// security practitioner
Find the risk.
Understand it.
Reduce it.
Notes on cybersecurity from someone who does it for a living — vulnerabilities and CVEs, threat intel worth acting on, ISMS and risk, secure architecture, and the occasional bug bounty write-up. Practitioner analysis, not headlines.
// recent writing
- cve Cisco FMC Auth Bypass Is In KEV — Here's What Actually Matters 2026-08-03
- architecture Security Debt: Why Architecture Decisions Compound Faster Than Code Debt 2026-07-31
- oauth OAuth 2.0 Access Tokens Actually Mean — What the Spec Says and What It Doesn't 2026-07-29
- cve Three CVSS 10.0 Microsoft CVEs from One Patch Day — And What They Share 2026-07-27
- detection The Three Layers of Logging That Actually Detect Things 2026-07-24
- cve CVE-2026-55454: Appsmith's Caddy Admin API Gets a 9.9 from SSRF 2026-07-22
- isms Configuration Management That Doesn't Rot in Six Months 2026-07-20
- cve CVE-2026-58644: SharePoint Deserialization Hits CISA KEV — 48 Hours to Patch 2026-07-17
- vulnerability-management CVSS, EPSS, KEV — A Prioritization Workflow That Doesn't Lie 2026-07-15
- kubernetes The Invisible Admin: Unauthenticated Endpoints in Kubernetes Infrastructure 2026-07-13
- cve Old CVEs Don't Die, They Get Added to KEV 2026-07-10
- bug-bounty Scope Is the Whole Game 2026-07-06
- bug-bounty A PoC Is a Contract 2026-06-29
- bug-bounty Passive Watchlists Are Not Findings 2026-06-22
- bug-bounty Blocked Is a Result 2026-06-15
- bug-bounty Bug Bounty Needs a Run Loop 2026-06-09
- local-models Same Model, Different Brain: How a ReACT Loop Transformed a 35B Model's Security Skills 2026-03-16
- methodology How I Approach a New Bug Bounty Target 2026-03-11
- bug-bounty When 'Informative' Is the Answer 2026-03-11