Article

Can AI Detect Web Attacks Better Than Rules?
The real challenge is not choosing rules or AI, but designing detection systems that can operate under uncertainty and adversarial pressure. This article examines web attack detection and WAF evasion through scientific research and real-world observations.

SBOM Demystified: A Practical Guide to Software Supply Chain Transparency
Software is built like a layer cake full of libraries, packages, and hidden dependencies. But when a security crisis hits, do you really know what's inside your code? This is where a Software Bill of Materials (SBOM) becomes essential.

Remote Code Execution on SolarView Compact Firmware: A Technical Walkthrough
In this post, we demonstrate how we achieved Remote Code Execution (RCE) on a web server connected to a solar system monitoring firmware: SolarView Compact. This walkthrough covers four key stages: Firmware Extraction, Reconnaissance, Code Review, and Exploitation.

Securing the RAN #1: An Introduction
When people talk about mobile network security, the conversation almost always gravitates toward the core network. However, there is another part of the network that quietly sits in public spaces, exposed by design: the Radio Access Network (RAN).