Tag
AppSec
3 posts. See all posts.
Player-Coach: Why I Still Do the Work
I manage a security team and still do pen tests and threat models. Here's why I think more security leaders should, and what it costs.
Where OAuth Goes Wrong in Real APIs: A Step-by-Step Walkthrough
Walking through the OAuth code flow with PKCE step by step, and the validation gaps I keep finding in real APIs at each stage.
The Impact of AI on Software Security
How AI strengthens cybersecurity defenses and empowers attackers at the same time, plus the AI versus ML distinction security professionals need to understand.