[{"category":"Web Security","date":"Jul 27, 2026","haystack":"waf evasion 101: how attackers bypass “security gates” a breakdown of how waf evasion actually works and why more rules alone can't fix it. covers the core attack techniques, the layered-interpretation gap that makes them possible, and a practical defender's playbook: combining rules with ml and strict validation, rejecting ambiguous requests, testing for evasion resistance, adding rasp, and automating adversarial testing. waf sql-injection xss rasp adversarial-ml owasp-crs security-testing encoding-bypass web security","kind":"post","summary":"A breakdown of how WAF evasion actually works and why more rules alone can't fix it. Covers the core attack techniques, the layered-interpretation gap that makes them possible, and a practical defender's playbook: combining rules with ML and strict validation, rejecting ambiguous requests, testing for evasion resistance, adding RASP, and automating adversarial testing.","tags":["WAF","SQL-injection","XSS","RASP","adversarial-ML","OWASP-CRS","security-testing","encoding-bypass"],"title":"WAF Evasion 101: How Attackers Bypass “Security Gates”","ts":1785110400,"url":"/posts/waf-evasion-101-how-attackers-bypass-security-gates/"},{"category":"AI Security","date":"Jul 12, 2026","haystack":"why high accuracy can still mean bad security ! high accuracy in security research does not guarantee real-world protection. this post examines what accuracy metrics hide, how false positives and false negatives manifest in production, and what a security-grade evaluation framework should actually measure. waf machine learning false positives false negatives buaz payload classification security metrics ai security","kind":"post","summary":"High accuracy in security research does not guarantee real-world protection. This post examines what accuracy metrics hide, how false positives and false negatives manifest in production, and what a security-grade evaluation framework should actually measure.","tags":["WAF","Machine Learning","False Positives","False Negatives","BUAZ","Payload Classification","Security Metrics"],"title":"Why High Accuracy Can Still Mean Bad Security !","ts":1783814400,"url":"/posts/why-high-accuracy-can-still-mean-bad-security/"},{"category":"Web Security","date":"Jul 8, 2026","haystack":"augmenting sr-bh 2020: a technical methodology for modern threat simulation this post walks through a full-scale enhancement of the sr-bh 2020 dataset for waf training and ml-based attack detection. the methodology includes llm-assisted label refinement, diversified benign traffic generation across multiple backend technologies, and targeted attack payload injection using custom burp suite configurations aligned with owasp top 10 classifications. dataset waf owasp top 10 attack detection data curation llm web security","kind":"post","summary":"This post walks through a full-scale enhancement of the SR-BH 2020 dataset for WAF training and ML-based attack detection. The methodology includes LLM-assisted label refinement, diversified benign traffic generation across multiple backend technologies, and targeted attack payload injection using custom Burp Suite configurations aligned with OWASP Top 10 classifications.","tags":["Dataset","WAF","OWASP Top 10","Attack Detection","Data Curation","LLM"],"title":"Augmenting SR-BH 2020: A Technical Methodology for Modern Threat Simulation","ts":1783468800,"url":"/posts/augmenting-sr-bh-2020-a-technical-methodology-for-modern-threat-simulation/"},{"category":"Telecom Security","date":"Jun 16, 2026","haystack":"attacks on the radio interface different attack surfaces, attack vectors, and attack scenarios across the ran are explored. the post highlights the importance of assessing ran security by explaining different categories of threats and attackers' tactics, techniques, and procedures. ran lte mobile networks telecom radio security telecom security","kind":"post","summary":"Different attack surfaces, attack vectors, and attack scenarios across the RAN are explored. The post highlights the importance of assessing RAN security by explaining different categories of threats and attackers' tactics, techniques, and procedures.","tags":["RAN","LTE","Mobile Networks","Telecom","Radio Security"],"title":"Attacks on the Radio Interface","ts":1781568e3,"url":"/posts/ran-attacks/"},{"category":"AI Security","date":"Jun 16, 2026","haystack":"can ai detect web attacks better than rules? neither rule-based detection nor ai-based detection is sufficient on its own. this article examines web attack detection and waf evasion through scientific research and real-world observations, arguing that resilience emerges from integration, not replacement. waf web attacks machine learning evasion detection ai security","kind":"post","summary":"Neither rule-based detection nor AI-based detection is sufficient on its own. This article examines web attack detection and WAF evasion through scientific research and real-world observations, arguing that resilience emerges from integration, not replacement.","tags":["WAF","Web Attacks","Machine Learning","Evasion","Detection"],"title":"Can AI Detect Web Attacks Better Than Rules?","ts":1781568e3,"url":"/posts/can-ai-detect-web-attacks-better-than-rules/"},{"category":"Web Security","date":"Jun 16, 2026","haystack":"cyctf 2023 challenge: a whitebox walkthrough of \"the secret app v1.0\" chaining blind sql injection, captcha bypass, and session misuse to achieve full account takeover in a cyctf 2023 php challenge — with ocr-automated exploitation. ctf sql injection php account takeover captcha bypass web security","kind":"post","summary":"Chaining blind SQL injection, CAPTCHA bypass, and session misuse to achieve full account takeover in a CyCTF 2023 PHP challenge — with OCR-automated exploitation.","tags":["CTF","SQL Injection","PHP","Account Takeover","CAPTCHA Bypass"],"title":"CyCTF 2023 Challenge: A Whitebox Walkthrough of \"The Secret App v1.0\"","ts":1781568e3,"url":"/posts/cyctf-2023-secret-app-walkthrough/"},{"category":"Telecom Security","date":"Jun 16, 2026","haystack":"ran introduction and its criticality the radio access network is the front door of every mobile network — physically exposed, radio-accessible, and historically under-secured. this post introduces the ran and explains why it deserves more security attention. ran lte mobile networks telecom telecom security","kind":"post","summary":"The Radio Access Network is the front door of every mobile network — physically exposed, radio-accessible, and historically under-secured. This post introduces the RAN and explains why it deserves more security attention.","tags":["RAN","LTE","Mobile Networks","Telecom"],"title":"RAN Introduction and its Criticality","ts":1781568e3,"url":"/posts/ran-introduction-and-criticality/"},{"category":"IoT Security","date":"Jun 16, 2026","haystack":"remote code execution on solarview compact firmware: a technical walkthrough a technical walkthrough demonstrating remote code execution on solarview compact firmware through firmware extraction, reconnaissance, code review, and exploitation. rce firmware iot php command injection iot security","kind":"post","summary":"A technical walkthrough demonstrating Remote Code Execution on SolarView Compact firmware through firmware extraction, reconnaissance, code review, and exploitation.","tags":["RCE","Firmware","IoT","PHP","Command Injection"],"title":"Remote Code Execution on SolarView Compact Firmware: A Technical Walkthrough","ts":1781568e3,"url":"/posts/solarview-compact-rce-walkthrough/"},{"category":"Application Security","date":"Jun 16, 2026","haystack":"sbom demystified: a practical guide to software supply chain transparency what a software bill of materials is, why it matters, how to create and use them, and how they're becoming a cornerstone of software supply chain security. sbom supply chain devsecops compliance application security","kind":"post","summary":"What a Software Bill of Materials is, why it matters, how to create and use them, and how they're becoming a cornerstone of software supply chain security.","tags":["SBOM","Supply Chain","DevSecOps","Compliance"],"title":"SBOM Demystified: A Practical Guide to Software Supply Chain Transparency","ts":1781568e3,"url":"/posts/sbom-practical-guide/"},{"cve":"CVE-2025-15517","date":"Mar 23, 2026","haystack":"multiple tp-link routers: authorization bypass in http server cve-2025-15517 archer nx600 cwe-863: incorrect authorization","kind":"advisory","product":"Archer NX600","score":8.6,"severity":"high","summary":"A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.","title":"Multiple TP-Link Routers: Authorization Bypass in HTTP Server","ts":1774224e3,"url":"/advisories/cve-2025-15517/"},{"cve":"CVE-2025-15605","date":"Mar 23, 2026","haystack":"multiple tp-link routers: hardcoded configuration encryption key cve-2025-15605 archer nx600 cwe-321: use of hard-coded cryptographic key","kind":"advisory","product":"Archer NX600","score":8.5,"severity":"high","summary":"A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.","title":"Multiple TP-Link Routers: Hardcoded Configuration Encryption Key","ts":1774224e3,"url":"/advisories/cve-2025-15605/"},{"cve":"CVE-2025-15518","date":"Mar 23, 2026","haystack":"multiple tp-link routers: post authentication command injection in cli controlbf handler cve-2025-15518 archer nx600 cwe-78: improper neutralization of special elements used in an os command ('os command injection')","kind":"advisory","product":"Archer NX600","score":8.5,"severity":"high","summary":"Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.","title":"Multiple TP-Link Routers: Post Authentication Command Injection in CLI controlBF Handler","ts":1774224e3,"url":"/advisories/cve-2025-15518/"},{"cve":"CVE-2025-15519","date":"Mar 23, 2026","haystack":"multiple tp-link routers: post authentication command injection in cli sendatcmd handler cve-2025-15519 archer nx600 cwe-78: improper neutralization of special elements used in an os command ('os command injection')","kind":"advisory","product":"Archer NX600","score":8.5,"severity":"high","summary":"Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.","title":"Multiple TP-Link Routers: Post Authentication Command Injection in CLI sendAtCmd Handler","ts":1774224e3,"url":"/advisories/cve-2025-15519/"},{"haystack":"ahmed maghawry security researcher","kind":"author","role":"Security Researcher","slug":"ahmed-maghawry","summary":"Security Researcher","title":"Ahmed Maghawry","url":"/authors/ahmed-maghawry/"},{"haystack":"omar elebiary senior cyber security researcher","kind":"author","role":"Senior Cyber Security Researcher","slug":"omar-elebiary","summary":"Senior Cyber Security Researcher","title":"Omar Elebiary","url":"/authors/omar-elebiary/"},{"haystack":"heba osama senior research operations specialist","kind":"author","role":"Senior Research Operations Specialist","slug":"heba-osama","summary":"Senior Research Operations Specialist","title":"Heba Osama","url":"/authors/heba-osama/"},{"haystack":"hussein misbah cyber security engineer","kind":"author","role":"Cyber Security Engineer","slug":"hussein-misbah","summary":"Cyber Security Engineer","title":"Hussein Misbah","url":"/authors/hussein-misbah/"},{"haystack":"khaled emad cyber security engineer","kind":"author","role":"Cyber Security Engineer","slug":"khaled-emad","summary":"Cyber Security Engineer","title":"Khaled Emad","url":"/authors/khaled-emad/"},{"haystack":"wessam deif allah telecom security researcher","kind":"author","role":"Telecom Security Researcher","slug":"wessam-deif-allah","summary":"Telecom Security Researcher","title":"Wessam Deif Allah","url":"/authors/wessam-deif-allah/"},{"haystack":"saifeldeen aziz security research technical lead","kind":"author","role":"Security Research Technical Lead","slug":"saifeldeen-aziz","summary":"Security Research Technical Lead","title":"Saifeldeen Aziz","url":"/authors/saifeldeen-aziz/"},{"haystack":"jana elfeky associate research operations specialist","kind":"author","role":"Associate Research Operations Specialist","slug":"jana-elfeky","summary":"Associate Research Operations Specialist","title":"Jana Elfeky","url":"/authors/jana-elfeky/"},{"haystack":"mohamed amgad security r\u0026d lead","kind":"author","role":"Security R\u0026D Lead","slug":"mohamed-amgad","summary":"Security R\u0026D Lead","title":"Mohamed Amgad","url":"/authors/mohamed-amgad/"},{"haystack":"sarah ali research operations specialist","kind":"author","role":"Research Operations Specialist","slug":"sarah-ali","summary":"Research Operations Specialist","title":"Sarah Ali","url":"/authors/sarah-ali/"},{"haystack":"ai security","kind":"category","summary":"2 posts","title":"AI Security","url":"/categories/ai-security/"},{"haystack":"application security","kind":"category","summary":"1 post","title":"Application Security","url":"/categories/application-security/"},{"haystack":"iot security","kind":"category","summary":"1 post","title":"IoT Security","url":"/categories/iot-security/"},{"haystack":"telecom security","kind":"category","summary":"2 posts","title":"Telecom Security","url":"/categories/telecom-security/"},{"haystack":"web security","kind":"category","summary":"3 posts","title":"Web Security","url":"/categories/web-security/"}]