Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

165 posts · page 8 / 14

Is the Ship Sinking? Lost Security Between Container Layers and Lessons from the Field

Let’s debunk the myth that containers are inherently secure. From root user illusions to supply chain risks, I’m diving into why your 'isolated' environments might be more vulnerable than you think.

May 1, 2026·4 dk readcontainer-securitydevsecopsdocker

Ghost in the Terminal: Unconventional Penetration Testing Scenarios and Real-World Defense

A deep dive into the Red Teamer mindset: why your security is only as strong as your forgotten legacy server, moving beyond automated tools to explore RCE via misconfigurations, and the art of lateral movement.

April 30, 2026·4 dk readcybersecuritydefensive-hardeningoffensive-security

Loosening the Prison Bars: Docker Escape and the Art of Defense

A deep dive into why privileged containers are a Red Teamer's dream, how to spot escape routes like the Docker socket, and the right way to harden your containerized infrastructure.

April 29, 2026·4 dk readcontainer-securitydevsecopsdocker-escape

JSON’s Backdoor: The Forgotten 'Logic' and Invisible Threats in API Security

Modern security isn't just about blocking scripts; it's about understanding the logic of your APIs. Let's dive into why WAFs aren't enough when your business logic is broken.

April 28, 2026·3 dk readapi-securitybolacybersecurity

The Silent Killer in the Factory: The Cold Reality of the 'Force Coil' Command in OT Systems

Hacking a server in the IT world leads to data leaks; hacking a system in the OT world leads to physical disasters. Let's dive into the vulnerabilities of Modbus/TCP and why the air-gap myth is dangerous.

April 27, 2026·4 dk readindustrial-securitymodbusot-security

Smart Devices, Dumb Security: IoT Backdoors and Silent Takeovers

From a coffee machine trying to talk to a Domain Controller to hardcoded secrets in firmware, let's dive into the Wild West of IoT security from a Red Teamer's perspective.

April 26, 2026·4 dk readdefensive-securityhardware-hackingiot-security

An Invisible Bullet: Zero-Days and That Fatal Gap in Memory

Zero-Days aren't just Hollywood magic; they are the result of unnoticed logic flaws or memory management slips. Let's dive into the 'Window of Exposure' and how these vulnerabilities actually work under the hood.

April 25, 2026·3 dk readcybersecuritydefense-in-depthexploit

The Only Bug Even the Most Expensive Firewall Can’t Patch: The Human Factor

Ever seen a massive security budget get wiped out by a single 'free coffee' link? Let's dive into why the 'human interface' remains our most critical vulnerability and how we, as Red Teamers, look at psychological triggers.

April 24, 2026·3 dk readcybersecuritydefensephishing

The Browser's Dark Alleys: DOM-Based XSS and the 'It Won't Happen to Me' Delusion

We've spent years hardening our servers, but the battlefield has shifted to the client-side. Let's dive into why your modern SPA might be more vulnerable than you think, focusing on the subtle danger of DOM-based XSS.

April 23, 2026·4 dk readdefensive-securitydom-xssjavascript

The Shadow Creeping Behind the Walls: Anatomy of SSRF and Those 'Innocent' Looking Parameters

A deep dive into Server-Side Request Forgery (SSRF), exploring how 'innocent' URL parameters can lead to full cloud environment compromise, shared from the perspective of a Red Team Lead.

April 22, 2026·3 dk readcloud-securitydefensered-teaming

Stop Playing in the Sandbox: Facing the Realities of Malware Analysis

Relying solely on automated sandboxes is a trap. Let's dive into the real-world mindset of malware analysis, covering entropy, static inspection, and why your automated tools might be lying to you.

April 21, 2026·4 dk readblue-teamdefensive-securitymalware-analysis

We Used to Drop the Report and Run, Now We Live Together Inside: The Evolution of Modern Pentesting

Pentesting is no longer just about scanning for vulnerabilities and handing over a PDF. Modern Red Teaming focuses on the 'Assumed Breach' mindset and testing how well the Blue Team actually detects 'Living off the Land' techniques.

April 20, 2026·4 dk readassumed-breachinfosecpenetration-testing