Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

165 posts · page 2 / 14

Trojan in the Mailbox: Zimbra and the Invisible Leak

A deep dive into why enterprise mail platforms like Zimbra remain a goldmine for attackers and how DevSecOps can mitigate zero-day risks.

July 27, 2026·4 dk readaptdevsecopssiberguvenlik

Midnight Signal: SonicWall and the Broken Perimeters

A 3:14 AM alert, cold coffee, and a flashing dashboard. PulseCom's VPN gateway is acting up. Let's talk about the SonicWall SMA 100 series zero-day.

July 20, 2026·5 dk readcybersecuritydevsecopspentesting

Do Certificates Lie? Ten Thousand Hours at the Terminal

A candid look at why real-world experience, broken home-labs, and protocol knowledge outweigh fancy paper certificates in the world of ethical hacking.

July 17, 2026·3 dk readcareermentorshippersonal

The Shift Left Illusion: Are We Building Security or Just Generating Noise?

Why are remediation times still 200+ days if we're 'shifting left'? A deep dive into the trap of over-relying on automated security tools in CI/CD.

July 15, 2026·3 dk readdevsecopsopinionsecurity-culture

Invisible Danger: The Ghost in the Images and AI Agents

A deep dive into how 'Ghostcommit' turns simple image uploads into sophisticated prompt injection attacks against AI-driven DevSecOps workflows.

July 13, 2026·4 dk readai-securitydevsecopsghostcommit

Driver as a Weapon: How BYOVD Reaches Into the Kernel

BYOVD isn't new — but it's still punching holes through EDRs. Here's what attackers do, and what defenders actually need to fix.

July 10, 2026·3 dk readbyovdkernel-securityransomware

Saatli Bombayı Duymak: Zero-Day Gerçeği ve Savunmanın Görünmez Cephesi

Yazılım dünyasının en büyük kabusu: Sıfırıncı gün. Peki, daha kimsenin bilmediği bir açığa karşı nasıl savunma yapılır? Gelin, bilinmeyenin peşine düşelim.

July 10, 2026·4 dk readexploit-developmentred-teamsavunma

A Stowaway on the Container Ship: Hidden Dangers Behind Images and Safe Harbors

We used to brag about uptime records; now we get suspicious if a container lives longer than five minutes. Let's dive into why 'it’s dockerized' doesn't mean 'it's secure' and how to stop hidden threats in your image layers.

July 8, 2026·3 dk readcontainer-securitydevsecopsdocker

Think Twice Before Opening That File: A Peek into the Kitchen of Malware Analysis

My journey from a 'zombie' computer to a Red Team Lead taught me one thing: malware analysis is as much about discipline as it is about art. Here's how we dissect those suspicious files safely.

July 6, 2026·4 dk readblue-teamcyber-securityincident-response

Seeing Behind the Mask: A Late-Night Shift in the Analysis Lab

Signature-based detection is no longer enough. Let's dive into the 'kitchen' of malware analysis to see how we unmask modern, fileless threats using static and dynamic techniques.

July 5, 2026·3 dk readblue-teamcybersecuritymalware-analysis

Don't Underestimate __proto__: You Might Lose the Whole Kingdom

How a 'sneaky' JSON key turned a 3 AM incident response into a deep dive into Prototype Pollution and its path to Remote Code Execution.

July 4, 2026·3 dk readcybersecuritynodejsprototype-pollution

The Silent Cry of Parameters: Hunting Logic and Architecture in Modern Web Apps

When you multiply the 'amount' parameter in a checkout request by -1 and the server returns a 200 OK, your entire security architecture just became a paper tiger. Let's dive into why logic and architecture hunting is the real frontier of modern security.

July 3, 2026·4 dk readbusiness-logicidorred-teaming