Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

165 posts · page 14 / 14

Leaving the Key in the Lock: Why We’re Still Failing at Identity Management

Million-dollar security is useless if you leave your AWS keys in a script. Let's talk about why IAM is still our weakest link and how to fix it.

February 5, 2026·4 dk readcloud-securityiamidentity-management

The "Root" Illusion in Container Land: How Not to Score an Own Goal

Just because it's in a container doesn't mean it's secure. Let's talk about the common mistakes that turn your isolated box into an open door.

February 5, 2026·4 dk readcloud-securitydevsecopsdocker

Lord of the Leaks: Data Hunting in the Epstein Archives and the Gritty Side of OSINT

Digging through thousands of leaked documents is a nightmare. Here’s how I use OCR and Python to find the signal in the noise.

February 4, 2026·4 dk readdata-analysisdigital-forensicsepstein-docs

Your Screen Isn’t Just Black, Your Heart Just Stopped: The Reality of Ransomware

A raw look at how ransomware actually works, why speed is everything, and what attackers are really doing inside your network before the big "lockdown."

February 4, 2026·5 dk readcybersecurityincident-responsemalware-analysis

Did You Actually Code It or Just Vibe It? The Dark Side of AI-Generated Apps

AI makes coding feel like magic, but that "vibe" can be dangerous. Let's talk about why trusting LLMs too much might break your security.

February 3, 2026·5 dk readiot-securityosint

Hunting Digital Footprints: Why Google is Just the Tip of the Iceberg

Forget basic dorking. Let’s talk about how to find the hidden gaps in a company’s attack surface using subdomains and GitHub leaks.

February 3, 2026·5 dk readcybersecurityinformation-gatheringosint

That 3 AM Phone Call: The Side of Incident Response You Won't Find in Textbooks

Incident response isn't just about technical steps; it's about managing chaos. Here's what really happens when the SOC calls you at midnight.

February 3, 2026·5 dk readblue-teamforensicsincident-response

Moving Fast vs. Playing it Safe: The Dirty Laundry of DevSecOps

Is your speed causing security nightmares? From leaked AWS keys to noisy SAST tools, here is the real deal on making DevSecOps actually work for you.

February 3, 2026·5 dk readapplication-securityci-cd-securitydevsecops

Hunting the Silence: Are You Just Waiting or Actually Looking?

Everything looks green on your dashboard, but is it really? Learn why waiting for alarms is a trap and how to start hunting threats instead.

February 3, 2026·4 dk readblue-teamcyber-defenselog-analysis