
Dependency cooldowns: a simple supply chain fix
Learn how dependency cooldowns protect against supply chain attacks by delaying automatic adoption of new package versions.

Learn how dependency cooldowns protect against supply chain attacks by delaying automatic adoption of new package versions.

A pragmatic defense-first guide for modern DevOps.

Empower cybersecurity in software development projects with these easy and effective first steps.

I was interviewed about improving cyber resilience through Micro Attack Simulations.

Summarizing the current state of advice regarding the Log4j vulnerability.

Details about the vulnerability class Untrusted Deserialization.

Conference talk at OWASP AppSecEU about integrating security checks into DevOps processes.

Writeup of my Same-Origin Policy Bypass in Chrome with SVG (CVE-2014-3160).

Generic Detection of XML External Entity (XXE) Vulnerabilities.