// security practitioner
Find the risk.
Understand it.
Reduce it.
Notes on cybersecurity from someone who does it for a living — vulnerabilities and CVEs, threat intel worth acting on, ISMS and risk, secure architecture, and the occasional bug bounty write-up. Practitioner analysis, not headlines.
// recent writing
- cve CISA's KEV Catalog Just Gave Federal Agencies 72 Hours for Five Critical Flaws 2026-09-16
- cve CVE-2026-85706: GitLab's Commits API Lets Unauthenticated Path Traversal — CISA KEV 2026-09-16
- cloud The Null Entity ID: Why Your SAML IdP Trusts Anyone 2026-09-16
- inventory Your Vulnerability Data Is Only as Good as Your Asset Inventory 2026-09-14
- cve CVE-2026-19490: NetScaler's SAML Action Is Now an Auth Bypass — CISA KEV 2026-09-11
- isms Evidence Decays: Why 'We Do X' Doesn't Survive the Audit 2026-09-09
- cve CVE-2026-55040: SharePoint's JWT Handler Let Anyone Forge a Token — CISA KEV 2026-09-07
- detection Detection Rules That Alert on the Attacker Already Know 2026-09-02
- cve Gitea's diffpatch Flaw Turns a Git Patch Into a Shell — and CISA Says It's Already Being Exploited 2026-08-26
- cve CISA KEV Is a Prioritization Multiplier — Here's How to Use It Properly 2026-08-24
- microsoft-365 Microsoft M365 Is Not Zero-Knowledge — Here's the Evidence (And What Customers Get Wrong) 2026-08-22
- microsoft Storm-0558 Wasn't Microsoft's Worst Security Failure — It Was the Only One 2026-08-22
- cve VMware vCenter Path Traversal Hits KEV — Due Date Is Today 2026-08-21
- risk Risk Treatment Plans That Work (And Why Yours Probably Doesn't) 2026-08-19
- cve Cisco ASA/FTD SSL VPN DoS Is In KEV — 3 Days Past Due 2026-08-17
- cve CISA KEV Catalog: How to Actually Use It (Beyond "Patch the Critical Ones") 2026-08-14
- cve kcp's Unauthenticated Cache Server — When Your Control Plane Leaks Everything 2026-08-12
- vulnerability-management CVSS is Not Priority: A Practical Vulnerability Prioritization Framework 2026-08-10
- cve TeamCity RCE Is In KEV — Due Date Is Today 2026-08-07
- isms 93 Controls, Zero Idealism: ISO 27001 in the Real World 2026-08-05
- cve Cisco FMC Auth Bypass Is In KEV — Here's What Actually Matters 2026-08-03
- architecture Security Debt: Why Architecture Decisions Compound Faster Than Code Debt 2026-07-31
- oauth OAuth 2.0 Access Tokens Actually Mean — What the Spec Says and What It Doesn't 2026-07-29
- cve Three CVSS 10.0 Microsoft CVEs from One Patch Day — And What They Share 2026-07-27
- detection The Three Layers of Logging That Actually Detect Things 2026-07-24
- cve CVE-2026-55454: Appsmith's Caddy Admin API Gets a 9.9 from SSRF 2026-07-22
- isms Configuration Management That Doesn't Rot in Six Months 2026-07-20
- cve CVE-2026-58644: SharePoint Deserialization Hits CISA KEV — 48 Hours to Patch 2026-07-17
- vulnerability-management CVSS, EPSS, KEV — A Prioritization Workflow That Doesn't Lie 2026-07-15
- kubernetes The Invisible Admin: Unauthenticated Endpoints in Kubernetes Infrastructure 2026-07-13
- cve Old CVEs Don't Die, They Get Added to KEV 2026-07-10
- bug-bounty Scope Is the Whole Game 2026-07-06
- bug-bounty A PoC Is a Contract 2026-06-29
- bug-bounty Passive Watchlists Are Not Findings 2026-06-22
- bug-bounty Blocked Is a Result 2026-06-15
- bug-bounty Bug Bounty Needs a Run Loop 2026-06-09
- local-models Same Model, Different Brain: How a ReACT Loop Transformed a 35B Model's Security Skills 2026-03-16
- methodology How I Approach a New Bug Bounty Target 2026-03-11
- bug-bounty When 'Informative' Is the Answer 2026-03-11