Testing Lab
Resources Blog

Testing Lab

Keep up to date with the latest offensive security news, knowledge, and resources.
From Threat Volume to Real-World Exposure: What the 2025 Comcast Cybersecurity Threat Report Tells Us

From Threat Volume to Real-World Exposure: What the 2025 Comcast Cybersecurity Threat Report Tells Us

Comcast Business Cybersecurity Threat Report analyzed events, revealing how attackers are shifting tactics and accelerating the pace at which exposures become exploitable. We will expand on four of the threats that keep showing up in breach postmortems, how they work in reality, and what organizations should do about them.
Weird Ways to DA

Weird Ways to DA

Sprocket Security's Director of Technical Operations reveals how Domain Admin access was gained through overlooked misconfigurations and intricate attack paths, with both insight and humor.
Lost in Transliteration: Hidden Passwords in a Multilingual World

Lost in Transliteration: Hidden Passwords in a Multilingual World

Sprocket Security Senior Penetration Tester examines how transliteration and language backgrounds shape password creation, adding complexity for both users and attackers in his 2025 CypherCon talk.
A Primer on Insecure Reflection Practices in Java and C# Applications

A Primer on Insecure Reflection Practices in Java and C# Applications

Explore common pitfalls in Java and C# reflection practices—understand how insecure use of reflection can expose applications to vulnerabilities like code injection, unauthorized access, and bypassed security controls, and learn key strategies to harden your code.
CVE ALERT (CVE-2025-44043 & CVE-2025-44044) - The Search Bar Hacks Aren't Dead Yet

CVE ALERT (CVE-2025-44043 & CVE-2025-44044) - The Search Bar Hacks Aren't Dead Yet

Explore how Sprocket Security uncovered chained vulnerabilities and learn how overlooked parameters led to serious security risks.
What It Really Means to Be a Hacker: Lessons from 10 Years in Offensive Security

What It Really Means to Be a Hacker: Lessons from 10 Years in Offensive Security

What being a hacker really means—no title required. After a decade in offensive security, Nate Fair shares honest lessons on hacking.
2 3 4 5 6