
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 7 / 14What’s Inside the Box? Shedding Light into Darkness with Malware Analysis
A deep dive into why relying on file hashes is no longer enough and how to safely dissect modern threats using static and dynamic analysis techniques.
Smart Devices, Dumb Mistakes: The Dark Backdoors of the IoT World
Relying on Shodan scans for IoT security is the laziest approach in the industry. Let's talk about the missing 'S' in IoT, why MQTT acts like a gossiping neighbor, and what's actually hiding inside that firmware.
From Streetlights to Server Rooms: The Mystery of the Letter 'S' in IoT Security
Think that smart sensor is harmless? Think again. From UART shells to hardcoded cloud keys, let's look at how IoT devices become the weakest link in your infrastructure.
Cebimizdeki Casuslar: Mobil Güvenliğin Görünmeyen Yüzü ve Tersine Mühendislik Maceraları
Mobil uygulamalarda 'güvenli' sandığımız o alanların aslında ne kadar kırılgan olduğunu, kendi yaptığım hatalardan yola çıkarak anlatıyorum. Tersine mühendislikten SSL pinning'e kadar sahada karşılaştığımız gerçekleri konuşalım.
The Trojan in Our Pockets: The Illusion of 'Security' in Mobile Apps
Mobile security is a different beast altogether. Your code isn't behind a firewall; it's sitting in the attacker's living room. Let's talk about why 'hardcoded' is a dirty word and how SSL Pinning isn't the silver bullet you think it is.
The Day You Exposed Kube-apiserver to the Internet, You Handed Over the Keys to Your Cluster
If you aren't seeing 401 or 403 errors in your logs, you're either not being targeted or you're already compromised. Let's dive into the dirty realities of Kubernetes security and how to harden your cluster.
Zero-Day: The Art of Living with an Unpatchable Nightmare
Facing a vulnerability with no signature, no patch, and no known pattern is a wake-up call for any security pro. Here is a look into the reality of zero-days from the perspective of the Red Team kitchen.
The Dumb Security of Smart Homes: Why Are We Still Living in the 1990s in the IoT World?
Is Shodan really everything? In this piece, we dive into why the IoT ecosystem feels like the Wild West, exploring MQTT vulnerabilities and the 'geeky' reality of firmware analysis from a Red Teamer's perspective.
The Keyless Lock of Invisible Doors: Why 'IDOR' is Just the Tip of the Iceberg in Modern API Security
A deep dive into the shift from monoliths to microservices and how logic flaws like BOLA have become the new frontier for Red Team operations.
When the Foundations Crumble: Software Supply Chain and 'Dependency Hell'
Think you're safe behind your firewall? Think again. The real threat might be that 'npm install' you just ran. Let's dive into the messy world of Software Supply Chain attacks and how they turn your trust against you.
Kubernetes: Orchestration Magic or a Trojan Horse Within?
Is your K8s cluster a secure fortress or just a playground for attackers? Let's dive into API server security, RBAC pitfalls, and why Base64 isn't encryption.
Trusting Your Package Manager? Feeding a Trojan Horse in the Supply Chain
Think your CI/CD pipeline is safe because of a few SCA scans? Think again. We’re diving into the blind spots of package managers, from malicious logic to dependency confusion.