cybersecurity
education
€ EUR
  • $ USD
  • € EUR

Your SQL Server Is Handing Attackers a Map — By Default

Author: Margarita Naumova | Microsoft MVP | MCM SQL Server | Data Engineer | MCT The Starting Point: A Login With Nothing Imagine a login just created on your SQL Server instance (especially the one with a weak password). No database access granted. No roles assigned. No permissions of any kind. Here is what it […]

Cybersecurity Lost Its Natural Language And Why Upskilling Is the Only Way to Bridge the Gap

Author: Paula Januszkiewicz, CEO of CQURE & CQURE Academy, Cybersecurity Expert, MVP & RD, MCT Intro Cybersecurity used to have a relatively shared vocabulary. Firewalls. Antivirus. Patching. Perimeter defense. These concepts once formed a common language understood not only by security teams, but also by IT, leadership, and even non-technical stakeholders. Security discussions were simpler, […]

Two 9.5-Rated “Digital Front Doors”: Why Attackers Are Hammering Citrix NetScaler and Why You Need to Move Now

What happens when the guardian of the network, the security appliance itself gets broken into?  On September 27, 2026, an alert went out that should put every cybersecurity professional on high alert. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urgently added two vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772) to its […]

The Nightmare Is Over: World’s Longest-Running DDoS Service Finally Shut Down 

Have you ever wondered how easy it is to launch an attack that can take down an entire website? The answer is unsettling: all it took was a visit to the right website and a payment in cryptocurrency. NightmareStresser was the perfect example: a digital weapons shop, open to anyone, anonymous, and devastatingly effective.  A […]

CVE-2026-69836 

The vulnerability stems from an unsafe deserialization of untrusted data, a class of flaw where an application reconstructs objects from attacker-supplied input without first validating it.  Because Entra ID is a cloud-hosted service, Microsoft was able to remediate the vulnerability on the server-side, meaning customers did not need to install any patches.   The disclosure itself […]

The Problem of 35,800 Vulnerabilities: Why Your CVSS Score is Lying to You

In the first half of 2026, nearly 36,000 CVEs were published. That’s a 49% jump from the year before. But here’s the twist that should change your entire security strategy: Fewer than 500 were actually exploited in the wild.We have a massive vulnerability problem, but a much smaller action problem. The traditional model of treating […]

Security Is Not About Tools – It’s About Thoughtful Decisions

If you were to describe a typical attack scenario on a company in a few steps – from the initial entry point to full infrastructure takeover – what would it look like? First, let me clarify how attacks themselves should be perceived, because there are fundamental principles we must understand first. In cybersecurity, there is […]

CQURE Hacks #79: Azure Storage Misconfiguration in Practice From Public Blob to Key Vault Access

Starting with a simple inspection of a web application, we uncover an exposed Azure Blob Storage container with anonymous listing enabled. From there, we demonstrate how attackers can enumerate additional containers, discover sensitive internal information, and take advantage of blob versioning to recover deleted credential files. The attack escalates quickly – by retrieving an old […]

CQURE Hacks #84: Understanding Event ID 4624 in Action

Event ID 4624 is one of the most important Windows events for monitoring successful logons. We start by enabling detailed logon auditing on the Domain Controller and then generate several different logon scenarios, including: 1. Workstation unlocks, Logon Type 7 2. Local interactive logons, Type 2 3. Network authentication, Type 3 4. New logon session […]

CQURE Hacks #83: Attack on Active Directory Certificate Services (AD CS) – ESC16

ESC16 occurs when a Certificate Authority is configured not to include the SID security extension in issued certificates. This extension provides a strong binding between a certificate and the Active Directory account for which it was issued. If the extension is absent and the Domain Controller permits weak certificate mapping, certificate identities such as the […]

How can we help you?

Suggested searches

    Search history

      Popular searches:

      Not sure what course to look for?

      Mobile Newsletter Form