
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 10 / 14Trojan Horses in Our Pockets: Mobile App Security Blunders We Swear We'd Never Make
From mistaking public API keys for crown jewels to the 'allowBackup' trap, let's dive into some common mobile security pitfalls I've seen in the field—and how to avoid them.
Human Vulnerability or System Failure? The Dirty Lab of Social Engineering
Forget those generic 'click for a pay raise' phishing simulations. Let's talk about how real-world social engineering works, the art of pretexting, and the silent dance of fileless payloads.
From Smart Bulbs to Corporate Networks: The 'Default' Disaster in IoT Security
Think that smart coffee machine in the breakroom is harmless? Think again. Let's dive into how 'default' settings and lazy engineering turn IoT devices into a Red Teamer's favorite entry point.
The Trojan in Our Pockets: The Unseen Side of Mobile Security and the 'Safe' Pitfalls
Mobile security is more than just FaceID. From hardcoded secrets in APKs to sensitive data leaking in SharedPreferences, let's dive into the defensive side of mobile app development through the eyes of a Red Teamer.
When the PLC Heartbeat Stops: Red Teaming Industrial Systems and the Harsh Reality
In the world of ICS/OT, a single hex code can be the difference between a smooth operation and physical disaster. Here's why security in the field is a completely different ballgame.
Could Your Smart Bulb Be Watching You? The 'Shodan' Illusion and Bitter Truths in IoT Security
IoT security is more than just scanning Shodan. Let's dive into the world of 'Embedded Insecurity,' firmware analysis, and why your office coffee machine might be your biggest vulnerability.
You’ve Got a Shell, Now What? Navigating the Labyrinths of Internal Networks Silently
Initial access is just the beginning. The real game starts with staying under the radar, moving laterally, and understanding the defensive gaps that let attackers roam free.
Vulnerabilities in the Human OS: More Than Just Taking the Bait
In the cyber world, we pour millions into firewalls and EDRs, but the 'Human OS' remains the most critical patch. From a Red Teamer's perspective, social engineering is less about simple trickery and more about meticulous technical infrastructure.
The Shadow of the Ghost: Is Anyone Truly Safe in a Zero-Day World?
Dive into the world of Zero-Day vulnerabilities from a Red Team perspective. We explore how these invisible threats are born and why understanding the 'logic of the break-in' is the best defense.
Unlocking Invisible Doors: IDOR and the Silent Guests at API Backdoors
Ever seen someone else's invoice just by changing a number in the URL? That's IDOR. Let’s look at why this 'old but gold' vulnerability still haunts modern APIs and how we can secure our systems.
Smart Bulbs, Dumb Passwords: The IoT Backdoor Reality
A deep dive into why IoT devices remain the ultimate 'pivot points' for attackers and how a $20 smart plug can compromise an entire corporate network.
Security Beyond Borders: Anatomy of SASE Architecture and Modern Defense
The traditional 'castle and moat' approach is dead. Discover why SASE is the new frontier of security and how Zero Trust is reshaping our defense strategies from a Red Team perspective.