hackersacademyofficial

hackersacademyofficial We do info-sec training & CTFs

10/01/2026

You reset the password.
You locked the account.
The attacker is still in. šŸ‘€

By default, any user in Microsoft Entra can register an app.

Compromise one account. Create an app. Keep access long after the cleanup.

It doesn’t look like a breach. It looks like just another app.

Part 2 of 2 dangerous Azure defaults. Missed part 1? Check our guest invites video.

Our Azure Security Specialist course covers this and more. One subscription unlocks every course. Link in bio.

09/28/2026

By default, anyone in your Microsoft Entra tenant can invite guests. Even the guests themselves.

Attackers love that.

One compromised user is all it takes. They invite a guest account they control, and now they have a quiet, persistent way back into your environment. Most teams never spot it.

Watch to see how the attack works and the three settings that shut it down.

This is part one of two dangerous Azure defaults. Follow so you don’t miss part two.

Want to go deeper? Our Azure Security Specialist course takes you further. One subscription, monthly or yearly, unlocks every course on the site. Or create a free account and start with the labs. Link in bio.

09/24/2026

Break glass accounts exist for emergencies. Too many are never monitored.

A forgotten admin account with no MFA is not a backup plan. It’s an open door.

How to lock yours down in Azure:

- Phishing-resistant MFA, like a FIDO2 key or certificate
- An alert on every single sign-in
- Not tied to any one person’s phone or device
- Tested regularly, so it works when you need it

Follow for more tips.

Top cybersecurity threats facing UAE organisations right now:1ļøāƒ£ Credential attacks2ļøāƒ£ Supply chain compromise3ļøāƒ£ AI-ass...
09/21/2026

Top cybersecurity threats facing UAE organisations right now:

1ļøāƒ£ Credential attacks
2ļøāƒ£ Supply chain compromise
3ļøāƒ£ AI-assisted phishing
4ļøāƒ£ Unpatched legacy infrastructure

The ones who get breached aren’t unlucky. They’re unprepared.

CISO

09/17/2026

Kerberoasting has been around since Windows Server 2003.

It still works in 2026.

Here’s why: most organizations run service accounts with weak, unrotated passwords.

Attackers don’t need to breach your perimeter. They just request a ticket, crack the hash offline, and walk right in.

No exploit. No zero-day. Just a gap nobody closed.

We break down exactly how it works and what actually stops it. Full video up now.

Want to go deeper? Explore our full course catalog, link in bio.

Homam went from student to cybersecurity specialist at IBM in a few years.This Saturday, he’s telling you the decisions,...
09/15/2026

Homam went from student to cybersecurity specialist at IBM in a few years.

This Saturday, he’s telling you the decisions, the skills, and the mistakes he’d skip if he could do it again.

Free webinar. Real talk, no fluff.

šŸ”— Link in bio to reserve your spot.

09/07/2026

Fine grained password policies sound like a defence. Sometimes they are the gap.

A quick breakdown of how this specific AD feature gets exploited when it’s set up without thinking it through.

Full breakdown in the video. Course link in bio.

The verdict is in.Our Azure Pe*******on Testing course ran live at Black Hat USA 2026, and this is what attendees actual...
09/03/2026

The verdict is in.

Our Azure Pe*******on Testing course ran live at Black Hat USA 2026, and this is what attendees actually said, no filter, no cherry-picking, just real feedback from the room.

Highly technical, still understandable. That’s the balance we aim for every time.

Swipe through.

08/31/2026

Part two. 🚨

The breach path most defenders never see coming.

Lateral movement inside AD is quieter than people think.

It doesn’t trip alarms. It just looks... normal.

Here’s what it actually looks like from the attacker’s side.

Full breakdown in the video. Course link in bio.

08/28/2026

No Metasploit. No zero-day. Full enterprise takeover.

Once an attacker is inside, the real work starts. Enumeration. Native tool abuse. NTLM and Kerberos attacks. On-prem to cloud escalation. None of it needs an exploit. All of it runs on misconfigurations that humans left behind.

That is the gap between knowing the theory and doing the job.

Full breakdown in the video. Course link in bio.

*******onTesting

Address

Las Vegas, NV

Alerts

Be the first to know and let us send you an email when hackersacademyofficial posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The School

Send a message to hackersacademyofficial:

Shortcuts

Featured

Share