Explore the world
of Cybersecurity
- Penetration Test - Vulnerability research
AI-Augmented Penetration Testing: how we use AI agents without sacrificing human judgment
AI is changing many of our activities across different fields, including Offensive Security. AI-Augmented Penetration Testing combines Artificial Intelligence tools with human expertise to analyze broader attack surfaces, conduct more in-depth testing, and accelerate activities without sacrificing the specialist's judgment.
- Vulnerability research
AI, deepfake and the future of cybersecurity
Generative AI, deepfakes, and autonomous agents are revolutionizing cybersecurity, making attacks more convincing and increasingly automated. Organizations must adopt a continuous and integrated security approach, combining AI capabilities with human expertise.
- Vulnerability research
CVE-2026-31717: hijacking SMB in the Linux kernel
This article analyzes CVE-2026-31717 from the protocol internals down to the vulnerable code path, showing how a single missing identity check turns predictable handle identifiers into a practical cross-user file access primitive.
- Penetration Test
Performing NTLM relay attacks against AD CS in ESC8 scenarios by exploiting RBCD
In this article, I analyse an end-to-end attack chain that combines relaying to AD CS, authentication coercion via PetitPotam, and the exploitation of Resource-Based Constrained Delegation (RBCD). I will show you how these techniques can be chained together to impersonate privileged accounts and compromise the Domain Controller, whilst also exploring the role of U2U and S4U in the final stages of the attack.
- Application security
Security by Design: why it is essential in 2026
By 2026, Security by Design will no longer be optional. The data shows a steady rise in vulnerabilities, cyberattacks and data breaches. Taking action ‘after the event’ is no longer enough to protect systems and data, and without a cross-functional approach, any security strategy will be incomplete.
- Direttive UE
DORA regulation and the TLPT testing methodology
The European DORA Regulation marks a turning point for the financial sector, introducing stringent requirements to ensure digital operational resilience and the ability to effectively manage cyber incidents. Among the new features, Delegated Regulation (EU) 2025/1190 defines the technical and methodological standards for the adoption of Threat-Led Penetration Testing (TLPT), reinforcing the structured approach to security testing based on real threats.
- Direttive UE
NIS2 and 2026 deadlines: why offensive security has become a strategic requirement
2026 marks a turning point for the NIS2 Directive: from this year onwards, operational obligations, regulatory oversight and the first assessments of organisations’ actual security levels will come into full effect. Offensive Security is the key tool for demonstrating compliance and resilience.
- Case Study
Physical Red Teaming: Betrusted it is not only digital, but also physical
In this case study, we will tell you how we organised Physical Red Teaming activities at the ACME company buildings located in the centre of Clerville.
Discover how we can help you
Together, we’ll find the best solutions to tackle the challenges your business faces every day.