๐บ๐๐๐๐๐๐๐ ๐ฉ๐๐
[Advent of Cyber 2025] is back with over $150,000 worth of prizes. How To Qualify? Complete the rooms in the [Advent of Cyber 2025] event, starting with Day 1. N.B: 1. It doesn't matter when you complete rooms. You just need to complete them by 31st Decemberโฆ
๐ Advent of Cyber 2025 Recap ๐
====================
I have managed to complete Advent of Cyber 2025 in the last few days. As always, It was a good learning ground for beginners to pick new concepts. Here is my review.What was your experience?
Something new I have learned
- - - - - - - - - - - - - - - - - - - - - -
Quishing: I learned that phishing via QR codes has its own name! (Day 02)
Hot Takes & Insights
- - - - - - - - - - - - - - -
1. The IDOR Misnomer (Day 05) The name Insecure Direct Object Reference is misleading. Having a "Direct Reference" (like /user/1) isn't the flawโthe flaw is missing authorization.
โ ๏ธ Pro-tip: Hiding IDs (e.g., /user/ea21f...) is just "security by obscurity." If the server doesn't check permissions, itโs still broken. Focus on the check, not the ID!
2. Practical AI Usage in Security Teams (Day 04)
๐ด Red Teams: Instant exploit script generation.
๐ต Blue Teams: Rapid log analysis post-attack.
๐ DevSecOps: Automated source code auditing.
Room Rankings
- - - - - - - - - - -
1. Favorites:
- Containers (Day 14)
- AWS Security (Day 23)
2. Annoying:
- Prompt Injection (Day 08) ๐ค (That tiny chatbot UI was a struggle!)
Tools I discovered/enjoyed
- - - - - - - - - - - - - - - - - -
1. https://hashes.com/en/tools/hash_identifier
2. https://www.uuidtools.com/decode
3. https://cyberchef.io/
4. https://github.com/activecm/rita
5. https://malware-traffic-analysis.net/
6. https://www.winitor.com/download
7. https://github.com/Seabreg/Regshot
8. https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
9. https://tio.run/#
10. https://ericzimmerman.github.io/#!index.md
#learning
#ctf
#tryhackme
@securednation
====================
I have managed to complete Advent of Cyber 2025 in the last few days. As always, It was a good learning ground for beginners to pick new concepts. Here is my review.
Something new I have learned
- - - - - - - - - - - - - - - - - - - - - -
Quishing: I learned that phishing via QR codes has its own name! (Day 02)
Hot Takes & Insights
- - - - - - - - - - - - - - -
1. The IDOR Misnomer (Day 05) The name Insecure Direct Object Reference is misleading. Having a "Direct Reference" (like /user/1) isn't the flawโthe flaw is missing authorization.
โ ๏ธ Pro-tip: Hiding IDs (e.g., /user/ea21f...) is just "security by obscurity." If the server doesn't check permissions, itโs still broken. Focus on the check, not the ID!
2. Practical AI Usage in Security Teams (Day 04)
๐ด Red Teams: Instant exploit script generation.
๐ต Blue Teams: Rapid log analysis post-attack.
๐ DevSecOps: Automated source code auditing.
Room Rankings
- - - - - - - - - - -
1. Favorites:
- Containers (Day 14)
- AWS Security (Day 23)
2. Annoying:
- Prompt Injection (Day 08) ๐ค (That tiny chatbot UI was a struggle!)
Tools I discovered/enjoyed
- - - - - - - - - - - - - - - - - -
1. https://hashes.com/en/tools/hash_identifier
2. https://www.uuidtools.com/decode
3. https://cyberchef.io/
4. https://github.com/activecm/rita
5. https://malware-traffic-analysis.net/
6. https://www.winitor.com/download
7. https://github.com/Seabreg/Regshot
8. https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
9. https://tio.run/#
10. https://ericzimmerman.github.io/#!index.md
#learning
#ctf
#tryhackme
@securednation
๐ฅ4โค2
Forwarded from Geez Security
#Launching ๐
Today marks a new chapter. Geez Security๐งโ๐ป is officially launched to strengthen cybersecurity across Ethiopia.
As digital transformation grows, so do cyber threats. Weโre here to help organizations stay secure, resilient, and prepared.
Our Services:
โ๏ธ Web,Mobile & API Penetration Testing
โ๏ธ Red Team Engagement
โ๏ธ Cyber Incident Response
& More...
๐ Cybersecurity Consulting & Training
โน๏ธ geezsecurity.com
#GeezSecurity #CyberSecurityEthiopia #DigitalSecurity2030 @geezsecurity
Today marks a new chapter. Geez Security
As digital transformation grows, so do cyber threats. Weโre here to help organizations stay secure, resilient, and prepared.
Our Services:
& More...
#GeezSecurity #CyberSecurityEthiopia #DigitalSecurity2030 @geezsecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฅ4โค1
Geez Security
#Launching ๐ Today marks a new chapter. Geez Security๐งโ๐ป is officially launched to strengthen cybersecurity across Ethiopia. As digital transformation grows, so do cyber threats. Weโre here to help organizations stay secure, resilient, and prepared. Ourโฆ
The actual date of this post is not today(01/01/2026) but from 30/12/2025. I just want to make that clear.
@securednation
@securednation
๐2
Forwarded from The Hacker News
๐จ Popular workflow automation platform n8n disclosed a critical flaw that lets authenticated users with workflow edit rights execute OS commands on the host.
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
๐ Details here โ https://thehackernews.com/2026/01/new-n8n-vulnerability-99-cvss-lets.html
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
๐ Details here โ https://thehackernews.com/2026/01/new-n8n-vulnerability-99-cvss-lets.html
๐ฅ2
[Arcanum PI Taxonomy]
Prompt Injection Attack Classification System
Prompt Injection Attack Classification System
โค2
You can't patch people. That's the painful truth in security.
๐ฏ4โค1
Forwarded from INSA Cyber Talent Center
Linkedin
Telegram Announcement (Schedule Update)
๐ Live Session Schedule Update โ INSA Cyber Talent Center
Weโre excited to announce thatโฆ
๐ Live Session Schedule Update โ INSA Cyber Talent Center
Weโre excited to announce thatโฆ
Telegram Announcement (Schedule Update)
๐ Live Session Schedule Update โ INSA Cyber Talent Center
Weโre excited to announce that our live online sessions have been refreshed with a new weekly schedule to improve consistency and engagement.
๐ New Live Sessionโฆ
๐ Live Session Schedule Update โ INSA Cyber Talent Center
Weโre excited to announce that our live online sessions have been refreshed with a new weekly schedule to improve consistency and engagement.
๐ New Live Sessionโฆ
Forwarded from INSA Cyber Talent Center
๐ด LIVE SESSION TONIGHT ๐ด
Topic: Network Security Basics
โฐ Today | 2:00 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
Join us for an essential live session where we dive into the core of infrastructure defense. Weโll move beyond the basics to explore how modern networks stay resilient against evolving cyber threats.
โก๏ธ Session highlights:
- The First Line of Defense: Firewalls, VPNs, and IDS/IPS systems.
- Deep dive into Zero-Trust architecture.
- Defense in Depth: How to layer these tools to create a "hardened" network environment.
- Interactive Q&A: Get your questions answered by experts on this field.
@insactc @cteinsa
#INSA #NetworkSecurity #ZeroTrust #Firewall #CyberSecurity
Topic: Network Security Basics
โฐ Today | 2:00 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
Join us for an essential live session where we dive into the core of infrastructure defense. Weโll move beyond the basics to explore how modern networks stay resilient against evolving cyber threats.
โก๏ธ Session highlights:
- The First Line of Defense: Firewalls, VPNs, and IDS/IPS systems.
- Deep dive into Zero-Trust architecture.
- Defense in Depth: How to layer these tools to create a "hardened" network environment.
- Interactive Q&A: Get your questions answered by experts on this field.
๐ข Happening today at 2:00 LT night. Donโt miss it!
@insactc @cteinsa
#INSA #NetworkSecurity #ZeroTrust #Firewall #CyberSecurity
Forwarded from INSA Cyber Talent Center
แจแขแแฐแ /INSA แจแแญ แขแแต/weekend แจแณแแแต แแแต แแฎแแซแ แแแแฃ แฐแแแจ
แแฎแแซแ แจแแฐแฅแ แต แแแต - แ แณแแแฑ แแจแจแป แ แณแ แฅแ แฅแแต
แแฎแแซแ แจแแฐแ แ - แ แฒแต แ แ แฃ แขแแฐแ แณแแแต แแฅแจแ
แแฎแแซแแ แแณแฐแ แจแแฝแ
1.แ แณแญแ แญ แฅแ แ แแณแฐแแต แแญแแฝ แแญแ แแญ แแฉ แณแแแต แซแแธแ แฅแ แจแแซแจแฏแธแแ แแฎแแญแถแฝ แแณแจแต แจแแฝแ
2.แฐแแ แจแแซแแแแแ แแฐแ/แปแแแ แแแ แจแแฝแ
3.แ แณแ แฅแ แฅแแต แฐแแแแฐแ แแณแฐแ แจแแฝแ
4.แจแ แแฐแ แฐแจแ แแแฎ แฅแตแจ แฉแแจแญแตแฒ แฐแแซแ
แแแแฃแ แจแแฐแจแแ แต แแแตแแญแ แแแ แแฎแแซแ แฐแฅแ แ แฐแแแ แแญแณแ - https://talent.insa.gov.et
แจแแแแฃ แแ แจแฅแญ 27 - แจแซแฒแต 07 แตแจแต
แตแแแฎแแซแ แแฅแซแชแซ แจแแแ แ แณแแแต แแฅแจแ แจแดแแแซแ แปแแ
https://t.me/insactc
https://t.me/cteinsa
แ แแแฃแต แแแแต แจแแตแฝแ แแแแ แฅแแณแแแแแข ๐ข INSA Weekend Talent Development Program โ Registration Open
The Information Network Security Administration (INSA) invites talented individuals to apply for its Weekend Talent Development Program in cyber security and related fields.
๐ Schedule: Saturdays & Sundays
๐ Location: INSA Talent Center, Addis Ababa
Eligible applicants:
โ๏ธ Talented individuals with demonstrable projects
โ๏ธ Those who pass INSAโs exam/challenge
โ๏ธ Primary school students to university graduates
โ๏ธ Must be available on weekends
๐ Registration: February 04 โ February 14
๐ Apply at: https://talent.insa.gov.et
โน๏ธ More info:
https://t.me/insactc
| https://t.me/cteinsa
แแฎแแซแ แจแแฐแฅแ แต แแแต - แ แณแแแฑ แแจแจแป แ แณแ แฅแ แฅแแต
แแฎแแซแ แจแแฐแ แ - แ แฒแต แ แ แฃ แขแแฐแ แณแแแต แแฅแจแ
แแฎแแซแแ แแณแฐแ แจแแฝแ
1.แ แณแญแ แญ แฅแ แ แแณแฐแแต แแญแแฝ แแญแ แแญ แแฉ แณแแแต แซแแธแ แฅแ แจแแซแจแฏแธแแ แแฎแแญแถแฝ แแณแจแต แจแแฝแ
2.แฐแแ แจแแซแแแแแ แแฐแ/แปแแแ แแแ แจแแฝแ
3.แ แณแ แฅแ แฅแแต แฐแแแแฐแ แแณแฐแ แจแแฝแ
4.แจแ แแฐแ แฐแจแ แแแฎ แฅแตแจ แฉแแจแญแตแฒ แฐแแซแ
แแแแฃแ แจแแฐแจแแ แต แแแตแแญแ แแแ แแฎแแซแ แฐแฅแ แ แฐแแแ แแญแณแ - https://talent.insa.gov.et
แจแแแแฃ แแ แจแฅแญ 27 - แจแซแฒแต 07 แตแจแต
แตแแแฎแแซแ แแฅแซแชแซ แจแแแ แ แณแแแต แแฅแจแ แจแดแแแซแ แปแแ
https://t.me/insactc
https://t.me/cteinsa
แ แแแฃแต แแแแต แจแแตแฝแ แแแแ แฅแแณแแแแแข ๐ข INSA Weekend Talent Development Program โ Registration Open
The Information Network Security Administration (INSA) invites talented individuals to apply for its Weekend Talent Development Program in cyber security and related fields.
๐ Schedule: Saturdays & Sundays
๐ Location: INSA Talent Center, Addis Ababa
Eligible applicants:
โ๏ธ Talented individuals with demonstrable projects
โ๏ธ Those who pass INSAโs exam/challenge
โ๏ธ Primary school students to university graduates
โ๏ธ Must be available on weekends
๐ Registration: February 04 โ February 14
๐ Apply at: https://talent.insa.gov.et
โน๏ธ More info:
https://t.me/insactc
| https://t.me/cteinsa
Sign up by March 16, 2026 for a chance to win one of 10 Course and Certification Bundles for 90-days access and 1 exam attempt. Winners are chosen at random and notified by email. No purchase required. Exclusions apply.
Sign up here: offs.ec/3Z6p7W0
Sign up here: offs.ec/3Z6p7W0
โค3
Forwarded from INSA Cyber Talent Center
๐ด LIVE SESSION ANNOUNCEMENT
๐ Main Topic: Deployment & Infrastructure Basics
๐ Time: 2:00 LT
In this live session, weโll break down how real applications move from your laptop to production โ in a simple, developer-friendly way ๐ฉ๐ฝโ๐ปโจ
๐ What youโll learn:
โ Dev vs Production Environments (whatโs really different?)
โ Application Deployment Flow (step-by-step)
โ Introduction to CI/CD โ from a developerโs perspective
โ Common mistakes developers make during deployment
Whether youโre a student, junior developer, or self-taught coder, this session will help you understand deployment without fear ๐ก
๐ฏ Join live, ask questions, and level up your backend & DevOps basics!
๐ Donโt miss it!
Join our
๐ฅ Our Group and Our Channel
๐ Main Topic: Deployment & Infrastructure Basics
๐ Time: 2:00 LT
In this live session, weโll break down how real applications move from your laptop to production โ in a simple, developer-friendly way ๐ฉ๐ฝโ๐ปโจ
๐ What youโll learn:
โ Dev vs Production Environments (whatโs really different?)
โ Application Deployment Flow (step-by-step)
โ Introduction to CI/CD โ from a developerโs perspective
โ Common mistakes developers make during deployment
Whether youโre a student, junior developer, or self-taught coder, this session will help you understand deployment without fear ๐ก
๐ฏ Join live, ask questions, and level up your backend & DevOps basics!
๐ Donโt miss it!
Join our
๐ฅ Our Group and Our Channel
the-right-questions-a-universal-troubleshooting-guide-v8.pdf
55.2 KB
A universal troubleshooting guide. There are lots of things I learned from this one page cheat sheet about how to approach a problem.
Forwarded from INSA Cyber Talent Center
๐ด LIVE SESSION TONIGHT ๐ด
Topic: Penetration Testing (Web Security)
We will cover deep about how to perform web penetration testing security based on the OWASP TOP 10.
โฐ Today | 2:00 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
@insactc @cteinsa
#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
Topic: Penetration Testing (Web Security)
We will cover deep about how to perform web penetration testing security based on the OWASP TOP 10.
โฐ Today | 2:00 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
๐ข The session have 2 classes. Donโt miss it!
@insactc @cteinsa
#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
Forwarded from INSA Cyber Talent Center
๐ด PENETRATION TESTING LIVE SESSION PART 2 WILL CONTINUE TONIGHT ๐ด
We will focus on doing a simulated labs based on the OWASP TOP 10.
โฐ Today | 1:50 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
@insactc @cteinsa
#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
We will focus on doing a simulated labs based on the OWASP TOP 10.
โฐ Today | 1:50 LT (Night)
๐ On INSA Cyber Talent Center Channel @insactc
๐ข Donโt miss it! We will ask you some questions at the end of the session.
@insactc @cteinsa
#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
โค2