CyberForce is a blog where we break down networks, attacks and defense in a way that actually makes sense — from TCP/IP fundamentals to practical protection against everyday threats.
From network fundamentals and routing protocols, through the most common cyberattacks and modern security architecture (SASE, ZTNA, CASB, DLP, EDR/XDR, SIEM), to the history of the internet and the artificial intelligence that's now reshaping how attacks and defense happen too.
A complete guide to the TCP/IP layer model — from MAC addresses and ARP through IPv4 addressing and routing, to the TCP handshake, ports, and the security risks baked into the protocol's design.
Read articleThe link-state principle, Dijkstra's algorithm, neighbor states, DR/BDR election, LSA types, and the area hierarchy around Area 0 — with a custom diagram.
Read articleAutonomous systems, the path-vector principle, eBGP vs iBGP, attributes and the decision process — including BGP hijacking and RPKI as a defense.
Read articleThe Bellman-Ford algorithm, the count-to-infinity problem, split horizon, and the differences between RIPv1, RIPv2 and RIPng.
Read articlePhishing, ransomware, DDoS, MITM, SQL injection, brute-force, and supply chain attacks — an overview of 2026's most common threats and concrete steps that reduce your risk.
Read articleExploiting the TCP/IP handshake, amplification and reflection, SYN cookies, BGP Flowspec, and Anycast — plus a review of techniques used by leading anti-DDoS vendors (Cloudflare, Akamai, AWS, Google, NETSCOUT, Radware).
Read articleWhy SASE emerged, how it combines SD-WAN, SWG, FWaaS, CASB and ZTNA into a single cloud service, and its benefits and limits — with a custom diagram.
Read articleHow ZTNA differs from a traditional VPN, least-privilege access at the application level, and continuous verification instead of a one-time login.
Read articleGartner's four pillars, API vs proxy deployment, shadow IT, and how a CASB protects data inside corporate SaaS applications.
Read articleNetwork, endpoint, and cloud DLP, how a system recognizes sensitive data, and what actions it takes when it catches an attempted leak.
Read articleHow EDR and XDR work, how they differ from antivirus and from each other, and how they fit alongside SIEM and SOAR in modern security architecture.
Read articleSIEM architecture, key features, and an in-depth look at open source options — Wazuh, Security Onion, Graylog, OpenSearch, Elastic Security, and TheHive/Cortex/MISP.
Read articleFrom the Turing test and the Dartmouth conference through two AI winters, expert systems and the deep learning revolution, to large language models and agentic AI — and what it means for cybersecurity.
Read articleTokenization, embeddings, self-attention and the Transformer architecture, training and RLHF, text generation, hallucinations, and security risks like prompt injection — LLMs from the ground up.
Read articlePacket switching, ARPANET's first four nodes in 1969, TCP/IP, DNS and the World Wide Web, through the dot-com era, the mobile internet, and the first internet worm — with custom diagrams.
Read articleFrom the Morris Worm to Kevin Mitnick to LulzSec and state-sponsored attackers — the stories that explain why modern cybersecurity looks exactly the way it does.
Read article