Ten lessons from Black Hat and DEF CON on AI agents, cheaper attacks, supply chain risk, security fundamentals and cyber skills.
Tag: OffSec
Are Security Teams Keeping Pace With AI-Accelerated Threats?
The strongest response to AI-driven change is a workforce that can use faster tools without surrendering the judgment behind the work.
What If Your Idea Became the Next OffSec Lab?
Learn all about OffSec’s new Creator Platform – create labs, earn rewards and help the security community skill up.
Road to OSCE3: Episodio 1 – OSEP
¡Hola a todos! Con este post da comienzo una serie de 3 posts donde hablaré de las certificaciones que forman OSCE3 y de cómo yo me las he preparado. ¿Qué…
Knowing what not to attack
Most talk about offensive security agents is about power. Can it find the bug? Can it chain the exploit? Can it own the box? That’s the easy part. Wiring…
CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability
CVE-2026-72898 is a critical unauthenticated SQL injection in Metabase’s password-reset functionality. Learn more about it.
Who Secures AI When It Touches Every Security Team?
Learn how organizations can develop relevant offensive knowledge across every security function responsible for AI systems.
What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security
The recent water system attacks are a reminder that familiar techniques can have serious consequences when they reach critical infrastructure. Preparing…
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Recently, I read a great post by Melvin Tan Zhi Xian sharing his thoughts halfway through the OffSec OSAI+ course. He touched on something crucial that…
How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability
If your agency is planning how to use remaining Fiscal Year funding, now is the time to build a stronger cybersecurity workforce.
The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?
The EU AI Act deadline is approaching but the attack surface is already here. Is your workforce ready to secure it? The post The EU AI Act Deadline Is Approaching. Is Your Workforce Ready? appeared first on OffSec. This article…
Cybersecurity Training in the Age of AI
How AI is changing cybersecurity training, why live learning matters, and how AI-300 helps professionals secure evolving AI systems. The post Cybersecurity Training in the Age of AI appeared first on OffSec. This article has been indexed from OffSec Read…
Intro to STIG Tools
Effective hardening requires balancing security, operational needs, and long term maintainability. The post Intro to STIG Tools appeared first on OffSec. This article has been indexed from OffSec Read the original article: Intro to STIG Tools
AI vs Traditional Penetration Testing: Tooling and Outcomes
Second part of the AI vs Traditional Pentesting series, focusing this time on tools and outcomes of both approaches. The post AI vs Traditional Penetration Testing: Tooling and Outcomes appeared first on OffSec. This article has been indexed from OffSec…
What Live Cybersecurity Training Reveals That Self-Paced Learning Doesn’t
Hear directly from OffSec’s Live Training instructor on what makes live training different than self-paced training. The post What Live Cybersecurity Training Reveals That Self-Paced Learning Doesn’t appeared first on OffSec. This article has been indexed from OffSec Read the…
AI Penetration Testing vs Traditional Penetration Testing: Changes in 2026
AI pentesting vs traditional testing in 2026: where AI wins, where humans still matter, and which skills compound for offensive security. The post AI Penetration Testing vs Traditional Penetration Testing: Changes in 2026 appeared first on OffSec. This article has…
從 Noob 到 Ambassador 的旅程
在這個 AI 能快速回答問題、產生程式碼,甚至分析漏洞的時代,我常常在思考一個問題:學習資安過程中的卡關、反覆嘗試和失敗意味著什麼? 一直以來我都是個很喜歡學習各種有趣東西的人(即使不見得對我現在有用),我的其中一個學習哲學就是:「學習本身就是目的」。我至今仍然無法忘懷當年為了一個簡單的漏洞,苦思冥想奮戰數天,也曾為了弄復現漏洞,投入很長的時間反覆測試和驗證(我相信這是很多資安人曾經或現在的寫照)。 還記得第一次正式接觸資訊安全,是在我大學時期偶然參加的一次 Wargame,以現在的角度來看,簡單到令人驚訝,我還記得第一關,就是對著網頁 F12(或右鍵查看原始碼),Flag 就在當中。不過對於當初非本科系出身的我,彷彿打開了新世界的大門,上一次接觸到類似的東西大概是國小時期的 VB6。 在那場 Wargame 之後,我開始積極的尋找各種平台練習,不出意外,遇到比想像中更多的難關,當時我不會寫程式、對資訊系統的理解幾乎是從零開始,因此我開始回頭從最基礎的Python / TCP / Linux 指令開始,在那個沒有 LLM 的年代只能依賴實體的書籍、各種線上資源與社群。 在 2018 的某天意外看到 Billy 的一篇關於 OSCP 的文章,開啟了我對這張證照的興趣,接著又在 PTT 上看到有人發文說「想創個 Kali 的社群」,我就私訊了那位發文者 T0ny,他把我邀進去群組後,發現群組成員:只有我、那位發文者 T0ny。 身為一個當時對於資安技術充滿好奇的人,我開始加入很多資安群組,也在 PTT 上發文,宣傳我們的小群組,希望能找到願意一起學習和交流的人(現在想想還真是有點厚臉皮)。 這裡還有個小故事,由於當年我實在厭煩於有些人會跑到資安群組問「能不能幫我入侵 XXX」,我設計了一個表單,裡面都是一些簡單的資安問題,目的是希望避免一樣的情況發生,效果意外的不錯。 總之我徹底踏入滲透測試這個領域,也很幸運地結識了 Billy、Dexter 和其他當年一起奮戰打…
Beat AI or Let AI Beat You
AI feels like an enemy. From a certain angle, it is. But mostly it’s just scary, the same way the internet was scary back in the day, and the same way personal computers were scary before that. It helps to…
Matcha, Sueño y Ejercicio: La Guía Off-Topic del Hacker Saludable
Presentación Aquí está el primer post del blog del equipo del Capítulo Español. Esta vez queremos empezar con algo un poco off-topic para dar inicio al blog de la comunidad OffSec. En este 1º Post quiero empezar un poco hablando…
The Gap Between Cybersecurity Training Investment and Actual Team Performance
If your team can pass certifications but you’re not sure how they’d perform during a real incident, see how Live Training closes that gap The post The Gap Between Cybersecurity Training Investment and Actual Team Performance appeared first on OffSec.…
