explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 7 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
performing-cryptographic-audit-of-application
performing-cryptographic-audit-of-application

A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillimplementing-network-deception-with-honeypots
    implementing-network-deception-with-honeypots

    Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillinvestigating-phishing-email-incident
    investigating-phishing-email-incident

    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, a…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-taxii-server-with-opentaxii
    implementing-taxii-server-with-opentaxii

    Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-web-application-penetration-test
    performing-web-application-penetration-test

    Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session manageme…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-authenticated-scan-with-openvas
    performing-authenticated-scan-with-openvas

    Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-aws-cloudtrail-anomalies
    detecting-aws-cloudtrail-anomalies

    Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-hardware-security-module-integration
    performing-hardware-security-module-integration

    Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-deepfake-audio-in-vishing-attacks
    detecting-deepfake-audio-in-vishing-attacks

    Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-android-intents-for-vulnerabilities
    testing-android-intents-for-vulnerabilities

    Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leak…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-wireless-network-penetration-test
    conducting-wireless-network-penetration-test

    Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rog…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-idor-vulnerabilities
    exploiting-idor-vulnerabilities

    Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-mobile-application-management
    implementing-mobile-application-management

    Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, an…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-container-registry-images
    securing-container-registry-images

    Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that p…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-api-security-testing-with-postman
    performing-api-security-testing-with-postman

    Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure.…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillmapping-mitre-attack-techniques
    mapping-mitre-attack-techniques

    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based co…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-web-application-scanning-with-nikto
    performing-web-application-scanning-with-nikto

    Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-for-xss-vulnerabilities
    testing-for-xss-vulnerabilities

    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and use…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-indicator-lifecycle-management
    performing-indicator-lifecycle-management

    Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillscanning-container-images-with-grype
    scanning-container-images-with-grype

    Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-firmware-extraction-with-binwalk
    performing-firmware-extraction-with-binwalk

    Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypte…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-mobile-app-penetration-test
    conducting-mobile-app-penetration-test

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authenticatio…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-clickjacking-attack-test
    performing-clickjacking-attack-test

    Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-malware-incident-response
    conducting-malware-incident-response

    Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detecti…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillextracting-memory-artifacts-with-rekall
    extracting-memory-artifacts-with-rekall

    Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ssrf-vulnerability-exploitation
    performing-ssrf-vulnerability-exploitation

    Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillscanning-infrastructure-with-nessus
    scanning-infrastructure-with-nessus

    Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-ddos-mitigation-with-cloudflare
    implementing-ddos-mitigation-with-cloudflare

    Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-trust-network-access-with-zscaler
    implementing-zero-trust-network-access-with-zscaler

    Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-csrf-attack-simulation
    performing-csrf-attack-simulation

    Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-data-staging-before-exfiltration
    hunting-for-data-staging-before-exfiltration

    Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-trust-with-beyondcorp
    implementing-zero-trust-with-beyondcorp

    Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based a…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-container-image-hardening
    performing-container-image-hardening

    This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-usb-device-control-policy
    implementing-usb-device-control-policy

    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Pol…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-ldap-security-hardening
    configuring-ldap-security-hardening

    Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-threat-intelligence-platform
    building-threat-intelligence-platform

    Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-azure-activity-logs-for-threats
    analyzing-azure-activity-logs-for-threats

    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for th…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-certificate-transparency-for-phishing
    analyzing-certificate-transparency-for-phishing

    Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-dcsync-attacks
    hunting-for-dcsync-attacks

    Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-s3-data-exfiltration-attempts
    detecting-s3-data-exfiltration-attempts

    Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillextracting-credentials-from-memory-dump
    extracting-credentials-from-memory-dump

    Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-race-condition-vulnerabilities
    exploiting-race-condition-vulnerabilities

    Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-ethereum-smart-contract-vulnerabilities
    analyzing-ethereum-smart-contract-vulnerabilities

    Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-image-provenance-verification-with-cosign
    implementing-image-provenance-verification-with-cosign

    Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-timeline-reconstruction-with-plaso
    performing-timeline-reconstruction-with-plaso

    Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-application-whitelisting-with-applocker
    implementing-application-whitelisting-with-applocker

    Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing applicati…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-network-segmentation-for-ot
    implementing-network-segmentation-for-ot

    This skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentatio…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-cloud-dlp-for-data-protection
    implementing-cloud-dlp-for-data-protection

    Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipeli…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-sqlite-database-forensics
    performing-sqlite-database-forensics

    Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-type-juggling-vulnerabilities
    exploiting-type-juggling-vulnerabilities

    Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    1…56789…11
    next →