Cybersecurity Research & Knowledge Hub

A curated collection of top-tier blogs, frameworks, and community discussions.

World-Class Cybersecurity Blogs

KrebsOnSecurity logo

KrebsOnSecurity

Investigative Journalism

In-depth security news and investigation by Brian Krebs.

The Hacker News logo

The Hacker News

News

Trusted source for cybersecurity news, vulnerabilities, and events.

BleepingComputer logo

BleepingComputer

News & Support

Tech news, security threat updates, and support forums.

Exploit Database logo

Exploit Database

Vulnerability Research

Archive of publicly available exploits and vulnerable software.

Dark Reading logo

Dark Reading

News & Analysis

News and commentary on IT security, helping professionals manage risk.

CISA logo

CISA

Government Agency

Cybersecurity & Infrastructure Security Agency - US official alerts and guidance.

Daniel Miessler Blog logo

Daniel Miessler Blog

Expert Blog

Essays on security, technology, and society by Daniel Miessler.

Null Byte logo

Null Byte

Tutorials & How-Tos

Hands-on hacking tutorials, guides, and news for ethical hackers.

🛡️ OWASP Top 10 - 2021

The OWASP Top 10 is a standard awareness document for developers and web application security, representing a broad consensus about the most critical security risks.Learn more

A01:2021: Broken Access Control

Restrictions on what authenticated users are allowed to do are often not properly enforced.

Web
API
Critical

A02:2021: Cryptographic Failures

Failures related to cryptography (or lack thereof) which can lead to sensitive data exposure.

Data
Critical

A03:2021: Injection

Untrusted data is sent to an interpreter as part of a command or query, leading to unintended commands or data access.

Web
API
Critical

A04:2021: Insecure Design

Flaws in design and architecture, missing or ineffective control design.

Architecture
Important

A05:2021: Security Misconfiguration

Missing appropriate security hardening across any part of the application stack.

Config
Web
API

A06:2021: Vulnerable and Outdated Components

Using components with known vulnerabilities that undermine application defenses.

Software
Dependencies

A07:2021: Identification and Authentication Failures

Incorrectly implemented functions related to user identity, authentication, or session management.

Auth
Critical

A08:2021: Software and Data Integrity Failures

Failures relating to software updates, critical data, and CI/CD pipelines without verifying integrity.

DevOps
Data

A09:2021: Security Logging and Monitoring Failures

Insufficient logging, monitoring, or incident response.

Operations
Detection

A10:2021: Server-Side Request Forgery (SSRF)

Web applications fetching a remote resource without validating the user-supplied URL.

Web
API
Critical

Research & Framework Hubs

MITRE ATT&CK® logo

MITRE ATT&CK®

Framework

A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.

NIST Cybersecurity Framework logo

NIST Cybersecurity Framework

Framework

Voluntary guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk.

CIS Benchmarks logo

CIS Benchmarks

Standards

Consensus-based configuration guidelines for various technology groups to safeguard systems against today's evolving cyber threats.

OWASP Cheat Sheet Series logo

OWASP Cheat Sheet Series

Guidance

A collection of concise cheat sheets on specific application security topics.

Join the Community: Top Discord Servers

TryHackMe Official Discord

Platform Community

The official Discord server for TryHackMe users.

Hack The Box Discord

Platform Community

Connect with the Hack The Box community.

The Cyber Mentor Community

Influencer Community

Heath Adams' (The Cyber Mentor) community server.

InfoSec Prep

General InfoSec

A general server for InfoSec discussions and preparation.

John Hammond's Discord

Influencer Community

Community server for John Hammond's followers.

TCM Security Discord

Training Provider

Official Discord for TCM Security and its courses.

Blue Team Village

Blue Team

A community focused on blue team skills and defense.

Community-Powered News Feeds

r/netsec

Community discussions and news from Reddit.

View Feed
Community Feed

r/cybersecurity

Community discussions and news from Reddit.

View Feed
Community Feed

r/netsecstudents

Community discussions and news from Reddit.

View Feed
Community Feed