Giuseppe Toscano
Author

Giuseppe Toscano

28 yo | Ethical Hacker and AI Security Expert

26 articles

Latest

Stop Prompting Blindly: The Practical Guide to Mastering Claude Code
AI 26 min read

Stop Prompting Blindly: The Practical Guide to Mastering Claude Code

Claude Code’s killer features are autonomous code editing, terminal execution, test driven iteration, project memory through `CLAUDE.md`, reusable skills, subagents, hooks, MCP integrations, and seamless workflows across the CLI and VS Code.

HackTheBox - MonitorsFour Writeup
Cybersecurity 8 min read

HackTheBox - MonitorsFour Writeup

Writeup for HTB MonitorsFour — token=0 IDOR leaked MD5 creds, cracked to wonderful1, Cacti RCE via CVE-2025-24367, escaped container via unauthenticated Docker Desktop API (CVE-2025-9074) to read root off the Windows host.

HackTheBox - Interpreter Writeup
Cybersecurity 8 min read

HackTheBox - Interpreter Writeup

Writeup for HTB Interpreter — pre-auth RCE on Mirth Connect 4.4.0 via CVE-2023-43208, pulled DB creds from the config, found an internal root-owned Python service in the channel table, got root via format-string injection in a patient XML field.

HackTheBox - Facts Writeup
Cybersecurity 6 min read

HackTheBox - Facts Writeup

Writeup for HTB Facts machine — registered a user, escalated to admin via CVE-2025-2304, stole MinIO S3 credentials, downloaded an SSH private key from an internal bucket, cracked the passphrase, logged in as trivia, then abused sudo facter to execute arbitrary Ruby as root.

Floci: The Free LocalStack Alternative That Starts in 24ms and It's Better Than What You Lost
Cloud 9 min read

Floci: The Free LocalStack Alternative That Starts in 24ms and It's Better Than What You Lost

LocalStack sunset its free tier in 2026. Floci is the open-source AWS local emulator that filled the gap — 137x faster, MIT-licensed, no auth tokens, and covering services LocalStack never offered for free.

423 Bugs in One Month: How AI Rewrote Firefox Security Forever
Cybersecurity 8 min read

423 Bugs in One Month: How AI Rewrote Firefox Security Forever

In April 2026, Mozilla patched 423 Firefox vulnerabilities — nearly 20× its monthly average. The engine behind it: Anthropic's Claude Mythos Preview, an AI so capable at finding zero-days that Anthropic deemed it too dangerous for public release.

Your Linux Server Has Been Rootable Since 2017 by a 732-Byte Script
Cybersecurity 8 min read

Your Linux Server Has Been Rootable Since 2017 by a 732-Byte Script

Copy Fail (CVE-2026-31431): a 732-byte Python script roots every Linux distro since 2017 through a straight-line kernel crypto flaw. It poisons the page cache to hijack setuid binaries, leaves zero disk traces, and escapes containers. AI-found in 1 hour. 100% reliable. Patch now.

How to Use Claude Code for Free in 2026: Ollama, OpenRouter, and NVIDIA NIM
AI 11 min read

How to Use Claude Code for Free in 2026: Ollama, OpenRouter, and NVIDIA NIM

Paying $100/month for Claude Max just to use Claude Code in your terminal? You don't have to. This guide breaks down every free alternative, from running open-weight models locally on your own machine to tapping NVIDIA's free cloud API, so you can keep the workflow without the bill.

Hyper + Zsh + Powerlevel10k: My 2026 Terminal Stack
OS 6 min read

Hyper + Zsh + Powerlevel10k: My 2026 Terminal Stack

Every tool that makes my terminal faster, smarter, and easier to live in.. packaged into a single install script.

Hacking with Claude: Step-by-step Kali MCP Server Setup for Claude Desktop
Cybersecurity 10 min read

Hacking with Claude: Step-by-step Kali MCP Server Setup for Claude Desktop

What if Claude could run hacking tools for you? This guide shows you how to connect Claude Desktop to a Kali Linux machine and turn a chat interface into a smart AI-powered pentesting companion.

One pip install to Lose Everything: The LiteLLM Supply-Chain Breach
Cybersecurity 10 min read

One pip install to Lose Everything: The LiteLLM Supply-Chain Breach

One pip install was all it took. For three hours on March 24, 2026, malicious versions of LiteLLM sat on PyPI, stealing credentials and backdooring machines. Here's how it happened.

Cloud Hacking: When Clouds Turn Dark
Cybersecurity 7 min read

Cloud Hacking: When Clouds Turn Dark

Millions of companies run on the cloud. Far fewer actually secure it. Here's a look at how attackers get in, from exposed storage buckets to phished employees to misconfigured infrastructure.