Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

165 posts · page 9 / 14

The Human Factor: Bypassing the World’s Strongest Firewall with a Cup of Coffee

While we spend millions on security infrastructure, the biggest vulnerability remains the person behind the screen. Let's talk about how social engineering exploits psychology and why it's a Red Teamer's favorite tool.

April 19, 2026·4 dk readdefensehuman-hackingphishing

A Night in the Lab: Why That File Isn’t Behaving Like You’d Expect

Signature-based detection is a thing of the past. Join me in the lab as we dissect how modern malware hides in memory and how we can unmask these 'ghost' scripts using both static and dynamic analysis.

April 18, 2026·3 dk readcybersecuritydefensemalware-analysis

The Trojan in Our Pocket: Getting Blindsided in Mobile App Security

It's past midnight, your Frida scripts are failing, and the app keeps crashing. Think SSL Pinning is an impenetrable wall? Think again. Let's dive into the 'wild' world of mobile security through the lens of a Red Teamer.

April 17, 2026·3 dk readandroid-pentestfridaios-security

You Can't Patch the Human Factor: The Dirty Lab of Social Engineering

Why most phishing simulations are a waste of time and how real-world social engineering actually works—from the art of OSINT to the psychology of pretexting.

April 16, 2026·4 dk readcybersecuritydefensehuman-hacking

Dumb Passwords of Smart Devices: Firmware Hunting and Shadow Protocols in the IoT World

Ever wondered why billion-dollar IoT infrastructures fail? Let's dive into firmware extraction, hidden backdoors, and the inherent risks of misconfigured MQTT protocols from a Red Teamer's perspective.

April 15, 2026·3 dk readembedded-systemsfirmware-analysisiot-security

Is Your Smart Bulb Handing Over Your House Keys? The Dark Backdoors of IoT

Forget 'admin:admin' hunts on Shodan. Real IoT security threats hide deep within unpatched, messy firmware files and unencrypted protocols. Here's a look at how we analyze these devices during Red Team ops.

April 14, 2026·4 dk readfirmware-analysishardware-hackingiot-security

The Illusion of Container Isolation: Owning the Host via docker.sock

Think your containers are securely isolated? Think again. From exposed Docker sockets to unnecessary privileges, let's talk about how misconfigurations turn your secure containers into host-level backdoors.

April 13, 2026·3 dk readcontainer-securitydevsecopsdocker

Smart Devices or Trojan Horses in Your Home? IoT Security Needs More Than Just Shodan Tourism

Scanning for open IPs on Shodan isn't real IoT security. Join Payten's Red Team Lead, Sedat Özdemir, as he dives into firmware analysis, hardcoded backdoors, and why your smart toaster might be a bigger risk than you think.

April 12, 2026·4 dk readcybersecurityfirmware-analysishardware-hacking

Hitting the 'Reset' Button in the Factory: Why Red Teaming Industrial Systems Gets the Heart Racing

A deep dive into the high-stakes world of Industrial Control Systems (OT) security, featuring a 'learning-the-hard-way' story about how a simple Nmap scan can halt an entire production line.

April 11, 2026·4 dk readicsmodbusot-security

The Silent Betrayal of the Cache: Web Cache Poisoning via Unkeyed Headers

Ever wonder how a performance booster like Varnish or Cloudflare could be turned against your users? Let's dive into the world of unkeyed headers and see how a simple X-Forwarded-Host can lead to a full-scale JavaScript injection.

April 10, 2026·3 dk readcache-poisoningdefensive-securityred-team

The Silent Danger Hidden Between JSON Packets: API Logic Errors and Mass Assignment

In the modern web, the real danger isn't always a complex script; sometimes it's just an extra field in a JSON packet. Let's explore Mass Assignment and how to secure your APIs.

April 9, 2026·4 dk readapi-securitycybersecuritylogic-flaws

Whose Shoulders Are You Standing On? The Supply Chain Nightmare

You trust your code, but do you trust your dependencies? A deep dive into why shifting left also means looking at the libraries you invite into your house.

April 6, 2026·4 dk readcybersecuritydependency-securitydevsecops