Secure Code Review: The 5 Mistakes I Find in Every Backend
Five security vulnerabilities lurking in almost every backend project — and how to fix them.
Full-Cycle Security Engineer: Why Developers Should Learn Pentesting
Most pentesters find vulnerabilities but can't fix them. Most devs don't see the vulnerabilities. I do both.
Why Your Backend JWT Setup Is Insecure Despite Using a Library
How an attacker bypasses your JWT – and how you as a developer actually secure it.
Security Risks in IoT Devices (Default Passwords, Update Strategies)
Minimizing common vulnerabilities and establishing secure OTA processes.
Security in Embedded Software (Buffer Overflows, Secure State Machines)
Avoiding common vulnerability classes and building robust state machines.
Embedded Security as a Future Topic (Secure Boot, TrustZone)
Reducing attack surfaces, signature/verification and hardware isolation.