Writing
Security & engineering deep-dives
- From Self-XSS to Account Takeover: Chaining Web Cache Poisoning on a Public Bug-Bounty Targetcybersecurity · 2026-04-02 · 8 min read
- A Repeatable Red-Team Harness for LLM Agents: From Corpora to Guardrailsaiml · 2026-03-28 · 8 min read
- Spending a Voucher Twice in 40ms: A TOCTOU Race Condition in a Payments Flowcybersecurity · 2026-03-19 · 8 min read
- Choose Your Lens: Designing a Portfolio for a Multi-Disciplinary Careeruiux · 2026-03-04 · 8 min read
- An ML Anomaly Detector for Auth Logs That a SOC Actually Trustsaiml · 2026-02-23 · 8 min read
- Breaking Tool Trust Boundaries in Agentic Multi-LLM Workflowscybersecurity · 2026-02-09 · 9 min read
- Building BugTraceAI: A 6-Phase Autonomous Security Scanning Pipelineengineering · 2026-01-26 · 9 min read
- Event-Driven at Scale: Idempotent Apache Kafka Consumers in Spring Bootengineering · 2025-12-30 · 9 min read
- Closing 24 GDPR Control Gaps by Wiring Article 30/32 into CI/CDcybersecurity · 2025-12-15 · 8 min read
- From IDOR to Full Account Takeover: A Repeatable Authorization-Matrix Workflowcybersecurity · 2025-11-18 · 8 min read
- Benchmarking Post-Quantum Blind Signatures: Lessons From My MSc Dissertationresearch · 2025-11-02 · 9 min read
- Accessibility Is a Security Control: WCAG 2.2 AA in High-Stakes Dashboardsuiux · 2025-10-12 · 7 min read
- Cutting Scanner Alert Fatigue 61% With an Embeddings-Based LLM Triage Layercybersecurity · 2025-09-30 · 9 min read
- Engineering a .NET Core Microservices Estate for 99.99% Uptimeengineering · 2025-08-21 · 9 min read