Offensive Security
Resources Blog

Offensive Security

Keep up to date with the latest offensive security news, knowledge, and resources.
CVE-2026-9209: Pre-Authentication SQL Injection to Remote Code Execution in mJobTime

CVE-2026-9209: Pre-Authentication SQL Injection to Remote Code Execution in mJobTime

Unauthenticated SQL injection in mJobTime (CVE-2026-9209) exposes construction and field services data. No vendor fix exists after 120-day disclosure.
Can We Beat the Adversary, or Am I Willing to Accept the Risk?

Can We Beat the Adversary, or Am I Willing to Accept the Risk?

Most security programs detect breaches. Fewer can prove they won't happen. Learn the offensive security framework that turns "are we secure?" into an answerable question.
The Human Touch in the Era of AI: Why Pentesting Still Needs a Human in the Loop

The Human Touch in the Era of AI: Why Pentesting Still Needs a Human in the Loop

AI accelerates pentesting but human judgement close the gap. See how two real engagements turned quiet banners and a single timestamp into critical findings.
Top 10 CPTaaS Companies in 2026: The Definitive Guide

Top 10 CPTaaS Companies in 2026: The Definitive Guide

Explore the top 10 CPTaaS companies in 2026. Compare continuous penetration testing platforms, PTaaS providers, ASM capabilities, compliance support, and human-led testing models.
Cracking NTLMv1 SSP With Rainbow Tables

Cracking NTLMv1 SSP With Rainbow Tables

Step-by-step walkthrough of cracking NTLMv1-SSP hashes with rainbow tables, including how to coerce auth, disable ESS, recover NT hashes, and remediate.
Penetration Testing Strategies for Legacy Healthcare Systems

Penetration Testing Strategies for Legacy Healthcare Systems

Legacy healthcare systems can’t be patched but they can’t be ignored. Learn how to pentest around clinical assets without disrupting patient care.
1 2 3 4 5