Guides & Analysis
Evergreen technical guides and deep-dive analysis for IT security practitioners.
GitHub Actions Supply Chain Attack: tj-actions/changed-files Backdoored to Steal Secrets
The widely-used tj-actions/changed-files GitHub Action was compromised in a supply chain attack, executing malicious code that printed CI/CD secrets to workflow logs in hundreds of repositories.
Pinning Actions by SHA is now mandatory security practice — mutable tags like @v45 are a supply chain liability in every pipeline.
NTLM Relay Attacks: A Complete Sysadmin Guide to Detection and Prevention
NTLM relay remains one of the most effective lateral movement techniques in Active Directory environments. This guide explains how it works and exactly what to configure to stop it.
Default Active Directory configurations are vulnerable to NTLM relay — most environments can eliminate this risk with three Group Policy changes.
Scattered Spider's Social Engineering Playbook: How They Bypass MFA and Help Desks
Scattered Spider (UNC3944) continues to compromise Fortune 500 companies by impersonating employees to IT help desks and exploiting SIM swapping — even after MGM and Caesars breaches drew federal attention.
Your help desk might be your biggest attack surface — a single social engineering call can bypass millions of dollars of security tooling.