Cybersecurity blog

Cybersecurity made clear, and in depth

CyberForce is a blog where we break down networks, attacks and defense in a way that actually makes sense — from TCP/IP fundamentals to practical protection against everyday threats.

Networks & protocols Cyberattacks Defense & hardening Practical, no fluff
Updated daily

Quick news from AI and cybersecurity

All news
Latest articles

From the blog

From network fundamentals and routing protocols, through the most common cyberattacks and modern security architecture (SASE, ZTNA, CASB, DLP, EDR/XDR, SIEM), to the history of the internet and the artificial intelligence that's now reshaping how attacks and defense happen too.

Networking January 14, 2026 · 14 min read

TCP/IP in depth: how network communication actually works

A complete guide to the TCP/IP layer model — from MAC addresses and ARP through IPv4 addressing and routing, to the TCP handshake, ports, and the security risks baked into the protocol's design.

Read article
Networking February 6, 2026 · 18 min read

OSPF in depth: how the link-state routing protocol works

The link-state principle, Dijkstra's algorithm, neighbor states, DR/BDR election, LSA types, and the area hierarchy around Area 0 — with a custom diagram.

Read article
Networking February 25, 2026 · 19 min read

BGP in depth: the protocol holding the internet together

Autonomous systems, the path-vector principle, eBGP vs iBGP, attributes and the decision process — including BGP hijacking and RPKI as a defense.

Read article
Networking March 17, 2026 · 16 min read

RIP in depth: the distance-vector protocol and all its versions

The Bellman-Ford algorithm, the count-to-infinity problem, split horizon, and the differences between RIPv1, RIPv2 and RIPng.

Read article
Attacks April 9, 2026 · 12 min read

The most common cyberattacks and how to defend against them

Phishing, ransomware, DDoS, MITM, SQL injection, brute-force, and supply chain attacks — an overview of 2026's most common threats and concrete steps that reduce your risk.

Read article
Attacks April 18, 2026 · 27 min read

What is DDoS: how the attack works in depth and mitigation techniques

Exploiting the TCP/IP handshake, amplification and reflection, SYN cookies, BGP Flowspec, and Anycast — plus a review of techniques used by leading anti-DDoS vendors (Cloudflare, Akamai, AWS, Google, NETSCOUT, Radware).

Read article
Security architecture April 28, 2026 · 15 min read

What is SASE: converging networking and security in the cloud

Why SASE emerged, how it combines SD-WAN, SWG, FWaaS, CASB and ZTNA into a single cloud service, and its benefits and limits — with a custom diagram.

Read article
Security architecture May 19, 2026 · 14 min read

What is ZTNA: the end of VPN as we know it

How ZTNA differs from a traditional VPN, least-privilege access at the application level, and continuous verification instead of a one-time login.

Read article
Security architecture June 8, 2026 · 13 min read

What is CASB: taking control of cloud applications

Gartner's four pillars, API vs proxy deployment, shadow IT, and how a CASB protects data inside corporate SaaS applications.

Read article
Security architecture June 29, 2026 · 13 min read

What is DLP: preventing sensitive data from leaking out

Network, endpoint, and cloud DLP, how a system recognizes sensitive data, and what actions it takes when it catches an attempted leak.

Read article
Security architecture July 20, 2026 · 19 min read

What is EDR and XDR: threat detection and response in depth

How EDR and XDR work, how they differ from antivirus and from each other, and how they fit alongside SIEM and SOAR in modern security architecture.

Read article
Security architecture July 28, 2026 · 21 min read

What is SIEM: how it works and your open source deployment options

SIEM architecture, key features, and an in-depth look at open source options — Wazuh, Security Onion, Graylog, OpenSearch, Elastic Security, and TheHive/Cortex/MISP.

Read article
History August 4, 2026 · 19 min read

The history of artificial intelligence: from first ideas to today

From the Turing test and the Dartmouth conference through two AI winters, expert systems and the deep learning revolution, to large language models and agentic AI — and what it means for cybersecurity.

Read article
AI in depth August 13, 2026 · 22 min read

What is an LLM and how does it actually work: an in-depth explanation

Tokenization, embeddings, self-attention and the Transformer architecture, training and RLHF, text generation, hallucinations, and security risks like prompt injection — LLMs from the ground up.

Read article
History August 21, 2026 · 20 min read

The history of the internet: from ARPANET to today's global network

Packet switching, ARPANET's first four nodes in 1969, TCP/IP, DNS and the World Wide Web, through the dot-com era, the mobile internet, and the first internet worm — with custom diagrams.

Read article
History August 24, 2026 · 23 min read

The Most Famous Hackers in History: Stories That Shaped Cybersecurity

From the Morris Worm to Kevin Mitnick to LulzSec and state-sponsored attackers — the stories that explain why modern cybersecurity looks exactly the way it does.

Read article