
It's always nice to share useful information with the community. We asked our employees to recommend resources they personally visit to stay updated on developments in the world of cybersecurity. The selection turned out to be extensive, so we had to split it into two parts. Here is the first part.
- β a technical blog of a large cybersecurity company that regularly publishes its research, tools/plugins for Burp.
- β a security researcher and founder of the top CTF team Dragon Sector.
- β tweets about hacking and hardware.
- β an SDR developer and RF and IoT security researcher, tweets/retweets about hardware hacking.
- β about Active Directory and Windows security.
- β mainly writes about hardware, retweets posts on various cybersecurity topics.
Telegram
- β cybersecurity from the perspective of RedTeam. A lot of quality material dedicated to attacks on Active Directory.
- β a typical channel about web bugs for web bug enthusiasts. It often emphasizes dissecting exploitation methods of common vulnerabilities and advice on effective software use, along with lesser-known but useful features.
- β a channel about technology and cybersecurity.
- β a digest of data leaks.
- β a channel about system administration. Not strictly cybersecurity, but useful.
- β the linkmeup podcast channel, where enthusiasts have discussed networks, technology, and cybersecurity since 2011. We also recommend checking out .
- β posts about hacking and security in an accessible language (perfect for beginners).
- β a digest of useful materials mainly on RE, exploit development, and malware analysis.
Github repository
- β notes on Kubernetes security.
- β a set of video tutorials on web security, vulnerability analysis, and practical exercises.
- β a collection of repositories on themes for hackers, pentesters, and security researchers. We need to go deeper.
Blogs
- β usually does not need an introduction, but if you haven't heard of them: it's a team of cool specialists who search for vulnerabilities like "remote jailbreak for top iOS without user interaction", not for money, but for the sake of public safety.
- β the blog of the developers of the Burp Suite tool, which has become the de facto standard for web security. It is dedicated, of course, to web application security.
- β has written many useful tools/scripts for auditing, besides the blog, they actively share knowledge in their podcasts.
- β a digest of videos and articles on pentesting is published here every week.
Youtube
Bloggers
- β video walkthroughs, including from the well-known Gynvael Coldwind of the Google security team and founder of the top CTF team Dragon Sector, where he shares many interesting insights about reverse engineering, programming, solving CTF tasks, and code auditing.
- β a channel with very high-quality content β explaining cool exploitation methods in simple terms. There are also analyses of interesting Bug Bounty reports.
- β a channel focused on Bug Bounty, valuable advice and interviews with top bug hunters from HackerOne.
- β walkthroughs of machines on Hack the Box.
- β a company specializing in auditing Windows infrastructure. There are many useful videos on various aspects of Windows systems.
Conferences
Academic Conferences
Industry Conferences
Systematization of Knowledge (SoK)
This type of academic work can be very useful at the very beginning of delving into a new topic or when systematizing information. It's not hard to find such works, here are a few examples:
We hope you found something new. In the next part, we will suggest what to read if you are interested in topics like formula satisfiability in theories and machine learning in security, and we will also recommend whose talks on iOS jailbreaking would be useful.
We would be glad if you share your findings or personal blog in the comments.
Source: habr.com
