<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Paolo Costanzo — Independent Cybersecurity Research</title>
    <link>https://paolocostanzo.github.io</link>
    <description>Research reports, reproducible labs and technical field notes on cloud security, agentic AI and MCP, threat intelligence, networks and authorized offensive validation.</description>
    <language>en</language>
    <lastBuildDate>Sat, 08 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://paolocostanzo.github.io/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>CTF Writeups — Hacker Holidays 2026 (Byte Lotus Hotel)</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Step-by-step writeups for the TryHackMe Hacker Holidays 2026 series: a room a day across OSINT, web, cloud, forensics and boot2root. Every writeup is a reproducible runbook with methodology, defensive notes and redacted flags — the method is the point, not the flag value.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
      <category>Offensive Validation</category>
    </item>
    <item>
      <title>Management Wants a Word — TryHackMe Hacker Holidays 2026 Day 14 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/management-wants-a-word/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/management-wants-a-word/</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 14 forensics walkthrough: an autologon secret in the SECURITY hive unwinds DPAPI to Chrome&#x27;s saved password, which opens a VeraCrypt vault. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>The Guestbook — TryHackMe Hacker Holidays 2026 Day 13 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-guestbook/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-guestbook/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 13 walkthrough: /vera/activity shows every tool call VERA makes. Indirect prompt injection reaches the override: tool, which runs /bin/sh. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>After Hours — TryHackMe Hacker Holidays 2026 Day 12 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/after-hours/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/after-hours/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 12 forensics walkthrough: no specialist parser — strings and python3 carve OBJECTS.DATA to a CommandLineEventConsumer and a .NET payload. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Infinity Pool — TryHackMe Hacker Holidays 2026 Day 11 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/infinity-pool/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/infinity-pool/</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 11 walkthrough: command injection on a Flask netcheck, hard-coded FreePBX 16 UCP creds (CVE-2026-46376), a key in a voicemail, then root. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>The Hollow Shell — TryHackMe Hacker Holidays 2026 Day 10 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-hollow-shell/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-hollow-shell/</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 10 walkthrough: zip-slip beats an allowlist that only reads the manifest, then a poisoned Jinja template fires on a fresh gunicorn worker. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>CryptoCabana — TryHackMe Hacker Holidays 2026 Day 9 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/cryptocabana/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/cryptocabana/</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 9 Azure walkthrough: an over-scoped SAS token lists the whole account, a hidden container leads to Key Vault, the flag in an old version. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Towel on the Sunbed — TryHackMe Hacker Holidays 2026 Day 8 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/towel-on-the-sunbed/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/towel-on-the-sunbed/</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 8 walkthrough: a TOCTOU race on /claim, ten Burp Repeater tabs in parallel, Whale tier. The detail most posts skip: the session must be clean. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Do Not Disturb — TryHackMe Hacker Holidays 2026 Day 7 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/do-not-disturb/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/do-not-disturb/</guid>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 7 boot2root walkthrough: $ne login bypass, EJS SSTI on /staff/preview, RCE, then root without uid=0 via node --inspect and the disk group. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Overheard at Breakfast — TryHackMe Hacker Holidays Day 6 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/overheard-at-breakfast/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/overheard-at-breakfast/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate>
      <description>Day 6 OSINT walkthrough: a Discord screenshot leaks an email, the normalised MD5 opens the Gravatar, and /{md5}.json hides the flag in aboutMe. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Beach Bar — TryHackMe Hacker Holidays 2026 Day 5 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/beach-bar/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/beach-bar/</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 5 boot2root walkthrough: demo creds in view-source, an unsafe yaml.load turns a playlist import into RCE, ps aux leaks the root password. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Packed Light — TryHackMe Hacker Holidays 2026 Day 4 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/packed-light/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/packed-light/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 4 forensics walkthrough: from pcap to a keylogger exfiltrating keystrokes in Cookie headers. One char at a time, so it stays single-byte XOR. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Complimentary — TryHackMe Hacker Holidays 2026 Day 3 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/complimentary/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/complimentary/</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 3 cloud walkthrough: the kiosk hands you AWS keys. An anonymous Cognito pool plus an IAM role that allows dynamodb:Scan dumps the table. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>Room 404 — TryHackMe Hacker Holidays 2026 Day 2 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/room-404/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/room-404/</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 2 walkthrough: one curl to /.git/HEAD confirms the leak, git-dumper rebuilds the repo, and the flag sits in a supposedly cleaned commit. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>The Concierge Knows Too Much — TryHackMe Hacker Holidays Day 1 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-concierge-knows-too-much/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-concierge-knows-too-much/</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 1 walkthrough: prompt injection on the VERA LLM concierge. No jailbreak — recognition isn&#x27;t authentication, so she lists the VIPs herself. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>
    <item>
      <title>The Brochure — TryHackMe Hacker Holidays 2026 Day 0 Writeup</title>
      <link>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-brochure/</link>
      <guid>https://paolocostanzo.github.io/ctf/hacker-holidays-2026/the-brochure/</guid>
      <pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate>
      <description>Day 0 walkthrough: the EXIF is clean, the clue is printed. From the PNG brochure to an Instagram account, its only following, three Base64 posts. Flags redacted.</description>
      <category>CTF</category>
      <category>Walkthrough</category>
      <category>TryHackMe</category>
    </item>

    <item>
      <title>MCP 2026-07-28: Stateless Does Not Mean State-Free</title>
      <link>https://paolocostanzo.github.io/mcp-2026-07-28-stateless-security/</link>
      <guid>https://paolocostanzo.github.io/mcp-2026-07-28-stateless-security/</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Revision 2026-07-28 removes MCP protocol sessions and, in the same document, forbids treating possession of a state handle as authentication. An executable conformance test for that MUST NOT: three key strategies compared under identical tokens and UUIDs, 13/13 tests, fully in-process lab. The composite key the specification recommends turns out to be bypassable when the principal id contains the delimiter.</description>
      <category>Agentic AI</category>
      <category>MCP</category>
      <category>Tool Authorization</category>
      <category>Cloud Security</category>
    </item>

    <item>
      <title>Wearable Biometric Telemetry: Technical Tear-down and Data Supply Chain</title>
      <link>https://paolocostanzo.github.io/oura-palantir-biometrici/</link>
      <guid>https://paolocostanzo.github.io/oura-palantir-biometrici/</guid>
      <pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate>
      <description>Tear-down of a sensor ring (infrared PPG at 250 Hz, skin temperature at 0.1 °C), analysis of the v2 API and sync endpoints, documentary reconstruction of the corporate and investment chain, review of the clinical literature and of the US class actions. Includes a self-critique section and explicit limitations.</description>
      <category>Privacy</category>
      <category>Wearable</category>
      <category>OSINT</category>
    </item>

    <item>
      <title>Coordinated Abuse Network on Telegram: Content Moderation, Payment Rails and Regulatory Response</title>
      <link>https://paolocostanzo.github.io/rape-academy-cnn-threat-intel/</link>
      <guid>https://paolocostanzo.github.io/rape-academy-cnn-threat-intel/</guid>
      <pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate>
      <description>Starting from a published CNN investigation, a threat intelligence analysis of how an abuse-material distribution network stayed operational across content moderation, crypto payment rails and regulatory oversight. Public journalistic and documentary sources. Sensitive content.</description>
      <category>Threat Intelligence</category>
      <category>OSINT</category>
      <category>Content Moderation</category>
    </item>

    <item>
      <title>Anatomy of a TRON Wallet Drainer-as-a-Service</title>
      <link>https://paolocostanzo.github.io/crypto-drainer-svuotatasche/</link>
      <guid>https://paolocostanzo.github.io/crypto-drainer-svuotatasche/</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate>
      <description>Analysis of an affiliate-model drainer infrastructure: from the initial phishing message to the TRC-20 approval chain, mapping of collection wallets and command infrastructure, $13,960 in transfers traced on-chain. Public sources, open channels and blockchain data.</description>
      <category>Threat Intelligence</category>
      <category>OSINT</category>
      <category>On-chain</category>
    </item>

    <item>
      <title>SSRF → IMDSv1: Exfiltrating IAM Credentials from an EC2 Instance</title>
      <link>https://paolocostanzo.github.io/ssrf-imds-ec2-credentials/</link>
      <guid>https://paolocostanzo.github.io/ssrf-imds-ec2-credentials/</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <description>Reproducible lab on an owned environment: from an application-level SSRF against 169.254.169.254 to the instance role&#x27;s temporary credentials. Documented context (Capital One, 106 million records) and verifiable mitigations: HttpTokens=required, hop limit, least-privilege role policies.</description>
      <category>Cloud</category>
      <category>AWS</category>
      <category>SSRF</category>
    </item>

    <item>
      <title>Evil Portal, Beacon Spam and Deauth: a €40 Hardware Wi-Fi Lab</title>
      <link>https://paolocostanzo.github.io/cardputer-adv-wifi-security/</link>
      <guid>https://paolocostanzo.github.io/cardputer-adv-wifi-security/</guid>
      <pubDate>Sat, 21 Mar 2026 00:00:00 +0000</pubDate>
      <description>Classroom lab on an isolated lab network: Cardputer-Adv with Bruce firmware, evil portal, beacon spam and 802.11 deauthentication. Hardware setup, commands, observed results and client- and infrastructure-side countermeasures (802.11w/PMF, captive portal verification, DNS and certificates).</description>
      <category>Wi-Fi</category>
      <category>Hardware</category>
      <category>Lab</category>
    </item>

    <item>
      <title>Operation Epic Fury: Independent OSINT Analysis of a Dual-Platform Campaign</title>
      <link>https://paolocostanzo.github.io/operation-epic-fury-cyber-war-iran/</link>
      <guid>https://paolocostanzo.github.io/operation-epic-fury-cyber-war-iran/</guid>
      <pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate>
      <description>OSINT investigation into an Android + Windows campaign attributed to an Iranian actor. A Windows payload not documented in public reporting, a secondary C2 at 0/94 VirusTotal detections at time of analysis, infrastructure registered roughly 8 months before the operation. Comparison with the Unit 42 and CloudSEK reports, IoCs and detection rules.</description>
      <category>Threat Intelligence</category>
      <category>OSINT</category>
      <category>Payload Analysis</category>
    </item>

    <item>
      <title>TIM, GeForce Now and the ICMP Black Hole</title>
      <link>https://paolocostanzo.github.io/tim-packet-loss-gfn/</link>
      <guid>https://paolocostanzo.github.io/tim-packet-loss-gfn/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate>
      <description>Diagnosing an ICMP black hole on an access network that broke Path MTU Discovery, causing packet loss on GeForce Now and capping throughput at 26 Mbps on a 1 Gbps line. Measurement method, isolation of the offending hop and MTU/MSS-side workaround.</description>
      <category>Network</category>
      <category>ISP</category>
      <category>Diagnostics</category>
    </item>

    <item>
      <title>AWS IAM: Five Recurring Misconfigurations and How to Fix Them</title>
      <link>https://paolocostanzo.github.io/aws-iam-misconfiguration/</link>
      <guid>https://paolocostanzo.github.io/aws-iam-misconfiguration/</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate>
      <description>Wildcards in policies, root user without MFA, exposed static access keys, over-permissive roles and disabled logging. For each: how to detect it, why it matters and the applicable fix, mapped to Well-Architected Framework controls.</description>
      <category>Cloud</category>
      <category>AWS</category>
      <category>IAM</category>
    </item>

    <item>
      <title>Prompt Injection on Enterprise LLMs: Attack Surface and Mitigations</title>
      <link>https://paolocostanzo.github.io/prompt-injection-llm/</link>
      <guid>https://paolocostanzo.github.io/prompt-injection-llm/</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate>
      <description>An LLM wired into internal data and application tooling introduces an attack surface traditional threat models do not cover. Walk-through of the input → context → tool call chain and applicable mitigations: privilege separation, tool-level authorization, output validation and invocation logging.</description>
      <category>AI Security</category>
      <category>LLM</category>
      <category>AppSec</category>
    </item>

  </channel>
</rss>
