devsecops 13
- Your S3 Bucket Is an Open Directory and You Probably Don't Know It
- Breaking My Own Infrastructure: 12 Days, 19 Findings, 3 False Positives
- What --dryrun Taught Me About Confidence
- The Load Balancer That Trusted Everyone
- I Can Read Everyone's Invoices (and Found a Backdoor Inside)
- The Refresh Token That Wouldn't Die
- It's 3 AM and I'm Creating a Thousand Invoices
- I Just Sent XSS Payloads to the Support Team
- When Your Internal Fields Aren't Internal: The Day I Deleted My Own Account
- The CORS Rabbit Hole I Didn't Want to Go Down
- How Two curl Commands Gave Me Full Access to an S3 Bucket
- 5,000 Attack Vectors Later: What I Learned From Testing Everything
- From DevOps to DevSecOps: Why I Started Breaking Things on Purpose