Find the latest Webinar content from the Sprocket Testing Team.
Resources Blog

Blog

Keep up to date with the latest offensive security news, knowledge, and resources.
LLMs Don't Follow Rules – They Follow Context
Feb 24, 2026

LLMs Don't Follow Rules – They Follow Context

LLM behavior isn't governed by a rulebook — it emerges from context, shaped by a stack of training, fine-tuning, and runtime instructions. Understanding this explains why the same model gives radically different responses to functionally identical requests.
Hunting Secrets in JavaScript at Scale: How a Vite Misconfiguration Lead to Full CI/CD Compromise
Feb 16, 2026

Hunting Secrets in JavaScript at Scale: How a Vite Misconfiguration Lead to Full CI/CD Compromise

Sometimes when conducting a Penetration Testing exercise or Red Team engagement, you might be interested in extracting password hashes or credentials of your target Windows user, without the use of Mimikatz to avoid detection. This is where you would resort to using an NTLM downgrade attack. In this article we shall discuss how you can be able to perform this...
Ahead of the Breach – Matthew Winters on Threat Hunting, Graph Thinking, and Making Adversaries Cry
Feb 11, 2026

Ahead of the Breach – Matthew Winters on Threat Hunting, Graph Thinking, and Making Adversaries Cry

Matthew Winters of T. Rowe Price joins the pod to discuss how graph thinking changes the way you can investigate threats, mixed in with a nice dose of making life harder for attackers.
The Dangers of Public Registration in Web Apps: How a JWT + oData Leaked Millions of Records
Feb 06, 2026

The Dangers of Public Registration in Web Apps: How a JWT + oData Leaked Millions of Records

Nick Aures guides us through a real-life pentesting moment with important lessons for authentication using industry-standard technology, in this case JWTs.
Gear Up with Sprocket: AWS Scanner
Jan 22, 2026

Gear Up with Sprocket: AWS Scanner

Discover how Sprocket Security’s AWS Scanner continuously maps public cloud assets to keep penetration testing and attack surface management current.
The Cyber Threats That Will Define 2026 (And Why Point-in-Time Testing Keeps Missing Them)
Jan 20, 2026

The Cyber Threats That Will Define 2026 (And Why Point-in-Time Testing Keeps Missing Them)

Security risks for 2026 aren’t new threats. They’re missing exposure. Learn what attackers exploit today and why traditional pentests fall short.
1 2 3 4 5