest Reality](https://blog.cyberdesserts.com/is-cybersecurity-a-good-career.md) - May 2026 Cybersecurity is still a good career in 2026 but the market is far more uneven than most career guides admit. Demand for experienced cybersecurity professionals remains extremely high. According to CyberSeek’s March 2026 data, US employers can fill only 74% of open cybersecurity roles. But… - [Fable 5 Is Frozen and Glasswing Still Leaves Two Problems Open](https://blog.cyberdesserts.com/claude-mythos-project-glasswing.md) - Last updated: 30 June 2026 | What's changed: both models were suspended on 12 June under a US export directive. On 27 June, Mythos 5 access was partially restored to around 100 vetted US critical infrastructure organisations. Fable 5 stays restricted. On 12 June 2026, Anthropic disabled Claude Fabl… - [Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next](https://blog.cyberdesserts.com/scattered-spider.md) - April 2026 Scattered Spider is a financially motivated cybercrime collective responsible for some of the most disruptive attacks in recent British and American corporate history. The group (tracked under aliases including UNC3944 by Mandiant, Octo Tempest by Microsoft, and Muddled Libra by Palo Alt… - [Axios NPM Supply Chain Attack (2026): What Happened and What to Do](https://blog.cyberdesserts.com/axios-npm-supply-chain-attack.md) - On March 31, 2026, two malicious versions of the axios npm package were published using a compromised maintainer account. The affected versions, axios@1.14.1 and axios@0.30.4, introduced a hidden dependency that deployed a cross-platform remote access trojan. If you ran npm install between 00:21 an… - [Information Security Metrics for Executives: How to Report Cyber Risk to the Board](https://blog.cyberdesserts.com/information-security-metrics-executives.md) - April 2026 The gap between how security teams measure their work and how boards evaluate organisational risk is not a presentation problem. It is a structural failure with measurable consequences. Information security metrics for executives are measures used to translate technical security activity… - [Anthropic Cuts OpenClaw Off Claude Subscriptions And It's Just the Start](https://blog.cyberdesserts.com/anthropic-openclaw.md) - Last updated: 5 April 2026 | What's changed: Initial publication covering April 4 enforcement. Get updates like this delivered to your inbox. Subscribe to CyberDesserts for practical security insights, no fluff. On 4 April 2026 at 12pm PT, Anthropic ended Claude Pro and Max subscription coverage fo… - [Cybersecurity Career Report: April 2026](https://blog.cyberdesserts.com/cybersecurity-career-report-april-2026.md) - CyberDesserts | blog.cyberdesserts.com | April 2026 The cybersecurity skills shortage in 2026 is not a headcount problem. It is a skills-matching problem, and that distinction changes which career paths have the strongest hiring signal right now. The ISC2 2025 Workforce Study puts a number on it: 9… - [What Censys's OpenClaw Count Reveals That February's Headlines Did Not](https://blog.cyberdesserts.com/openclaw-exposure-numbers-explained.md) - 31st March 2026 OpenClaw's internet-facing exposure has fallen sharply since the February 2026 peak. Public scrutiny, repeated security warnings, and operational changes by some operators appear to have had a real effect. That is good news, and it is worth saying clearly before anything else. It is… - [Best Cybersecurity Books for 2026](https://blog.cyberdesserts.com/cybersecurity-books.md) - Last updated: April 2026 Most cybersecurity book lists are generic. This one is different. Every recommendation here is either used in practice or recommended by professionals who rely on it daily. I love finding books that help me approach topics and inspire me to learn more or important reference… - [Your Father Spent His Life Savings on Claude Code and We Shipped Nothing](https://blog.cyberdesserts.com/human-skills-ai-cannot-replace.md) - March 2026 On AI slop, borrowed thinking, and the skills that matter when everyone has the same tools. The meme everyone is laughing at is also the most accurate professional warning of 2026. "Your father spent his life savings on Claude Code and we shipped nothing." Funny. Also a confession that a… - [Cybersecurity Career Guide (2026)](https://blog.cyberdesserts.com/cybersecurity-career-guide-2026.md) - Updated April 2026 A practical roadmap from zero to job-ready in cybersecurity. This guide breaks down what to learn, how to build real skills, and how to position yourself for roles like SOC analyst, penetration tester, cloud security, and GRC. It is designed for people who want a clear path, not… - [How to Use UK Government Cybersecurity Resources to Advance Your Security Career](https://blog.cyberdesserts.com/cybersecurity-uk-government-resources.md) - March 2026 LinkedIn Post Copy Link UK government cybersecurity resources are the most underused career asset in the profession. While the government spends millions on national security tools, they have quietly built a professional framework that anyone can use to bridge the skills gap. The governm… - [Best Blue Team Cybersecurity Books to Read in 2026](https://blog.cyberdesserts.com/blue-team-books-cybersecurity.md) - A first-year student asked me what to read for blue team. The answer surprised them, not because the list was long, but because it was short. Get practical security reads delivered to your inbox. Subscribe to CyberDesserts for no-fluff guidance. Whether you are breaking into cybersecurity, switchin… - [Why Ransomware Groups Are Targeting Firewalls and VPN Appliances](https://blog.cyberdesserts.com/ransomware-firewall-vpn-exploitation.md) - Updated July 2026: Adds the FortiBleed credential-harvesting campaign, the largest current example of the firewall-as-ransomware-entry pattern, based on SOCRadar Threat Research Unit reporting and Fortinet PSIRT analysis. Ransomware groups have shifted their initial access strategy. Rather than phi… - [Microsoft Intune Security: Hardening Privileged Access](https://blog.cyberdesserts.com/microsoft-intune-security.md) - Updated March 2026: Based on the Stryker incident and Microsoft's official hardening guidance published 13 March 2026. LinkedIn Post Copy Link Attackers do not need malware to wipe your entire device fleet. They need one compromised administrator account and access to your endpoint management conso… - [What SOC Hiring Managers Test For In Interviews](https://blog.cyberdesserts.com/soc-analyst-interview.md) - SOC hiring managers reveal what actually gets analysts hired: soft skills rank above technical ones, MITRE ATT&CK fluency is the X-factor, and AI is raising the bar without replacing the role. - [The Dead Internet Is a Security Problem: What Digg's Collapse Teaches Us](https://blog.cyberdesserts.com/ai-bots-dead-internet-security.md) - Published March 2026 Digg launched in January 2026 to challenge the idea that the internet is full of bots, by building a platform that stops them. By March 2026, the team announced significant layoffs and a product reset. The bots unfortunately won. Get practical threat intelligence like this deli… - [Can You Use AI for Security Work Without the Cloud?](https://blog.cyberdesserts.com/local-ai-security-work.md) - This article draws on three months of production experience building the CyberDesserts Security Assistant, a RAG-based AI system trained on 67,900 documents from 30 curated security sources. The findings reflect real queries, real failures, and real costs. Yes, but only for a narrow set of tasks, a… - [Will AI Replace SOC Analysts?](https://blog.cyberdesserts.com/will-ai-replace-soc-analysts.md) - March 2026 LinkedIn Post Copy Link Large language models cannot yet be trusted to make autonomous security decisions. That is not a controversial position. It is the engineering constraint that Anthropic quietly embedded into Claude Code Security's own product design. On 20 February 2026, Anthropic… - [Being Authentic in the Age of AI](https://blog.cyberdesserts.com/being-authentic-age-of-ai.md) - Guest post by Keith Beech, Director - Proactive Communications The single most effective way to stand out in an AI-saturated content landscape is to ground everything you publish in lived experience that no language model can fabricate. Ahrefs reports that 74% of new web pages now contain AI-genera… - [AI Agent Security Risks in 2026: The Incident Landscape and Hardening Framework](https://blog.cyberdesserts.com/ai-agent-security-risks.md) - In February 2026, the supply chain threat model arrived in AI agent infrastructure all at once. The Model Context Protocol is the connective tissue across every major incident. Here's what practitioners need to know. - [How the UK Government Slashed Cyber Fix Times by 84%](https://blog.cyberdesserts.com/uk-government-vulnerability-monitoring.md) - Published March 2026 The UK government has slashed cyber vulnerability fix times by 84%. Through a new nationwide scanning service, the median time to remediate DNS vulnerabilities has plummeted from 50 days to just 8. This centrally funded initiative now monitors 6,000 public sector organisations,… - [Free Cybersecurity Training: Resources by Career Path](https://blog.cyberdesserts.com/free-cybersecurity-training-resources.md) - You can break into cybersecurity without a degree using free and low-cost training resources. This is not wishful thinking. One in three cybersecurity roles are now filled without a traditional degree, and 89% of employers say they prefer candidates with certifications over formal education credent… - [Cybersecurity Graduate Guide: From Degree to First Job](https://blog.cyberdesserts.com/cybersecurity-graduate-career-guide.md) - Cybersecurity graduates can bridge the gap between degree and first job by building hands-on skills in four areas most programmes underserve: networking fundamentals, cloud security, governance frameworks, and AI/automation. The global cybersecurity workforce gap stands at 4.8 million unfilled posi… - [Does Cybersecurity Require Coding? A Practitioner's Take](https://blog.cyberdesserts.com/do-you-need-coding-for-cybersecurity.md) - March 2026 Most cybersecurity roles do not require coding. Roughly 30-40% of positions need little to no programming knowledge (CyberSeek), and information security analyst roles are projected to grow 33% through 2033 (BLS, 2024). Many of those openings will never ask you to write a single line of… - [Cybersecurity Career Report: February 2026](https://blog.cyberdesserts.com/cybersecurity-career-report-february-2026.md) - LinkedIn Post Copy Link See the April 2026 Report for spotlight on DevSecOps The global cybersecurity workforce gap has hit 4.8 million unfilled positions (ISC2, 2025). Two out of three organisations report active staffing shortages, and roughly 90% say they have skills gaps in their security setup… - [Cybersecurity Threat Landscape Report: February 2026](https://blog.cyberdesserts.com/threat-landscape-february-2026.md) - Phishing was used by 200+ tracked threat entities, making it the single most common initial access vector across our intelligence dataset. In the first two months of 2026, ransomware groups have already claimed over 460 victims, with Qilin leading the pack at 188 YTD. CISA added seven new CVEs to i… - [Two Notepad Attacks in One Week: Your Tools Are the Target](https://blog.cyberdesserts.com/notepad-attacks-developer-tools.md) - Software supply chain attacks more than doubled in 2025, with developer workstations identified as high-value targets across multiple industry reports (ReversingLabs, 2026). In the first two weeks of February 2026, two completely unrelated security incidents hit two different text editors both call… - [OpenClaw Security Risks: Malicious Skills, Exposed Instances and Real Exploits](https://blog.cyberdesserts.com/openclaw-malicious-skills-security.md) - Latest updates (March 2026): NemoClaw announced, CVE count now 60+, and independent analysis using Censys identified 63,070 live instances alongside new critical disclosures. OpenClaw is an open-source AI agent framework that lets users install third-party skills from ClawHub to automate tasks on t… - [Notepad++ Compromised for 6 Months: Check Your Version Now](https://blog.cyberdesserts.com/notepad-supply-chain-attack.md) - Updated May 2026 Notepad++ update servers were compromised from June through December 2025 by a Chinese state-sponsored threat group. The attackers hijacked the hosting infrastructure to deliver custom backdoors and Cobalt Strike payloads to targeted organisations across government, finance, and IT… - [10 Cybersecurity Best Practices That Prevent Breaches](https://blog.cyberdesserts.com/cybersecurity-best-practices.md) - Sixty percent of breaches still involve human actions (Verizon DBIR, 2025). Organisations know they should train employees, enforce MFA, and patch systems. Most have policies that say exactly that. The problem is not knowledge. The disconnect is between knowing what to do and implementing it consis… - [CVE-2026-24858: The Fortinet Patch That Wasn't](https://blog.cyberdesserts.com/cve-2026-24858-fortinet-sso-bypass.md) - Organisations running the latest FortiOS firmware, fully patched against December's critical SSO bypass, still got compromised in January. On January 26, Fortinet took the unusual step of disabling FortiCloud SSO entirely to stop the bleeding. The vulnerability now tracked as CVE-2026-24858 carries… - [Who Is WorldLeaks? The Ransomware Group Behind the Nike and Tata Electronics Breaches](https://blog.cyberdesserts.com/worldleaks-ransomware-group.md) - July 2026 WorldLeaks is a data extortion group that has claimed well over 150 victims since January 2025, including Nike, Dell, UBS, and Apple supplier Tata Electronics. It steals data and threatens to publish it unless the victim pays, and it has largely abandoned the file encryption that defines… - [Threat Actor Tools: The Complete Guide for Defenders](https://blog.cyberdesserts.com/threat-actor-tools-guide.md) - Eighty-four percent of high-severity cyberattacks in 2024 leveraged legitimate system tools rather than custom malware (Vectra AI). Cobalt Strike appeared in the majority of ransomware intrusions, while credential-dumping tools like Mimikatz remain ubiquitous across both nation-state and criminal o… - [Connect Your AI to a Cybersecurity MCP Server](https://blog.cyberdesserts.com/ai-security-assistant.md) - The learning assistant grew up. It is now an open MCP server your AI client can call directly. Here is what it does and why it exists. - [ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them](https://blog.cyberdesserts.com/what-is-clickfix-social-engineering-attack.md) - Updated April 2026 - The trust-flow patterns behind ClickFix, the variants and vectors carrying it, and the defences that work in 2026. ClickFix is a social engineering attack that tricks users into running malicious commands on their own computers. It hides behind prompts that feel routine: a CAPT… - [Public Code Pushes on GitHub Grew 78% in a Year](https://blog.cyberdesserts.com/ai-agents-software-security.md) - July 2026 GitHub's own data shows public code pushes growing 78 per cent in the year to March 2026, after four years of decline in the growth rate. What that means for the code reaching production is a harder question, and less well evidenced than the confident numbers being quoted about it. Eighty… - [Hacktivist DDoS Attacks: A Defender's Guide](https://blog.cyberdesserts.com/hacktivist-ddos-attacks.md) - NoName057(16) has targeted 3,700+ hosts in thirteen months. Their playbook is predictable: strike during elections, holidays, and geopolitical flashpoints. Here's what the La Poste attack reveals about defending against hacktivist DDoS. - [14 Crypto Scams to Watch For in 2026](https://blog.cyberdesserts.com/crypto-scams.md) - Cryptocurrency scam losses reached $9.3 billion in the United States alone in 2024, a 66% increase from the previous year (FBI IC3). In the UK, Action Fraud recorded £649 million in investment fraud losses, with cryptocurrency accounting for 66% of reports. These figures are expected to climb in 20… - [MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers](https://blog.cyberdesserts.com/mongobleed-cve-2025-14847.md) - Updated January 10, 2026: CISA's remediation deadline for federal agencies is January 19. Ubuntu has retracted its claim that rsync was affected by this CVE. Attackers are actively exploiting MongoBleed to extract credentials from MongoDB servers without authentication. The vulnerability has alread… - [Prompt Injection Attacks: Examples, Techniques, and Defence](https://blog.cyberdesserts.com/prompt-injection-attacks.md) - Updated July 2026: Added Unit 42 and Google telemetry on web-based injection observed in the wild, plus a prompt injection pattern reference for building test cases. Earlier updates added "Attacker Moves Second" adaptive-attack research, the CaMeL defence framework, and Google AI VRP scope guidance… - [Building a Second Brain for Cybersecurity Work](https://blog.cyberdesserts.com/second-brain-cybersecurity.md) - Sixty-five percent of security professionals report their job has become harder in the past two years (ISSA/ESG, 2024). New CVEs, evolving attack techniques, shifting compliance requirements, and an ever-expanding toolset create a volume of knowledge that grows faster than any individual can absorb… - [What is CTEM? Why Vulnerability Management Misses the Attack Surface](https://blog.cyberdesserts.com/what-is-ctem.md) - Most breaches do not start with a vulnerability. CTEM helps answer the question patching alone cannot: what can an attacker still reach in your environment right now? - [npm Security Risks: Most Vulnerable Packages in 2026](https://blog.cyberdesserts.com/npm-security-vulnerabilities.md) - Updated April 2026 In 2025, attackers published 454,648 malicious npm packages. That’s nearly half a million in a single year. Over 99% of all open source malware now targets npm (Sonatype, 2026), making it the most heavily attacked open source ecosystem. At the same time, open source registries pr… - [Cybersecurity Career Paths: How to Choose Your Specialisation and Advance in 2026](https://blog.cyberdesserts.com/cybersecurity-career-paths.md) - Updated April 2026 59% of organisations report critical or significant cybersecurity skills gaps (ISC2, 2025). The constraint is not headcount: it is capability in the right areas. AI security, cloud, and risk expertise are where demand outstrips supply at every experience level. Choosing the right… - [AI Security Threats: Complete Guide to Attack Vectors](https://blog.cyberdesserts.com/ai-security-threats.md) - Last Updated: January 2026 AI-driven attacks now account for 16% of all breaches (IBM, 2025). Shadow AI adds $670,000 to the average breach cost. Voice phishing attacks increased 442% in the second half of 2024 compared to the first half (CrowdStrike, 2025). If your security program hasn't adapted… - [Cybersecurity Learning Roadmap 2026: Beginner to Job-Ready](https://blog.cyberdesserts.com/cybersecurity-skills-roadmap.md) - Updated April 2026 This cybersecurity roadmap takes you from beginner to job-ready in four phases: foundations, core skills, specialisation, and career launch. It is built for people starting from zero who want a practical path into roles like SOC analyst, penetration tester, cloud security, GRC, o… - [CVE-2025-55182: React2Shell Detection and Fix Guide](https://blog.cyberdesserts.com/cve-2025-55182-react-fix.md) - UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors actively exploiting. Patch immediately. Wiz Research found vulnerable React versions in 39% of cloud environments they scanned. Half of exposed sys… - [What is Cybersecurity Culture? A Practical Guide](https://blog.cyberdesserts.com/cybersecurity-culture.md) - Human error accounts for 95% of cybersecurity breaches (IBM Security, 2024). But here is what that statistic misses: employees in organisations with poor security culture are 52 times more likely to share their login credentials during phishing attacks (KnowBe4, 2025). The problem is not your peopl… - [ELK Log Collection Methods: The Complete Guide for Security Teams](https://blog.cyberdesserts.com/elk-log-collection-methods.md) - A guide to the different types of log collection you can achieve with ELK stack for cybersecurity teams. - [What is ELK in Cybersecurity? A Security Professional's Guide](https://blog.cyberdesserts.com/what-is-elk-in-cybersecurity.md) - ELK Stack is used by security teams for centralised log management, real-time threat detection, incident response, and compliance logging. This guide covers what it is, whether it qualifies as a SIEM, and when it makes sense to deploy it. - [Why npm audit fix Isn't Working](https://blog.cyberdesserts.com/npm-audit-fix-not-working.md) - You ran npm audit fix and it made no difference. Here is why, and what to do instead. This is one of the most common frustrations in JavaScript development. The command promises to fix vulnerabilities but often leaves you exactly where you started. Understanding why this happens is the first step t… - [How Attackers Target npm Maintainer Accounts](https://blog.cyberdesserts.com/npm-supply-chain-maintainer-attacks.md) - April 2026 The registry trusts credentials, not identity. Detection time for npm maintainer account attacks has compressed from months to three hours across documented cases. The exposure window (the gap between a malicious version appearing on the registry and a developer running npm install) rema… - [Cyber Awareness Training: Behavioral Methods That Move Beyond Conventional Approaches](https://blog.cyberdesserts.com/cyber-awareness-training.md) - Only 32% of employees engage with cybersecurity awareness training (CybSafe 2025), yet 91% of successful cyberattacks still begin with a phishing email (Deloitte). Even worse: among those who do receive training, fewer than half change their behavior as a result. The Knowing-Doing Gap: Why Conventi… - [AzureHound Attacks: How to Detect Cloud Reconnaissance](https://blog.cyberdesserts.com/what-is-azurehound.md) - Updated April 2026 By default, Microsoft Graph activity logs are not enabled (Unit 42). AzureHound reconnaissance by threat actors like Storm-0501 and Void Blizzard often leaves no trace in standard Azure activity logs. If your organisation has not enabled Graph API logging, an attacker can map you… - [Linux for Cybersecurity: The Complete Learning Path](https://blog.cyberdesserts.com/linux-cybersecurity-guide.md) - A systematic path that builds skills progressively getting you comfortable with Linux, each phase preparing you for the next. - [How to Build a Cybersecurity Practice Lab in 2026](https://blog.cyberdesserts.com/cybersecurity-practice-lab-setup.md) - Updated February 2026: Expanded with cloud lab environments, Docker-based labs, AI-assisted lab building, and GitHub workflows. Original VirtualBox guide updated. 4.8 million cybersecurity positions remain unfilled globally (ISC2, 2024). Yet 90% of hiring managers consider candidates with demonstra… - [Nmap NSE Scripts for Vulnerability Scanning (2026 Guide)](https://blog.cyberdesserts.com/nmap-nse-scripting-engine.md) - Updated March 2026 The Nmap Scripting Engine (NSE) is a built-in framework that extends Nmap from a port scanner into a vulnerability detection platform, with over 600 Lua scripts included in the standard distribution (Nmap.org). You point it at discovered services, and it checks for known CVEs, mi… - [Network Scanning with Nmap: Essential Guide for Security Professionals](https://blog.cyberdesserts.com/nmap-network-scanning-guide.md) - Article Content Almost all cybersecurity professionals have familiarity with Nmap and most use it frequently. It's an important part of your pentesting toolbox. Created in 1997 and downloaded thousands of times every week, Nmap remains the gold standard for network discovery, port scanning, and sec… - [AI's Capability And Exponential Growth: 2030 is Closer Than You Think](https://blog.cyberdesserts.com/ai-capability-growth.md) - tl;dr - AI capability is doubling every 7 months, this could have massive impact on how we use AI today and into the future. - [Linux Basics for Hackers: Essential Commands for Cybersecurity Professionals](https://blog.cyberdesserts.com/linux-basics-for-hackers.md) - Article Content Over 96% of the world's top 1 million web servers run on Linux (W3Techs). Meanwhile, 100% of the top penetration testing distributions like Kali Linux, Parrot OS, BlackArch are built on Linux foundations. If you're serious about cybersecurity then learning Linux basics for hackers s… - [A Guide to Cybersecurity Maturity Models](https://blog.cyberdesserts.com/cybersecurity-maturity-models.md) - Learn how to benchmark your security program understand cybersecurity maturity levels within NIST, CMMC, and HMM, for a strategic roadmap. - [Four Threat Shifts That Will Define the 2026 Security Landscape](https://blog.cyberdesserts.com/2025-security-threat-landscape.md) - How the threat landscape shifted in 2025 and what to expect in 2026 - [Splunk Enterprise Docker Setup: Quick Start Guide for Security Testing](https://blog.cyberdesserts.com/splunk-enterprise-docker-setup.md) - Build a Splunk Enterprise security monitoring environment with Docker in 30 minutes. Learn to deploy Splunk in a container, configure syslog collection, and test data ingestion for security log analysis. Quick Overview What You'll Learn: How to setup Splunk Enterprise in Docker for security testing… - [Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened](https://blog.cyberdesserts.com/gartners-2025-supply-chain-prediction-a-retrospective-look-at-what-actually-happened.md) - LinkedIn Post Copy Link In 2021, Gartner made a bold prediction: by 2025, 45% of organizations worldwide would experience attacks on their software supply chains. That's a three-fold increase from 2021 levels. Now, as we approach the end of 2025, the data reveals some interesting insights: Gartner'… - [AI Browser Security Risks: What to Know](https://blog.cyberdesserts.com/ai-browser-security-risks.md) - Updated April 2026 This article covers browser-specific risks. For the broader agentic AI security picture including MCP security, OpenClaw, and enterprise hardening, see the AI agent security guide. In December 2025, Gartner advised enterprises to block all AI browsers. Five months later, the unde… - [Cloud Security Fundamentals: What Every Organization Needs to Know](https://blog.cyberdesserts.com/cloud-security-fundamentals-guide.md) - Ninety-four percent of enterprises now use cloud services, yet cloud misconfigurations remain the leading cause of data breaches. If your organization is moving to the cloud understanding these cloud security fundamentals is essential. Once you start building systems in the cloud, you'll quickly re… - [Cybersecurity Career Playbook - 2026](https://blog.cyberdesserts.com/cybersecurity-career-playbook.md) - 18 CYBERSECURITY SKILLS THAT SEPARATE TOP PERFORMERS - [AI and Cybersecurity: Some Interesting Thoughts from a Recent Podcast Chat](https://blog.cyberdesserts.com/ai-security-attackers-advantage-guardrails.md) - TL;DR: Attackers build unrestricted AI models while defenders work within ethical guardrails, creating a dangerous asymmetry. Your expertise determines how much AI amplifies your productivity. And sometimes the most sophisticated AI systems still fail because of a default password. - [NIST Aligned CTEM: Making Your Framework Work](https://blog.cyberdesserts.com/nist-aligned-ctem.md) - TL;DR - Discover how NIST aligned CTEM transforms framework compliance into operational security. Bridge governance maturity and real threat detection through continuous validation of NIST CSF 2.0 controls. - [Writing An Acceptable Use Policy For AI - And What to Put In It](https://blog.cyberdesserts.com/writing-an-acceptable-use-policy-for-ai.md) - TL;DR: Only 10% of companies have a comprehensive AI policy in place (Security Magazine). Where do you start with writing an acceptable use policy for ai ? - [Why Shadow AI Governance Keeps Failing](https://blog.cyberdesserts.com/shadow-ai-governance.md) - Updated March 2026 LinkedIn Post Copy Link Shadow AI governance is the set of policies, monitoring capabilities, and enforcement controls organisations use to manage AI tools adopted outside official IT approval. In most organisations, it exists only on paper. New research from CultureAI (March 202… - [ELK Stack Security Monitoring Tutorial: Setup, Threat Detection & Real-World Configuration](https://blog.cyberdesserts.com/elk-stack-security-monitoring-tutorial.md) - Quick Overview * What You'll Learn: How to setup ELK Stack for security monitoring using Docker * Time Required: 30-45 minutes * Skill Level: Intermediate * Key Outcomes: Real-time security dashboard tracking authentication failures, network activity, and system threats * Quick Start: https://githu… - [Build an npm Vulnerability Scanner (Free deps.dev)](https://blog.cyberdesserts.com/npm-vulnerability-scanner.md) - How I created a custom npm vulnerability scanner using deps.dev API to track dependencies and vulnerabilities beyond traditional tools - [Choosing A SIEM Platform: Which Is The Most Effective For You ?](https://blog.cyberdesserts.com/which-siem-should-you-choose-2025-poll.md) - Choosing a SIEM? See what security professionals actually use or try them out and share your experience. - [Build Smarter RSS News Alerts](https://blog.cyberdesserts.com/build-smarter-rss-news-alerts.md) - Master the Art of Building Free RSS News Alerts for Cybersecurity Updates! Build Smarter RSS News Alerts To Cut Through The Noise Let's be honest, topics like "ransomware," "zero-day," and "data breach" are everywhere. The sheer volume of security news can be overwhelming, making it hard to separat… - [Poisoned Packages: Auditing the NPM Supply Chain](https://blog.cyberdesserts.com/auditing-the-npm-supply-chain.md) - Navigating the rise of self-replicating worms and credential theft in the open-source world - [Getting Started With Docker: For Cybersecurity Tools](https://blog.cyberdesserts.com/getting-started-with-docker.md) - Using Docker For Cybersecurity Projects. This tutorial will take you from complete beginner to confidently running and building Docker containers. - [Top Infostealers in 2026: How They Work and How to Stop Them](https://blog.cyberdesserts.com/what-are-infostealers.md) - Updated March 2026: Expanded MFA bypass section with Adversary-in-the-Middle (AitM) and the return of Lumma LinkedIn Post Copy Link Infostealers are malware purpose-built to harvest credentials, session cookies, and authentication tokens from compromised devices then sell that data directly into th… ## Optional - [RSS Feed](https://blog.cyberdesserts.com/rss/) - [Sitemap](https://blog.cyberdesserts.com/sitemap.xml) - [Full content of pages and posts](https://blog.cyberdesserts.com/llms-full.txt)