๐‘บ๐’†๐’„๐’–๐’“๐’Š๐’•๐’š ๐‘ฉ๐’๐’š
136 subscribers
579 photos
9 videos
11 files
374 links
Security Trainer | | System Administrator || CCNA || CC || Google Cybersecurity Professional

Join: https://t.me/sbycommunity
Contact: @Jetoson
Download Telegram
๐‘บ๐’†๐’„๐’–๐’“๐’Š๐’•๐’š ๐‘ฉ๐’๐’š
[Advent of Cyber 2025] is back with over $150,000 worth of prizes. How To Qualify? Complete the rooms in the [Advent of Cyber 2025] event, starting with Day 1. N.B: 1. It doesn't matter when you complete rooms. You just need to complete them by 31st Decemberโ€ฆ
๐Ÿ“Œ Advent of Cyber 2025 Recap ๐Ÿ“Œ
====================
I have managed to complete Advent of Cyber 2025 in the last few days. As always, It was a good learning ground for beginners to pick new concepts. Here is my review. What was your experience?

Something new I have learned
- - - - - - - - - - - - - - - - - - - - - -
Quishing: I learned that phishing via QR codes has its own name! (Day 02)

Hot Takes & Insights
- - - - - - - - - - - - - - -
1. The IDOR Misnomer (Day 05) The name Insecure Direct Object Reference is misleading. Having a "Direct Reference" (like /user/1) isn't the flawโ€”the flaw is missing authorization.

โš ๏ธ Pro-tip: Hiding IDs (e.g., /user/ea21f...) is just "security by obscurity." If the server doesn't check permissions, itโ€™s still broken. Focus on the check, not the ID!

2. Practical AI Usage in Security Teams (Day 04)
๐Ÿ”ด Red Teams: Instant exploit script generation.
๐Ÿ”ต Blue Teams: Rapid log analysis post-attack.
๐Ÿ›  DevSecOps: Automated source code auditing.

Room Rankings
- - - - - - - - - - -
1. Favorites:
- Containers (Day 14)
- AWS Security (Day 23)

2. Annoying:
- Prompt Injection (Day 08) ๐Ÿค– (That tiny chatbot UI was a struggle!)

Tools I discovered/enjoyed
- - - - - - - - - - - - - - - - - -
1. https://hashes.com/en/tools/hash_identifier
2. https://www.uuidtools.com/decode
3. https://cyberchef.io/
4. https://github.com/activecm/rita
5. https://malware-traffic-analysis.net/
6. https://www.winitor.com/download
7. https://github.com/Seabreg/Regshot
8. https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
9. https://tio.run/#
10. https://ericzimmerman.github.io/#!index.md

#learning
#ctf
#tryhackme

@securednation
๐Ÿ”ฅ4โค2
Forwarded from Geez Security
#Launching ๐Ÿš€

Today marks a new chapter. Geez Security๐Ÿง‘โ€๐Ÿ’ป is officially launched to strengthen cybersecurity across Ethiopia.

As digital transformation grows, so do cyber threats. Weโ€™re here to help organizations stay secure, resilient, and prepared.

Our Services:
โœ”๏ธWeb,Mobile & API Penetration Testing
โœ”๏ธRed Team Engagement
โœ”๏ธCyber Incident Response
& More...

๐Ÿ“ Cybersecurity Consulting & Training
โ„น๏ธ geezsecurity.com

#GeezSecurity #CyberSecurityEthiopia #DigitalSecurity2030 @geezsecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ4โค1
Forwarded from AfroSec
๐Ÿฉธ CRTOM โ€” done.

Started my red team cert path with Red Team Operations Management.
Not about popping shells yet โ€” this oneโ€™s about how real ops are planned, scoped, and run.

Foundations first:
๐Ÿง  attacker mindset
๐Ÿ“‹ engagement flow
๐ŸŽฏ operational thinking

@AfroSec
โšก2
Forwarded from The Hacker News
๐Ÿšจ Popular workflow automation platform n8n disclosed a critical flaw that lets authenticated users with workflow edit rights execute OS commands on the host.

Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.

๐Ÿ”— Details here โ†’ https://thehackernews.com/2026/01/new-n8n-vulnerability-99-cvss-lets.html
๐Ÿ”ฅ2
You can't patch people. That's the painful truth in security.
๐Ÿ’ฏ4โค1
Dear TechCrunch, you aren't muck for me. I will try to check out your stories๐Ÿ˜
๐Ÿคฃ3
Forwarded from INSA Cyber Talent Center
๐Ÿ”ด LIVE SESSION TONIGHT ๐Ÿ”ด

Topic: Network Security Basics

โฐ Today | 2:00 LT (Night)
๐Ÿ“ On INSA Cyber Talent Center Channel
@insactc

Join us for an essential live session where we dive into the core of infrastructure defense. Weโ€™ll move beyond the basics to explore how modern networks stay resilient against evolving cyber threats.

โšก๏ธ Session highlights:
- The First Line of Defense: Firewalls, VPNs, and IDS/IPS systems.
- Deep dive into Zero-Trust architecture.
- Defense in Depth: How to layer these tools to create a "hardened" network environment.
- Interactive Q&A: Get your questions answered by experts on this field.

๐Ÿ“ข Happening today at 2:00 LT night. Donโ€™t miss it!


@insactc @cteinsa

#INSA #NetworkSecurity #ZeroTrust #Firewall #CyberSecurity
Forwarded from INSA Cyber Talent Center
แ‹จแŠขแˆ˜แ‹ฐแŠ /INSA แ‹จแ‹ŠแŠญ แŠขแŠ•แ‹ต/weekend แ‹จแ‰ณแˆˆแŠ•แ‰ต แˆแˆ›แ‰ต แ•แˆฎแŒแˆซแˆ แˆแ‹แŒˆแ‰ฃ แ‰ฐแŒ€แˆ˜แˆจ

แ•แˆฎแŒแˆซแˆ™ แ‹จแˆšแˆฐแŒฅแ‰ แ‰ต แ‰€แŠ“แ‰ต - แ‰ แˆณแˆแŠ•แ‰ฑ แˆ˜แŒจแˆจแˆป แ‰…แ‹ณแˆœ แŠฅแŠ“ แŠฅแˆแ‹ต
แ•แˆฎแŒแˆซแˆ™ แ‹จแˆšแˆฐแŒ แ‹‰ - แŠ แ‹ฒแˆต แŠ แ‰ แ‰ฃ แŠขแˆ˜แ‹ฐแŠ  แ‰ณแˆˆแŠ•แ‰ต แˆ›แŠฅแŠจแˆ
แ•แˆฎแŒแˆซแˆ™แŠ• แˆ˜แˆณแ‰ฐแ แ‹จแˆšแ‰ฝแˆ‰
1.แ‰ แˆณแ‹ญแ‰ แˆญ แŠฅแŠ“ แ‰ แˆ˜แˆณแˆฐแˆ‰แ‰ต แ‹˜แˆญแŽแ‰ฝ แ‹˜แˆญแ‰ แˆ‹แ‹ญ แˆแ‹ฉ แ‰ณแˆˆแŠ•แ‰ต แ‹ซแˆ‹แ‰ธแ‹‰ แŠฅแŠ“ แ‹จแˆžแŠซแŠจแˆฏแ‰ธแ‹‰แŠ• แ•แˆฎแŒ€แŠญแ‰ถแ‰ฝ แˆ›แˆณแ‹จแ‰ต แ‹จแˆšแ‰ฝแˆ‰
2.แ‰ฐแ‰‹แˆ™ แ‹จแˆšแ‹ซแ‹˜แŒ‹แŒ€แ‹‰แŠ• แˆแ‰ฐแŠ“/แ‰ปแˆŒแŠ•แŒ… แˆ›แˆˆแ แ‹จแˆšแ‰ฝแˆ‰
3.แ‰…แ‹ณแˆœ แŠฅแŠ“ แŠฅแˆแ‹ต แ‰ฐแˆ˜แˆ‹แˆแˆฐแ‹‰ แˆ˜แˆณแ‰ฐแ แ‹จแˆšแ‰ฝแˆ‰
4.แŠจแŠ แŠ•แ‹ฐแŠ› แ‹ฐแˆจแŒƒ แŒ€แˆแˆฎ แŠฅแˆตแŠจ แ‹ฉแŠ’แ‰จแˆญแˆตแ‰ฒ แ‰ฐแˆ˜แˆซแ‰‚

แˆแ‹แŒˆแ‰ฃแ‹‰ แ‹จแˆšแ‹ฐแˆจแŒแ‰ แ‰ต แ•แˆ‹แ‰ตแŽแˆญแˆ แˆˆแ‹šแˆ แ•แˆฎแŒแˆซแˆ แ‰ฐแ‰ฅแˆŽ แ‰ แ‰ฐแ‹˜แŒ‹แŒ€ แ–แˆญแ‰ณแˆ - https://talent.insa.gov.et 

แ‹จแˆแ‹แŒˆแ‰ฃ แŒŠแ‹œ แŠจแŒฅแˆญ 27 - แ‹จแŠซแ‰ฒแ‰ต 07 แ‹ตแˆจแˆต

แˆตแˆˆแ•แˆฎแŒแˆซแˆ™ แˆ›แ‰ฅแˆซแˆชแ‹ซ แŠจแˆแˆˆแŒ‰ แ‰ แ‰ณแˆˆแŠ•แ‰ต แˆ›แŠฅแŠจแˆ‰ แ‹จแ‰ดแˆŒแŒแˆซแˆ แ‰ปแŠ“แˆ
https://t.me/insactc
https://t.me/cteinsa
แ‰ แˆ˜แŒแ‰ฃแ‰ต แˆ›แŒแŠ˜แ‰ต แ‹จแˆแ‰ตแ‰ฝแˆ‰ แˆ˜แˆ†แŠ‘แŠ• แŠฅแŠ“แˆณแ‹‰แ‰ƒแˆˆแŠ•แข ๐Ÿ“ข INSA Weekend Talent Development Program โ€“ Registration Open

The Information Network Security Administration (INSA) invites talented individuals to apply for its Weekend Talent Development Program in cyber security and related fields.

๐Ÿ—“ Schedule: Saturdays & Sundays
๐Ÿ“ Location: INSA Talent Center, Addis Ababa

Eligible applicants:
โœ”๏ธ Talented individuals with demonstrable projects
โœ”๏ธ Those who pass INSAโ€™s exam/challenge
โœ”๏ธ Primary school students to university graduates
โœ”๏ธ Must be available on weekends

๐Ÿ“ Registration: February 04 โ€“ February 14
๐Ÿ”— Apply at: https://talent.insa.gov.et

โ„น๏ธ More info:
https://t.me/insactc
| https://t.me/cteinsa
Sign up by March 16, 2026 for a chance to win one of 10 Course and Certification Bundles for 90-days access and 1 exam attempt. Winners are chosen at random and notified by email. No purchase required. Exclusions apply.

Sign up here: offs.ec/3Z6p7W0
โค3
Forwarded from INSA Cyber Talent Center
๐Ÿ”ด LIVE SESSION ANNOUNCEMENT
๐Ÿš€ Main Topic: Deployment & Infrastructure Basics
๐Ÿ•‘ Time: 2:00 LT
In this live session, weโ€™ll break down how real applications move from your laptop to production โ€” in a simple, developer-friendly way ๐Ÿ‘ฉ๐Ÿฝโ€๐Ÿ’ปโœจ
๐Ÿ“Œ What youโ€™ll learn:
โœ… Dev vs Production Environments (whatโ€™s really different?)
โœ… Application Deployment Flow (step-by-step)
โœ… Introduction to CI/CD โ€” from a developerโ€™s perspective
โœ… Common mistakes developers make during deployment
Whether youโ€™re a student, junior developer, or self-taught coder, this session will help you understand deployment without fear ๐Ÿ’ก
๐ŸŽฏ Join live, ask questions, and level up your backend & DevOps basics!
๐Ÿ”” Donโ€™t miss it!
Join our
๐Ÿ‘ฅ Our Group and Our Channel
the-right-questions-a-universal-troubleshooting-guide-v8.pdf
55.2 KB
A universal troubleshooting guide. There are lots of things I learned from this one page cheat sheet about how to approach a problem.
Forwarded from INSA Cyber Talent Center
๐Ÿ”ด LIVE SESSION TONIGHT ๐Ÿ”ด

Topic: Penetration Testing (Web Security)

We will cover deep about how to perform web penetration testing security based on the OWASP TOP 10.

โฐ Today | 2:00 LT (Night)
๐Ÿ“ On INSA Cyber Talent Center Channel
@insactc

๐Ÿ“ข The session have 2 classes. Donโ€™t miss it!


@insactc @cteinsa

#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
Forwarded from INSA Cyber Talent Center
๐Ÿ”ด PENETRATION TESTING LIVE SESSION PART 2 WILL CONTINUE TONIGHT ๐Ÿ”ด

We will focus on doing a simulated labs based on the OWASP TOP 10.

โฐ Today | 1:50 LT (Night)
๐Ÿ“ On INSA Cyber Talent Center Channel
@insactc

๐Ÿ“ข Donโ€™t miss it! We will ask you some questions at the end of the session.


@insactc @cteinsa

#LiveStream #CyberSecurity #PenetrationTesting #WebSecurity #OWASP #Talent #INSA
โค2