Skip to content
Sedat Özdemir

Posts on devsecops

41 posts on devsecops. Notes from public sources and my own test lab.

Kubernetes: Orchestration Magic or a Trojan Horse Within?

Is your K8s cluster a secure fortress or just a playground for attackers? Let's dive into API server security, RBAC pitfalls, and why Base64 isn't encryption.

May 3, 2026·4 dk readcontainer-securitydevsecopsk8s-security

Trusting Your Package Manager? Feeding a Trojan Horse in the Supply Chain

Think your CI/CD pipeline is safe because of a few SCA scans? Think again. We’re diving into the blind spots of package managers, from malicious logic to dependency confusion.

May 2, 2026·4 dk readappsecdependency-confusiondevsecops

Is the Ship Sinking? Lost Security Between Container Layers and Lessons from the Field

Let’s debunk the myth that containers are inherently secure. From root user illusions to supply chain risks, I’m diving into why your 'isolated' environments might be more vulnerable than you think.

May 1, 2026·4 dk readcontainer-securitydevsecopsdocker

Loosening the Prison Bars: Docker Escape and the Art of Defense

A deep dive into why privileged containers are a Red Teamer's dream, how to spot escape routes like the Docker socket, and the right way to harden your containerized infrastructure.

April 29, 2026·4 dk readcontainer-securitydevsecopsdocker-escape

The Illusion of Container Isolation: Owning the Host via docker.sock

Think your containers are securely isolated? Think again. From exposed Docker sockets to unnecessary privileges, let's talk about how misconfigurations turn your secure containers into host-level backdoors.

April 13, 2026·3 dk readcontainer-securitydevsecopsdocker

Whose Shoulders Are You Standing On? The Supply Chain Nightmare

You trust your code, but do you trust your dependencies? A deep dive into why shifting left also means looking at the libraries you invite into your house.

April 6, 2026·4 dk readcybersecuritydependency-securitydevsecops

Unlocking Invisible Doors: IDOR and the Silent Guests at API Backdoors

Ever seen someone else's invoice just by changing a number in the URL? That's IDOR. Let’s look at why this 'old but gold' vulnerability still haunts modern APIs and how we can secure our systems.

March 27, 2026·4 dk readapi-securitydevsecopsidor

When Your Safety Net Becomes a Trap: How Library Dependencies Betray You

Ever wonder who actually wrote the 100,000 lines of code running in your 'small' microservice? Let's talk about the fragility of the software supply chain and how Red Teamers exploit it.

March 21, 2026·3 dk readcybersecuritydependency-confusiondevsecops

Is Container Isolation a Lie? That Thin Line Between Docker Socket and Host

If you think your containers are bulletproof shells, think again. From Docker socket abuse to risky capabilities, let's talk about how that 'sandbox' can vanish in seconds and how to actually secure it.

March 19, 2026·4 dk readcontainer-securitydevsecopsdocker

Small Box, Big Trouble: Let’s Stop Romanticizing Alpine Linux

Think a 5MB container image makes you unhackable? Think again. We're diving into the myths of Alpine Linux and why your container's 'diet' might be making life easier for Red Teams.

March 17, 2026·4 dk readcontainersecuritydevsecopsdocker

Armored Vehicle or Glass Jar? The Illusion of Container Isolation

Think your containers are bulletproof? Think again. Let’s dive into why shared kernels and privileged flags are a Red Teamer’s dream and how you can actually lock things down.

March 16, 2026·4 dk readcontainer-securitydevsecopsdocker

Claude Code Terminale İndi: Kodun İçindeki Açıkları Bulmak Artık Çocuk Oyuncağı mı?

Claude Code duyuruldu ve işler iyice kızıştı. Peki bu yeni AI aracı gerçekten güvenlik açıklarını yakalayabiliyor mu yoksa sadece gürültü mü yapıyor?

February 23, 2026·4 dk readai-securityanthropicdevsecops