Fixitgearware Security’s cover photo
Fixitgearware Security

Fixitgearware Security

Technology, Information and Internet

Lagos, Lagos 398 followers

An organization that offers Cyber Security Services, Information Security training, threat and vulnerability Assessment.

About us

Fixitgearware Security is a cybersecurity company specializing on Cybersecurity Services, trainings, information security, threat and vulnerability assessment, data protection and data recovery, web-application development, promoting news on latest industry security breaches, and cybersecurity awareness.

Website
https://linktr.ee/fixitgearwaresecurity
Industry
Technology, Information and Internet
Company size
2-10 employees
Headquarters
Lagos, Lagos
Type
Privately Held
Founded
2019
Specialties
cybersecurity, Information security, Web-application dev., cybersecurity services, data recovery, threat and vulnerability assement, forensic training, Open Source Intelligence, cybersecurity courses, Data protection, Data backups, Cybersecurity consulting, Cybersecurity news, Penetration testing, Cybersecurity engineer, CRM web-application developement, Laravel framework, Red-teaming, Blue-teaming, and AI cybersecurity tools

Employees at Fixitgearware Security

Locations

Updates

  • The whole noise will be explained in October with consistent video release in series. - Agents (first free video is on the demo of creating the agents file, what they are, and a practical example). - date 04-Oct-26 - MCP (subsequent announcement) - LLM (subsequent announcement) - Automation Testing (subsequent announcement) - Prompt (subsequent announcement) A few demonstration starting with @OpenAI gpt-daybreak-blue-latest aka GPT-5.6 Sol. Token Maxing, caused by not properly aligning the flow of your AGENTS.md (Agents), making your LLM high on cost consumption instead of cutting. C-course plan flow, and why we have to postpone our Cybersecurity course release this year, cos the past decade has been rendered obsolete by the presence of Ai. #FixitgearwareSecurity

  • The Agentic Era Explained: Every LLM, MCP & AI Agent You Need to Know (2026 Edition): 1. In the content published, we discussed about the concept of LLMs, MCP, and AI Agents, how they work in synergy to yield prompt results. 2. More details explaining Run Models, Fine-Tune Models, Small-LLM, and Frontier Models. 3. Why caution should be deeply exercised when cloning agents built by community developers... and more. YouTube-Link: https://lnkd.in/gYXkyjqR #AI #LLM #MCP #AIAgents #Cybersecurity #FixitGearwareSecurity #GPT #Claude #Grok

  • Agents are the new core tool in cybersecurity. The art of cloning random agentic repos should be one avoidable practise to not only prevent system compromise, but also avoiding persistency on your infrastructure & priv* escalation. The need for more caution is that with AI, phishing doesn’t come to you anymore through emails or sms; now you go to phishing through cloning published agents and browser based plugins promising and providing quick task solutions, even from trusted sources. This week, let’s talk about Agentic Ai & understanding its underlying architecture e.g MCP Servers. #FixitgearwareSecurity #Ai #Cybersecurity

  • A Practical Incident Response Model for Home and Enterprise Environments Using AI-Assisted Tools: A strong understanding of operating systems, native utilities, and basic automation can help security teams manage incident response more effectively without depending entirely on expensive enterprise platforms. For home labs, small teams, and cost-conscious organizations, this approach can reduce tool overhead while still supporting structured evidence collection, centralized logging, and effective investigation workflows. The workflow below presents a practical model for carrying out incident response activities across both home and enterprise environments, using professional discipline, native system capabilities, and AI-assisted analysis where appropriate. 1. Build a collector script: When supporting organizations that cannot justify the cost of full enterprise tooling, it is important to rely on disciplined collection methods and a well-designed workflow. A collector script should gather the system data needed for investigation while remaining dependable, repeatable, and easy to deploy. - Schedule the script to run at defined intervals across the organization’s workstations using an appropriate task scheduling method. - Collect relevant artefacts such as running services, DNS cache entries, network connections, event identifiers, recent processes, and autorun data in the background. - Use a format and deployment method that supports reliability, authentication, and manageable error handling within your environment. - In enterprise environments, distribute the collection mechanism through centralized administration tools such as Group Policy or identity and device management platforms. 2. Write output to hostname-based, time-stamped files: Collected logs should be written to time-stamped files so investigators can track activity over time and review anomalies more efficiently. Separating records by host also improves traceability during analysis. Each file should reflect the originating host and collection time. Apply permissions carefully so systems can write logs without giving broad read access, and so incident response personnel can review the evidence without risking accidental modification. - Restrict read access to the incident response team or other specifically authorized groups. - Use permissions that reduce the risk of evidence tampering or unauthorized modification. - Store logs in a separate folder for each hostname or workstation rather than combining all systems into one generic location. Read More Here: https://lnkd.in/gDRS4Vp6 To Install Elasticsearch + Kibana Watch: https://lnkd.in/gGW7gHRj Follow Fixitgearware Security for trusted cybersec. tips, updates, and hands on experience insight. #FixitgearwareSecurity #IncidentResponse #SOCAnalyst101

    • No alternative text description for this image
  • Learning the concept of methodological approach, is the best way to adopt as an offensive expert or professional. Checkout two of our latest publications, on how we solved HTB-LABS, explaining the concepts and steps. Pawning The Redeemer Lab: https://lnkd.in/gg3vjkFb Pawning The Explosion Lab: https://lnkd.in/gMjuNCSa Read More about our upcoming paid course on C-programming: https://lnkd.in/gSqs3TcT #FixitgearwareSecurity #Cybersecurity.

    • No alternative text description for this image
  • The recent rise of unengaging cybersecurity content(s) and poor-quality information(s) underscores the need for strong foundational cybersecurity education. Timelines are increasingly filled with recycled ideas and vague claims that lack substance. AI should help make cybersecurity more engaging, but much of the content instead leans toward entertainment. Although we are hesitant to agree with Anthropic co-founder Dario Amodei, the trend is difficult to ignore: many junior-level roles may disappear within the next few years, leaving senior professionals and experts in greater demand. A quick look at current timelines and recent YouTube content reveals a strong focus on bug bounties and AI-driven hacking content, without fully exploring the depth of the profession cybersecurity. This deep concern and fear that we feel will widen even more, the lack of skillsets in the industry. Hence, a reason why we are intending to gradually integrate Ai contents on our official YouTube channel starting the second week of June, upon dropping our C-programming course, by the end of this month. In addition to these contents, adopting Ai, we also intend to enhance our paid Cybersecurity course and training schedule for this year, to have a touch of Ai on our introductory training and knowledge with regards to the profession. It will be worth it. 😎 IMPORTANT: See Pinned post, for our Timeline for the year 2026. #FixitgearwareSecurity #Cybersecurity #Ai #ArtificialIntelligence Watch Google IO Event 2026 live Stream here: https://lnkd.in/g53RMXQa Checkout various Community Groups here: https://lnkd.in/gTi7HZpm Play Google IO Build Event Game 2026: https://lnkd.in/dX5WuivN

  • Based on our years of experience, it takes at least 10-years to be in a Senior Role of Cybersecurity, and morethan 15-years to be on a professional/executive position. If you are between the age of 19-25, start now. Don’t let anyone fool you. The question you might be asking after reading this, is how do I get started ? 1. Start with Desktop support roles, everything you secure, pentestest, or conduct risk assessment on starts with these. Endpoint devices and infrastructure, are the key components to compromise or expose to vulnerabilities. e.g Computers and Servers. 2. Learn how attackers get an initial foot hold, escalate, and maintain consistency via privileged escalation. Every principle applies even with the advent of Ai (Artificial Intelligence). 3. Never undermine/underestimate Social engineering. Everybody talks, everybody is needy. Learn, how to tweak, for them to expose their deepest desires. 4. Ai makes it easy, having the knowledge on fundamentals makes Ai do your bidding’s. 5. Never stop learning, spend more time on researching, and most importantly fall in-love with the profession, that will be a source of motivation that keeps you going. 💯🫶🏻😎. #FixitgearwareSecurity #Cybersecurity

  • Cybersecurity Influencing is a catastrophe, especially when those influencing the profession have no idea of what they are talking about. Open a post ✉️ on social platforms, and you see contents like this: 1. Learn Cybersecurity by solving “TryHackMe Labs”. 2. Learn Cybersecurity by solving “Port-swigger Academy Labs.” These are the people creating garbage contents that go viral, leading to people learning and still feel empty. Lab solving platforms aren’t Cybersecurity they are a subset of Cybersecurity (A one giant big tree of profession). Depending on the nature of Lab and Solving the Labs, you can say things like: 1. Learn or Begin your Career in Cybersecurity Penetration Testing by solving TryHackMe Labs or HTB Labs, if your content is focused on Red Teaming. 2. Learn or Begin your Career in Cybersecurity Forensic Investigation by solving Blue Team Labs, if your content is focused on Blue Teaming. 3. Learn or Begin your Career in Cybersecurity SOC analyst & SIEM, by solving SIEM based Labs etc. We can go on and on. When an influencer has little or lots of garbage knowledge, they start posting shitty (sorry for the word but has to be said) contents, deceiving naive people who then think cybersecurity is a walk in the park, only to run insane when they don’t have any idea of what they are doing. Cybersecurity comprises of a lot of fields; cloud, network, cryptography, risk governance & data privacy etc. If you don’t know much about the profession, or lack the knowledge, study and stop putting out garbage for people to consume. 😎😅 #FixitgearwareSecurity #Cybersecurity

  • Learning The Fundamentals of Modern Red Teaming: Identifying Security Gaps in AI Systems and Agents: Vulnerability research now extends beyond traditional web penetration testing to include AI systems and agents. As organizations increasingly adopt AI to improve efficiency and support business goals, red teaming is evolving to address these emerging technologies. Below are the key concepts security researchers should understand before assessing AI systems and agents for security weaknesses. 1.     Understand how large language models (LLMs) work and the core concepts behind them. 2.     Study retrieval-augmented generation (RAG) to understand how AI systems can be manipulated into producing hallucinations and false information. 3.     Learn how agentic AI operates and how it integrates with AI service providers, especially where those integrations may introduce risks such as unauthorized access or remote code execution. 4.      Understand how generative AI works, including how direct and indirect prompt injection can lead to data poisoning, backdoor behaviour, and other security risks. 5.      Study prompt engineering and encoded inputs. For example, attackers may use formats such as Morse code to bypass safeguards and trigger unintended actions in AI systems. 6.      Review AI service provider documentation to better understand API key management and how exposed keys can be discovered through third-party agents. 7.      Develop a strong understanding of supply chain risk and attacks, including how trust in third-party vendors can be abused as a path to privilege escalation.   These fundamentals provide a solid foundation for building effective prompts and conducting AI and agent penetration testing. Follow us for more Cybersecurity contents. #FixitgearwareSecurity #Ai #Agents #LLM #OpenAi #OpenClaw #Claude   Important: Beyond these fundamentals, understand the services offered by the organization you are assessing, then apply this knowledge to identify potential vulnerabilities in its systems.

    • No alternative text description for this image