Cybersecurity
The ground truth of how traffic moves, the browser protections every site should enable, and the security problems that appear when language models are connected to documents and tools.
Everything here is for defence and for testing systems you own or are authorised to assess.
AI security
Category pagePrompt injection, retrieval poisoning, data leakage and the defensive patterns that reduce them.
Prompt injection in RAG systems and how to reduce it
Prompt injection makes a language model follow attacker-written text. Learn direct and indirect injection in RAG, why filters fail, and layered defences.
Intermediate3 min
Networking
Category pagePackets, ports, protocols and addressing: the ground truth every security skill is built on.
TCP vs UDP: differences, handshakes and when each is used
TCP gives reliable, ordered delivery after a handshake; UDP sends independent datagrams. Compare headers, use cases, ports and how both look in Wireshark.
Beginner3 min
Web security
Category pageHow HTTP, response headers, cookies and sessions work, the browser protections every site should enable, and the common ways web applications fail.
HTTP security headers explained: CSP, HSTS and more
Security headers tell browsers how to protect your users. Learn what CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame-ancestors do.
Beginner3 min