Independent Security Researcher Β· Co-Founder @ CoDe RTD Β· Professor of Cybersecurity & AWS @ ITS ICT Piemonte
Research reports, reproducible labs and technical field notes on cloud security, agentic AI/MCP, APIs and authorized offensive validation.
Step-by-step solutions to the Byte Lotus Hotel event rooms: OSINT, web, cloud, forensics, boot2root. Each writeup with reproducible methodology, defensive notes and redacted flags β the point is how you get there, not the value.
The revision removes protocol sessions and, in the same document, forbids treating possession of a state handle as authentication. An executable conformance test for that MUST NOT: three key strategies compared, 13/13 tests, in-process lab. The composite key the spec recommends can be bypassed when the principal id contains the delimiter.
Tear-down of a sensor ring (infrared PPG sampled at 250 Hz, skin temperature at 0.1Β°C), analysis of the v2 API and sync endpoints, documentary reconstruction of the corporate and investment chain, review of the available clinical literature (73% specificity, underestimated REM stage) and of the US class actions. With a self-critique section and explicit limitations.
Analysis of an affiliate-model drainer infrastructure: from the initial phishing message to the TRC-20 approval chain, mapping of collection wallets and command infrastructure, $13,960 in transfers traced on-chain. Public sources, open channels and blockchain data.
Reproducible lab on an owned environment: from an application-level SSRF against 169.254.169.254 to the instance role's temporary credentials. Documented context (Capital One, 106 million records, $80M fine) and verifiable mitigations: HttpTokens=required, hop limit, least-privilege role policies.
// ACCESS DENIED
// Clearance level: INSUFFICIENT
// Next post loading...
// ETA: soon™
Starting from a published CNN investigation, a threat intelligence analysis of how an abuse-material distribution network stayed operational across content moderation, crypto payment rails and regulatory oversight. Based on public journalistic and documentary sources. Sensitive content.
Classroom lab on an isolated lab network: Cardputer-Adv with Bruce firmware, evil portal, beacon spam and 802.11 deauthentication. Hardware setup, commands, observed results and client- and infrastructure-side countermeasures (802.11w/PMF, captive portal verification, DNS and certificates).
OSINT investigation into an Android + Windows campaign attributed to an Iranian actor. A Windows payload not documented in public reporting, a secondary C2 at 0/94 VirusTotal detections at time of analysis, infrastructure registered roughly 8 months before the operation. Point-by-point comparison with the Unit 42 and CloudSEK reports, full indicators of compromise and detection rules published alongside the report.
Diagnosing an ICMP black hole on an access network that broke Path MTU Discovery, causing packet loss on GeForce Now and capping throughput at 26 Mbps on a 1 Gbps line. Measurement method, isolation of the offending hop and MTU/MSS-side workaround.
Wildcards in policies, root user without MFA, exposed static access keys, over-permissive roles and disabled logging. For each: how to detect it, why it matters and the applicable fix, mapped to Well-Architected Framework controls.
An LLM wired into internal data and application tooling introduces an attack surface traditional threat models do not cover. Walk-through of the input β context β tool call chain, and applicable mitigations: privilege separation, tool-level authorization, output validation and invocation logging.