RINP // CYBERSECURITY SERVICES
Blog · broader reading and open sharing
A broader reading spacefor the cybersecurity agenda.
Industry developments, method notes, open-source work, and assessments of security practice come together here.
Readings on cybersecurity
Editorial scope: Conceptual frameworks related to the service appear in the Insight section, while anonymized work examples appear in the Case section. The Blog is devoted to industry reading, method discussion, and open knowledge sharing.
Related-Domain Attacks: The Collapse of Security Assumptions Delegated to the Browser
The cookie, CSP, CORS and framing techniques that chain from control of a single subdomain, with findings verified in a real browser and what they mean internally.
Read Concept and methodM365 Device Code Phishing - From Approval to Enterprise Access
A four-stage chain that advances on the user's own approval with no attacker-owned link: token capture, FOCI spread across 14 services, enterprise data access and a controlled pivot into the network.
Read Concept and methodmacOS Red Team - XPC-Based Persistence and Post-Exploitation
XPC-based persistence that works around BTM's advisory supervision on macOS: an evidence-measured visibility gap, with TCC and Keychain limits.
Read Concept and methodAWS Pentest - What can an identity actually reach in AWS?
An AWS penetration testing playbook that moves from declared permissions to effective decisions: test levels, evidence model, attack chains and rollback.
Read Concept and methodKubernetes Penetration Testing - Do your Kubernetes controls actually block anything?
A Kubernetes penetration testing playbook that moves from seeing a control to proving its decision: dry runs, canary evidence and attack chains.
Read Concept and methodLoad Test - Did your load test actually generate the load?
Sizing, executor choice and result interpretation with k6: no capacity claim before the load generator is proven.
Read// BLOG
From a reading to your organization's security agenda
If a piece aligns with your security priority, we can assess the relevant risk and the appropriate service scope together.