explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 3 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
building-threat-intelligence-feed-integration
building-threat-intelligence-feed-integration

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Us…

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillperforming-soc2-type2-audit-preparation
    performing-soc2-type2-audit-preparation

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillscanning-docker-images-with-trivy
    scanning-docker-images-with-trivy

    Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-linux-kernel-rootkits
    analyzing-linux-kernel-rootkits

    Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hi…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexecuting-red-team-exercise
    executing-red-team-exercise

    Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing t…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-cloud-forensics-with-aws-cloudtrail
    performing-cloud-forensics-with-aws-cloudtrail

    Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-graphql-security-assessment
    performing-graphql-security-assessment

    Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-velociraptor-for-ir-collection
    implementing-velociraptor-for-ir-collection

    Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-ot-network-traffic-analysis-with-nozomi
    implementing-ot-network-traffic-analysis-with-nozomi

    Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems witho…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-privileged-access-workstation
    implementing-privileged-access-workstation

    Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-business-email-compromise
    detecting-business-email-compromise

    Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-kerberoasting-attack
    performing-kerberoasting-attack

    Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-fileless-malware-techniques
    detecting-fileless-malware-techniques

    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executabl…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-network-segmentation-with-vlans
    configuring-network-segmentation-with-vlans

    Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterpris…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-websocket-api-security
    testing-websocket-api-security

    Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-social-engineering-pretext-call
    conducting-social-engineering-pretext-call

    Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-jwt-none-algorithm-attack
    performing-jwt-none-algorithm-attack

    Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-api-authentication-weaknesses
    testing-api-authentication-weaknesses

    Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and s…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-google-workspace-admin-security
    implementing-google-workspace-admin-security

    Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and externa…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-power-grid-cybersecurity-assessment
    performing-power-grid-cybersecurity-assessment

    This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control ce…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-arp-spoofing-attack-simulation
    performing-arp-spoofing-attack-simulation

    Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection count…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-insecure-data-storage-in-mobile
    exploiting-insecure-data-storage-in-mobile

    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage,…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-lateral-movement-in-network
    detecting-lateral-movement-in-network

    Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers movin…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-yara-rule-development-for-detection
    performing-yara-rule-development-for-detection

    Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-privilege-escalation-assessment
    performing-privilege-escalation-assessment

    Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable service…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-false-positive-reduction-in-siem
    performing-false-positive-reduction-in-siem

    Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-cloud-security-posture-management
    implementing-cloud-security-posture-management

    Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-supply-chain-attacks-in-ci-cd
    detecting-supply-chain-attacks-in-ci-cd

    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub an…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-sql-injection-via-waf-logs
    detecting-sql-injection-via-waf-logs

    Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), t…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-memory-forensics-with-volatility
    conducting-memory-forensics-with-volatility

    Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memor…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-agentless-vulnerability-scanning
    performing-agentless-vulnerability-scanning

    Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-privileged-session-monitoring
    implementing-privileged-session-monitoring

    Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording con…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-rdp-brute-force-attacks
    detecting-rdp-brute-force-attacks

    Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysi…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-spearphishing-simulation-campaign
    conducting-spearphishing-simulation-campaign

    Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-security-monitoring-with-datadog
    implementing-security-monitoring-with-datadog

    Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastruct…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-prototype-pollution-in-javascript
    exploiting-prototype-pollution-in-javascript

    Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-memory-forensics-with-volatility3-plugins
    performing-memory-forensics-with-volatility3-plugins

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-phishing-reporting-button-workflow
    building-phishing-reporting-button-workflow

    Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-ransomware-network-indicators
    analyzing-ransomware-network-indicators

    Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-tls-certificate-transparency-logs
    analyzing-tls-certificate-transparency-logs

    Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation usi…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-template-injection-vulnerabilities
    exploiting-template-injection-vulnerabilities

    Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-blind-ssrf-exploitation
    performing-blind-ssrf-exploitation

    Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ics-asset-discovery-with-claroty
    performing-ics-asset-discovery-with-claroty

    Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system ass…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-azure-with-microsoft-defender
    securing-azure-with-microsoft-defender

    This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillreverse-engineering-dotnet-malware-with-dnspy
    reverse-engineering-dotnet-malware-with-dnspy

    Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RA…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-ipv6-vulnerabilities
    exploiting-ipv6-vulnerabilities

    Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-semgrep-for-custom-sast-rules
    implementing-semgrep-for-custom-sast-rules

    Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-nist-csf-maturity-assessment
    performing-nist-csf-maturity-assessment

    The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recov…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-network-traffic-of-malware
    analyzing-network-traffic-of-malware

    Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Ze…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-bluetooth-security-assessment
    performing-bluetooth-security-assessment

    Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    12345…11
    next →