DevSecOps can take development to new heightsMy guest post on Kode24: how folding security into DevOps lets developers ship fast and safely, from defensive coding and reusable libraries to behavioural monitoring.
Hacker techniques developers should know in 2022My Kode24 guest post walking developers through four attack classes worth understanding: SQL injection, XXE, XSS, and SSRF, with the defensive takeaway for each.
Smart house attack vectorsBeyond WPA2 and a firewall: WPS, pre-compromised LAN hosts, evil-maid USB attacks, weak ISP routers, leaked credentials, and sub-GHz radio protocols.
XSS explainedThe three ways to deliver a Cross-Site Scripting payload, the attack vectors that make it dangerous, and a short history of XSS in the wild.