Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

165 posts · page 12 / 14

From Your Neighbor's Smart Bulb to the Corporate Network: The Backdoors of the IoT World

A deep dive into why everything labeled 'smart' is often a Trojan horse, and how we can secure the 'Internet of Troubles' based on real-world Red Teaming experience.

March 12, 2026·4 dk readfirmwarehardware-hackingiot

The Trojan Horse Inside the Fortress: Why Network Segmentation is Always Misunderstood

A deep dive into why 'flat networks' are a Red Teamer's dream and how proper segmentation is more than just VLANs—featuring a cautionary tale from my early days in the field.

February 28, 2026·4 dk readcybersecuritylateral-movementnetwork-security

From Cat and Mouse Games to Collective Intelligence: Why Purple Team?

A deep dive into why breaking the silos between Red and Blue teams is crucial for modern cybersecurity, featuring a technical look at Kerberoasting detection gaps.

February 27, 2026·4 dk readcybersecuritydetectionengineeringinfosec

Dumb Mistakes of Smart Devices: Getting Lost in the IoT Labyrinth

Think your office coffee machine is just for caffeine? Think again. From root passwords like '12345' to open SSH ports, I’m diving into why the IoT world is currently the Wild West of cybersecurity and how these 'toys' can become a bridge to your production database.

February 26, 2026·4 dk readcybersecurityembeddedsystemshardwarehacking

WAF Won't Save You: The Illusion Behind Firewalls and the Harsh Truths

Think your 'premium' WAF makes your web application invincible? Think again. Let's talk about why defense starts in the code, not at the perimeter.

February 25, 2026·3 dk readapplication-securityred-teamsecure-coding

The Regret After Double-Clicking That File: Getting Lost in the Labyrinths of Malware Analysis

A deep dive into the 'wild' path of analyzing malware from a Red Teamer's perspective, starting with a personal 'bridge mode' disaster and moving into static and dynamic analysis techniques.

February 24, 2026·4 dk readcyber-securitydefensemalware-analysis

New Eye in the Terminal: Can Claude Code Actually Spot Security Vulns?

I put Anthropic’s new Claude Code CLI to the test. Here’s how its agentic workflow stacks up against traditional tools in finding real-world bugs.

February 23, 2026·4 dk readai-securityclaude-codered-teaming

Claude Code Terminale İndi: Kodun İçindeki Açıkları Bulmak Artık Çocuk Oyuncağı mı?

Claude Code duyuruldu ve işler iyice kızıştı. Peki bu yeni AI aracı gerçekten güvenlik açıklarını yakalayabiliyor mu yoksa sadece gürültü mü yapıyor?

February 23, 2026·4 dk readai-securityanthropicdevsecops

Claude Code is Here: Hunting Vulnerabilities Directly from Your Terminal

Testing Claude Code from a security perspective—why this new CLI tool is more than just another chatbot for your workflow.

February 23, 2026·5 dk readai-securityanthropicclaude-code

When Valves Turn by Themselves: Inside the Dark Corridors of Industrial Systems

A midnight emergency call, the illusion of a 'perfectly fine' SCADA dashboard while physical machines struggle, and the harsh reality that air-gapped systems are never as secure as we think.

February 23, 2026·4 dk readicsindustrialcybersecuritymodbus

What Happens When You Change Just One Digit? The Silent Scream of IDOR

A deep dive into why authorization flaws like IDOR and business logic errors remain the 'invisible' threats that automated scanners often miss, told through real-world Red Team experience.

February 22, 2026·4 dk readcybersecurityidorred-team

The Art of Pen Testing: A Red Team Journey Beyond Automated Tools

It’s 3:15 AM. That hypnotic terminal glow is burning my eyes, but the real hunt has just begun. Here is why penetration testing is more than just clicking 'Scan' and why manual analysis is the true game changer.

February 21, 2026·4 dk readcyber-securityethical-hackinginfosec