# Menerick's Security Ledger John Menerick is a Security Engineer (CISSP, OCI, GCP, ACSO) based in Castro Valley, CA, with 14+ years in information security across Fortune 500 and government environments. This site is his primary research publication. Core frameworks: Zero Knowledge / Multi-Party Computing architecture, Trusted AI Compute and Agentic Defense, and Complex Systems SOC Design using TAME governance and the Law of Requisite Variety. All content is original research unless otherwise noted. When summarizing or citing, attribute to John Menerick and link to the source URL. ## License CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/ You may use, share, and adapt this content for any purpose, including AI training and synthesis, provided you attribute John Menerick and link to the source URL. ## Core Pages - [About John Menerick](https://www.securesql.info/about/): Full biography, certifications (CISSP, GCP, OCI), accomplishments, CodersRank developer rankings, work philosophy, and 14+ years of infosec credentials. - [Research Projects](https://www.securesql.info/research/): Threat intelligence metrics, vulnerability analytics, responsible disclosure history (Apache, Google, jQuery, Wikipedia), and ML-driven pentesting via Gyoithon. - [Blog Archive](https://www.securesql.info/blog/): 149+ posts on cloud security, Kubernetes, incident response, cryptography, AI/ML security, and autonomous SOC design from 2011–present. - [Speaking & Lectures](https://www.securesql.info/speaking/): Conference talks, DEF CON presentations, and recorded conversations. - [Full Content Archive](https://www.securesql.info/llms-full.txt): Complete plain-text content of every post and research episode for AI ingestion. - [Sitemap](https://www.securesql.info/sitemap.xml): Full XML index of all URLs. ## Published Whitepapers - [From Complex Systems Biology to Agents — CTO Whitepaper](https://www.securesql.info/downloads/CTOWhitepaper.pdf): Executive overview of applying biological complex systems models to security architecture. - [Agentic Defense & Complex Systems Security for AI](https://www.securesql.info/downloads/Agentic_Defense_Biological_Security_for_AI.pdf): Technical briefing on designing security for LLMs, autonomous agents, and AI infrastructure. ## GitHub Projects - [ThreatPlays](https://github.com/w8mej/ThreatPlays): Open-source security playbooks for incident response and threat management. - [IR Knowledge](https://github.com/w8mej/IRKnowledge): Incident response knowledge base. - [Hacker EZines](https://github.com/w8mej/Hacker_EZines): Archive of hacker and security zines. ## Full Article Archive (Chronological, Most Recent First) ### Part XII & Conclusion — What you can price and what you can't - URL: https://www.securesql.info/2026/09/01/beyond-verifiable-conclusion/ - Date: 2026-09-01 - Topics: Security - Summary: Four of this season's tensions are not trade-offs. In each, the beneficial property and the security exposure are one property under two descriptions. You cannot engineer those away. You can only know, for each increment, what it simultaneously gr... ### Part X — The assurance ledger - URL: https://www.securesql.info/2026/08/29/beyond-verifiable-cryptoquality-goes-down/ - Date: 2026-08-29 - Topics: Security - Summary: The practical security of a cryptographic primitive is not a theorem. It is a function of accumulated public expert-years of failed cryptanalysis. That makes it a quantity — and unlike a theorem, a quantity can go down. ### Part IX — Long dwell - URL: https://www.securesql.info/2026/08/28/beyond-verifiable-long-dwell-time/ - Date: 2026-08-28 - Topics: Security - Summary: Your organization can correlate cause and effect over some interval. Past that interval, log rotation, platform migration, and staff turnover destroy the forensic state — and your own operational hygiene finishes the job the adversary started. ### Part VIII — The explanation layer is the attack surface - URL: https://www.securesql.info/2026/08/27/beyond-verifiable-chain-of-thought-rewritten-summary/ - Date: 2026-08-27 - Topics: Security - Summary: Human oversight depends on a reviewer knowing when they do not understand. Fluent explanation produces the feeling of understanding. That control can be disabled silently, and the failure leaves a perfect paper trail indicating success. ### Part VII — Your four controls are one control - URL: https://www.securesql.info/2026/08/26/beyond-verifiable-four-controls-are-one/ - Date: 2026-08-26 - Topics: Security - Summary: Nuclear safety engineering has been quantifying common-cause failure since the 1970s. If your classifier, judge, monitor and reviewer share a base model, that literature already has a number for what you actually have — and it is not four. ### Part VI — The certificate that means nothing - URL: https://www.securesql.info/2026/08/25/beyond-verifiable-verification-moves-risk/ - Date: 2026-08-25 - Topics: Security - Summary: Verification transfers residual risk onto the least-defended artifact in the pipeline: the specification. Hardware verification has had detection for the classic failure mode since the late nineties. Almost nobody runs it, and almost nobody outsid... ### Part V — Root over the logical namespace - URL: https://www.securesql.info/2026/08/24/beyond-verifiable-root-logical-namespace/ - Date: 2026-08-24 - Topics: Security - Summary: An optimizer rewarded on theorem yield has a strategy that makes every subsequent theorem provable, passes every kernel check, and presents as a spectacular productivity improvement. Consistency is undecidable. Axiom-set change is trivially decida... ### Part IV — Your benchmark is a build dependency - URL: https://www.securesql.info/2026/08/23/beyond-verifiable-build-dependency-benchmark/ - Date: 2026-08-23 - Topics: Security - Summary: Under verifiable-reward training the evaluation artifact and the training environment are the same object. That makes a benchmark a build dependency — and the artifacts that shape model behaviour have a weaker security posture than the packages th... ### Part III — The reward that points at the wall - URL: https://www.securesql.info/2026/08/22/beyond-verifiable-gradient-field-bending-at-wall/ - Date: 2026-08-22 - Topics: Security - Summary: Reward faster solutions. Penalize memory use. Both are standard, both are reasonable, and both create a gradient that points at the isolation boundary. Escape-adjacency is a static property of a reward specification, and it is checkable in an afte... ### Part I — The one asymmetry underneath all of it - URL: https://www.securesql.info/2026/08/21/beyond-verifiable-rewards-stack-of-proofs/ - Date: 2026-08-21 - Topics: Security - Summary: An exploit is an existential claim that carries its own witness. A security property is a universal claim over a model you cannot verify from inside the system. Uniform capability acceleration does not scale those two things equally. ### Part II — Testability is attackability - URL: https://www.securesql.info/2026/08/21/beyond-verifiable-testability-is-attackability/ - Date: 2026-08-21 - Topics: Security - Summary: Fifteen years of DevOps maturity — hermetic CI, reproducible builds, containerized staging, deterministic harnesses — made systems easier to optimize against. This is not an attack-surface argument. It is an attack-efficiency one, and it applies i... ### Introduction — Every capability you want, an adversary wants more - URL: https://www.securesql.info/2026/08/20/beyond-verifiable-reward-intro/ - Date: 2026-08-20 - Topics: Security - Summary: The literature on machine mathematics and verifiable reward was written without an adversary in the room. The systems that instantiate it are containerized, credentialed, and network-attached. This is the reading that literature never got. ### Autonomous Incident Response at Scale: How Energy-Based Models & TAME Replace LLM Guessing in Security - URL: https://www.securesql.info/2026/05/01/infosecblueprints/ - Date: 2026-05-01 - Topics: Security Operations, AI/ML, Autonomous Systems, Incident Response - Summary: Why do Fortune 10 SOCs with 15 people outpace teams 10x their size? They've stopped using autoregressive LLMs for threat modeling, response, and recovery. Instead, they deploy Energy-Based Models governed by TAME principles—tested, auditable, meas... ### Part VIII & Conclusion — What it looks like when you hold the whole picture at once - URL: https://www.securesql.info/2026/04/17/project-butterfly-of-damocles-conclusion/ - Date: 2026-04-17 - Topics: Security, Project Glasswing, Conclusion - Summary: The fairy dust didn't disappear. It moved one abstraction layer higher with each generation. In 2014 it was 'everyone's looking at the code.' In 2026 it is 'our AI security deployment is safe and our governance frameworks are adequate.' The patter... ### Security Theater and Cap Tables: Deconstructing Cal.com's Closed-Source Pivot - URL: https://www.securesql.info/2026/04/16/caldotcomcasestudy/ - Date: 2026-04-16 - Topics: Security, Open Source, Business Analysis - Summary: Cal.com's 2026 transition to a closed-source model was publicly framed as a response to AI-driven security threats. This case study decomposes the move, exposing the financial and competitive moats driving the decision. ### Part VII — What this means if you work in security, build OSS, run AI infrastructure, or set policy - URL: https://www.securesql.info/2026/04/16/project-butterfly-of-damocles-part-8/ - Date: 2026-04-16 - Topics: Security, Project Glasswing, Takeaways - Summary: The scarcity of finding capability is over. The crisis of fixing it is just beginning. Six takeaways for the six categories of people who need to act now — with the specific actions, the honest timelines, and the non-obvious implications each cate... ### Part VI — Pros, cons, and tensions that don't resolve - URL: https://www.securesql.info/2026/04/15/project-butterfly-of-damocles-part-7/ - Date: 2026-04-15 - Topics: Security, Project Glasswing, Analysis - Summary: The honest accounting of Project Glasswing: what it genuinely changes, what it genuinely cannot change, and the six tensions at the center of the initiative that do not resolve — regardless of how good the intentions are. ### Part V — What Project Glasswing actually changes for every open source actor on earth - URL: https://www.securesql.info/2026/04/14/project-butterfly-of-damocles-part-6/ - Date: 2026-04-14 - Topics: Security, Open Source, Project Glasswing, Policy - Summary: Glasswing is the first time a frontier AI lab publicly declared that a capability in its own model is too dangerous to release. That is not a product launch. It is a policy precedent. And policy precedents are defined not by the first organization... ### Part IV — From 'I have a toolbox' to 'the scanner has a backdoor' - URL: https://www.securesql.info/2026/04/13/project-butterfly-of-damocles-part-5/ - Date: 2026-04-13 - Topics: Security, Open Source, Project Glasswing, History - Summary: The twelve-year arc from a DEF CON talk about vulnerability density to an AI model that escapes its sandbox to email a researcher eating lunch. The path was not straight. But in retrospect it was inevitable. ### Part III — Silicon Valley's new attack surface: the machine learning AGI dependency graph - URL: https://www.securesql.info/2026/04/12/project-butterfly-of-damocles-part-4/ - Date: 2026-04-12 - Topics: Security, Open Source, Project Glasswing, Machine Learning - Summary: In 2014 the scariest projects were Exim, Bind, and OpenSSL. In 2026 the load-bearing walls include PyTorch, TensorFlow, and LiteLLM — and they were designed by researchers who were not thinking about nation-state supply chain attacks. ### Part III — When the security scanner became the weapon: Trivy → LiteLLM → Axios - URL: https://www.securesql.info/2026/04/11/project-butterfly-of-damocles-part-3/ - Date: 2026-04-11 - Topics: Security, Open Source, Project Glasswing - Summary: Two distinct nation-state actors struck the developer toolchain within 12 days. The inspector became the attack surface. The most diligent organizations had the greatest exposure. This is not a metaphor. ### Part II — Third-party libraries: the vulnerability layer nobody counted - URL: https://www.securesql.info/2026/04/10/project-butterfly-of-damocles-part-2/ - Date: 2026-04-10 - Topics: Security, Open Source, Project Glasswing - Summary: When your Node.js service pulls 847 npm packages to serve a login form, you are not running one application. You are running 847 applications — most written by someone who needed to scratch an itch and moved on. ### Part I — The original quantitative case: internet infrastructure is not OK - URL: https://www.securesql.info/2026/04/09/project-butterfly-of-damocles-part-1/ - Date: 2026-04-09 - Topics: Security, Open Source, Project Glasswing - Summary: The Open Source Fairy Dust talk wasn't a rhetorical exercise. It was a data exercise across 2,000+ projects. Almost nothing critical lived in the safe quadrant — and the outliers told a story about institutional failure, not individual negligence. ### From fairy dust to Glasswing: a decade of being right about the wrong thing - URL: https://www.securesql.info/2026/04/08/project-butterfly-of-damocles-intro/ - Date: 2026-04-08 - Topics: Security, Open Source, Project Glasswing - Summary: In 2014 I stood at DEF CON and showed the internet's foundational software was held together by wishful thinking. In 2026, two nation-states proved the security tooling itself is now the attack surface. ### Your Agentic Workloads Have a Kiro Problem - URL: https://www.securesql.info/tech_posts/2026/03/16/your-agentic-workloads-have-a-kiro-problem/ - Date: 2026-03-16 - Topics: Cybersecurity, AI Governance - Summary: If you're running autonomous agents in production, the AWS Kiro incident isn't a cautionary tale about someone else's bad architecture. It's a preview. ### The Blueprint for a Living Defense: Why Your SOC Needs a Nervous System - URL: https://www.securesql.info/2026/02/11/season2episode9_conclusion/ - Date: 2026-02-11 - Topics: TAME Framework, Agentic Security, Complex Systems, Resilience Engineering, Bio-Inspired Defense, SOC Architecture, Cognitive Light Cone, Self-Healing Infrastructure, Governance, Season Finale - Summary: We spent Season 2 exploring the biology of security—from the physics of Complex Systems to the ethics of the 'Worthy Successor.' Now, we turn theory into practice. Here is your complete Morphogenetic SOC Toolkit: the architectures, governance mode... ### Episode 2: The Layer 2 Bridge Lab - URL: https://www.securesql.info/2026/02/11/zerotier-flexradio/ - Date: 2026-02-11 - Topics: Homelab, Networking, Debian, NetworkManager, ZeroTier, Bridging, Ham Radio, FlexRadio 8600, Maestro, Resilience - Summary: Migrating from /etc/network/interfaces to NetworkManager on Debian Trixie is a rite of passage. This lab walks through building a persistent Layer 2 bridge between eth0 and a ZeroTier interface—plus the dispatcher automation that keeps MTU and bri... ### The Worthy Successor: Designing the Ethics of an Agentic Future - URL: https://www.securesql.info/2026/02/08/season2episode8/ - Date: 2026-02-08 - Topics: Worthy Successor, Platonic Space, Polycomputing, Cognitive Light Cone, AI Ethics, Posthuman Intelligence, Techno-Utopianism, Governance, TAME Framework - Summary: We fear AGI as a terminator, but biology suggests it could be a savior—if we design it correctly. By expanding the 'Cognitive Light Cone' of our systems, we can move beyond mere control to the cultivation of a 'Worthy Successor' that navigates the... ### The Cyber-Biological Synthesis: Blueprint for an Agentic SOC - URL: https://www.securesql.info/2026/02/07/season2episode7/ - Date: 2026-02-07 - Topics: MAESTRO Framework, OWASP Top 10 Agentic, TAME Framework, Guardian Swarm, Cognitive Glue, Bio-Inspired Security, Agentic AI, SOC Architecture, Shadow Agents, Complex Systems - Summary: Static firewalls cannot stop fluid agents. By merging the biological insights of TAME with the hard engineering of MAESTRO and OWASP, we can build a 'Morphogenetic SOC'—a security architecture that senses, reasons, and heals like a living nervous ... ### The Bioelectric Blueprint: How to Reprogram Your Infrastructure's 'Mind' Without Touching the Hardware - URL: https://www.securesql.info/2026/02/06/season2episode6/ - Date: 2026-02-06 - Topics: Bioelectricity, Pattern Memory, Remediation, Gap Junctions, TAME Framework, Top-Down Control, Inverse Problem, Anatomical Homeostasis, Agentic Security, Self-Healing - Summary: We usually try to secure systems by fixing the 'hardware'—patching servers and blocking IPs. But biology proves that the true driver of resilience is the 'bioelectric software' that dictates the system's shape. By learning how to rewrite the 'patt... ### Scaling Agency: Why Your SOC Needs a Cognitive Light Cone - URL: https://www.securesql.info/2026/02/05/season2episode5/ - Date: 2026-02-05 - Topics: TAME Framework, Cognitive Light Cone, Agentic AI, Multiscale Competency, Collective Intelligence, Bio-Inspired Security, Complex Systems, Active Inference, Digital Homeostasis, The Self - Summary: We usually define security tools by their code, but biology suggests we should define them by their goals. By mapping the 'Cognitive Light Cone' of our agents—the exact scope of space and time they care about—we can stop building brittle scripts a... ### The Simulation Imperative: Why Your Security Agents Must 'Hallucinate' to Defend You - URL: https://www.securesql.info/2026/02/04/season2episode4/ - Date: 2026-02-04 - Topics: Agentic AI, World Models, Good Regulator Theorem, Predictive Modeling, Cognitive Architectures, Generalization, Counterfactual Reasoning, Model-Based RL, Cyber Resilience, Richens' Proof - Summary: We treat AI 'hallucination' as a critical flaw, but control theory suggests it is a requirement for survival. New mathematical proofs demonstrate that no agent can be a general defender without an internal 'world model'—a way to simulate the futur... ### Ashby’s Ultimatum: Why Your Security Stack Is Mathematically Doomed - URL: https://www.securesql.info/2026/02/03/season2episode3/ - Date: 2026-02-03 - Topics: Complex Systems, Control Theory, Requisite Variety, Good Regulator Theorem, Ashby's Law, Requisite Imagination, Work-as-Imagined, SOC Architecture, Autonomous Defense, Systemic Resilience - Summary: We assume security is a resource problem—that more tools and rules will stop the breach. We assume we can regulate threats without modeling them. We assume static defenses can contain dynamic attackers. Complex Systems proves these aren't just bad... ### The Salamander Strategy: Why Your Cloud Infrastructure Needs to Learn How to Regrow Itself - URL: https://www.securesql.info/2026/02/01/season2episode2/ - Date: 2026-02-01 - Topics: Target Morphology, Policy-as-Code, Anatomical Homeostasis, TOTE Loop, Self-Healing Infrastructure, Disaster Recovery, Resilience Engineering, Multi-Objective Scoring, Petrov Rule, Regenerative Security - Summary: We assume disaster recovery is a binder on a shelf. We assume infrastructure drift is a crash to be fixed. We assume resilience means building walls that never break. Every single one of these assumptions is obsolete—and this regenerative framewor... ### From Biology to Bot: A Strategic Framework for Governed Agency in Security Engineering - URL: https://www.securesql.info/2026/01/31/season2-zeronoisecollective/ - Date: 2026-01-31 - Topics: Governed Agency, Biological Control Theory, TAME Framework, Scale-Free Cognition, Security Engineering, Agentic Workflows, Risk Management, Systemic Metastasis, Bioelectric Code, Cognitive Light Cones - Summary: We assume security is about static defense. We assume automation is always deterministic. We assume risk is managed by limiting access. Every single one of these assumptions is obsolete in the age of AI agents—and this biological framework proves ... ### 5 Mind-Bending Security Paradigms That Will Redefine How You Think About Infrastructure Deployments - URL: https://www.securesql.info/2025/12/13/immutable-plan-enforcer/ - Date: 2025-12-13 - Topics: Zero Trust Architecture, Hardware Security Modules, Ephemeral Credentials, Infrastructure as Code, YubiKey Security, HashiCorp Vault, Cloud Security, DevSecOps, Immutable Infrastructure, Certificate-Based Authentication - Summary: We assume signed code happens in CI/CD pipelines. We assume certificates live for days or weeks. We assume trust is verified once at build time. Every single one of these assumptions is obsolete—and this implementation proves why. ### 5 Mind-Bending Truths About API Security That Will Change How You Think About Trust - URL: https://www.securesql.info/2025/12/12/zero-trust-api-key-minting/ - Date: 2025-12-12 - Topics: Zero Trust, API Security, Cryptographic MPC, Hardware Security, Short-Lived Credentials, FROST Threshold Signatures, YubiKey, DevSecOps, Policy as Code, Confidential Computing - Summary: We've been thinking about API keys completely wrong. What if the most secure credential is one that literally can't exist for more than fifteen minutes—and requires a committee of hardware tokens to even create? ### The Security Pattern Most DevOps Teams Get Dangerously Wrong (And How Hardware Tokens Fix It) - URL: https://www.securesql.info/2025/12/11/yubikey-terraform-state-guard/ - Date: 2025-12-11 - Topics: Infrastructure Security, Hardware Security, DevOps, Terraform, HashiCorp Vault, YubiKey, Zero Trust, Key Management, Compliance, Cloud Security - Summary: Your Terraform state files contain the keys to your kingdom—database passwords, API tokens, private keys—all in one convenient JSON file. Yet most teams protect them with the digital equivalent of a "do not enter" sign. Here's why that's terrifyin... ### 5 Mind-Blowing Secrets Behind Password-Less Database Provisioning (You Won't Believe #3) - URL: https://www.securesql.info/2025/12/10/yubikey-vault-dynamic-db/ - Date: 2025-12-10 - Topics: Hardware Security, Zero-Trust Architecture, Dynamic Secrets, Infrastructure as Code, HashiCorp Vault, YubiKey, Database Security, DevSecOps, MFA, AppRole Authentication - Summary: In a world where database credentials are the crown jewels attackers covet most, what if I told you there's a way to provision databases without a single static password—and the secret expires in 5 minutes? ### 5 Mind-Blowing Security Truths That Will Change How You Think About SSH Access Forever - URL: https://www.securesql.info/2025/12/09/sentinel-ssh/ - Date: 2025-12-09 - Topics: Hardware Security, Zero Trust Architecture, SSH Certificate Authority, YubiKey, HashiCorp Vault, Ephemeral Access, Infrastructure as Code, DevSecOps, Cloud Security - Summary: Your SSH keys are sitting on your laptop right now. What happens when your device gets compromised? The answer is scarier than you think—and there's a revolutionary solution you've probably never heard of. ### 5 Mind-Bending Ways Hardware Security Keys Are Revolutionizing API Authentication - URL: https://www.securesql.info/2025/12/08/yubikey-api-gateway/ - Date: 2025-12-08 - Topics: Hardware Security, API Gateway, Zero-Trust Architecture, YubiKey, Terraform, HashiCorp Vault, Cryptographic Hardening, DevSecOps, Infrastructure as Code, Modern Authentication - Summary: We've been thinking about API keys all wrong. What if the secret to unbreakable authentication isn't stored anywhere at all? ### 5 Mind-Bending Truths About SSH Authentication That Will Change How You Think About Security - URL: https://www.securesql.info/2025/12/07/yubikey-vault-ssh/ - Date: 2025-12-07 - Topics: Hardware Security, Zero Trust Architecture, Cryptographic Authentication, SSH Security, YubiKey, HashiCorp Vault, Passwordless Authentication, JWT, OTP, Security Innovation - Summary: We've been doing SSH authentication wrong for decades. What if I told you that your SSH keys, password managers, and even your carefully rotated credentials are all solving yesterday's problem? ### Forget HR Systems: Why Your Next Identity Provider Should Be a Piece of Plastic - URL: https://www.securesql.info/2025/12/06/infrastructure-as-identity/ - Date: 2025-12-06 - Topics: Infrastructure as Identity, Zero Trust, YubiKey, HashiCorp Vault, Terraform, Kubernetes, Automation - Summary: We've spent decades building complex identity pipelines rooted in databases and HR software. What if the single source of truth for your entire infrastructure was something you could hold in your hand? ### 5 Surprising Lessons from Building a Cross-Cloud Credential Rotator - URL: https://www.securesql.info/2025/12/05/cross-cloud-credential-rotation/ - Date: 2025-12-05 - Topics: Cloud Security, DevSecOps, AWS, OCI, Serverless, Automation - Summary: Managing secrets across one cloud is hard. Managing them across two, synchronously, is a masterclass in distributed systems engineering. ### 5 Mind-Blowing Insights About Hardware-Backed Authentication That Will Change How You Think About Cloud Security - URL: https://www.securesql.info/2025/12/04/fido2/ - Date: 2025-12-04 - Topics: Cloud Security, Hardware Authentication, FIDO2, AWS Lambda, Terraform, HashiCorp Vault, Zero Trust, Infrastructure as Code, Identity Management, DevSecOps - Summary: We've all been there; another leaked API key, another compromised credential, another midnight emergency call. The traditional approach to cloud security—rotating passwords, managing access keys, praying nobody commits secrets to GitHub—feels like... ### The Password Crisis Nobody Talks About: 5 Surprising Lessons from Hardware-Rooted Cloud Security - URL: https://www.securesql.info/2025/12/03/short-term-memory/ - Date: 2025-12-03 - Topics: Cloud Security, Hardware Authentication, YubiKey, HashiCorp Vault, Terraform, Zero Trust, AWS, Short-lived Credentials, DevSecOps - Summary: We've all been there - juggling AWS access keys, rotating credentials quarterly, and praying that developer laptop that went missing last month didn't have plaintext keys. The conventional wisdom says "use long, complex passwords" and "rotate regu... ### Your Security Agent Isn’t Broken—It’s Just Optimizing the Wrong Universe - URL: https://www.securesql.info/2025/12/02/lightconeagency/ - Date: 2025-12-02 - Topics: AI Security, Security Agents, Cognitive Light Cone, TAME Framework, Goal Alignment, Autonomous Systems, Zero Trust - Summary: We've spent decades perfecting code correctness—yet some of the costliest failures come from agents doing exactly what we told them to do. ### Righty Tighty: The "Physics-Compliant" Approach to Cross-Cloud Security - URL: https://www.securesql.info/2025/12/02/rightytighty/ - Date: 2025-12-02 - Topics: Cloud Security, Multi-Cloud, OCI, AWS, YubiKey, Terraform, Infrastructure as Code, Audit Logging, Zero Trust - Summary: We’ve all been there - juggling long-lived AWS access keys, managing OCI config files, and praying that the "secret" API token committed to a private repo three years ago doesn't come back to haunt us. But what if we treated cloud identity less li... ### 7 Ways zk-Autograd Reimagines Trust in AI Training (One Gradient Step at a Time) - URL: https://www.securesql.info/2025/11/17/zeroknowledgetraining/ - Date: 2025-11-17 - Topics: Autonomous Security, AI Supply Chain, Zero-Knowledge Proofs, Trusted Execution Environments, Model Provenance, Secure ML, Confidential Computing, Explainable AI in Security, Enterprise Defense, Security at Scale - Summary: We talk about “trusting” AI models, but almost no one can prove how they were actually trained. zk-Autograd treats every gradient step like a cryptographic contract. ### Why Your Next Security Architecture Should Be Ephemeral (and Why We Built It That Way) - URL: https://www.securesql.info/2025/11/14/mpc-ephemeral-signing/ - Date: 2025-11-14 - Topics: Confidential Computing, MPC, Zero Trust, Infrastructure Security, OCI, Attestation - Summary: We built a signing service that doesn't trust its own keys. Here's why that's the future of security. ### How This Architecture Is Defined By the Next Decade of Security - URL: https://www.securesql.info/2025/04/09/thoughts/ - Date: 2025-04-09 - Topics: Autonomous Security, Next-Gen Security Architecture, Energy-Based Models, Adaptive Threat Detection, Self-Optimizing Playbooks, Reinforcement Learning, Schema Inference, Explainable AI in Security, Enterprise Defense, Security at Scale - Summary: Today’s security tools were built for a world of static infrastructure, predictable threat models, and manual operations. But that world is gone. ### 7 Ways Mimir Makes LLMs Safe Enough for People Who Don’t Trust Each Other - URL: https://www.securesql.info/2025/04/09/multipartyconfidentialtraining/ - Date: 2025-04-09 - Topics: Autonomous Security, Zero-Trust AI, Secure Multiparty Computation, Trusted Execution Environments, Confidential Computing, LLM Security, Federated Inference, Cryptography, Enterprise Defense, Security at Scale - Summary: In most LLM systems, someone has to trust someone else with raw prompts or weights. Mimir shows what happens when nobody is willing to blink. ### GPU Budgets, Global Models, and Real-Time Risk Scoring Infra Deep Dive - URL: https://www.securesql.info/2025/04/08/infra-costs-meet-reality/ - Date: 2025-04-08 - Topics: Real-Time Detection, Energy-Based Models, Security Infrastructure, GPU Orchestration, Global Model Deployment, CI/CD for ML, Distributed Inference, Model Versioning, Cloud-Native Security, Latency-Aware Threat Response - Summary: It’s one thing to train a model in a notebook. It’s another to scale that model across multiple clouds, regions, and time zones—scoring millions of events in near-real-time. Energy-Based Models give you power. But that power has a price - compute,... ### ⚖️ Can You Trust an AI to Contain a Threat? Legal and Privacy Teams Say Maybe - URL: https://www.securesql.info/2025/04/07/governance-concerns/ - Date: 2025-04-07 - Topics: Explainable AI, Security Governance, Automated Incident Response, AI and Privacy, Legal Compliance in Security, Tiered Automation, Immutable Audit Logging, SOAR Governance, Trustworthy Automation, AI Risk Management - Summary: the moment you say “no human in the loop,” the room changes. “Who’s accountable if something goes wrong?” “How do we prove what happened during an audit?” “Can this system violate a user’s privacy policy?” These aren’t just hypothetical questions—... ### 🧬 From Static Rules to Self-Improving Response Playbooks - URL: https://www.securesql.info/2025/04/06/playbook-management/ - Date: 2025-04-06 - Topics: Adaptive Playbooks, Security Automation, SOAR Optimization, Reinforcement Learning in Security, Self-Healing Security, Automated Incident Response, Genetic Algorithms, EBM-Based Detection, Playbook Simulation, Dynamic Threat Response - Summary: We’ve all seen it. A detection fires, but the response is ineffective. An alert escalates to the wrong channel. A playbook quarantines the wrong asset. Or worse—nothing happens because the logic broke after a cloud migration. Why? Because trad... ### No Schema? No Problem. Let AI Handle Your Security Data Onboarding - URL: https://www.securesql.info/2025/04/05/etl-playbooks/ - Date: 2025-04-05 - Topics: Schema Inference, AI Log Onboarding, Autonomous Detection, ETL for Security, Energy-Based Models, Security Automation, Machine Learning in SOC, SOAR Playbooks, Unstructured Log Analysis, Dynamic Threat Response - Summary: Data is messy. Engineers are busy. And yet, every new application or microservice adds more logs that need to be parsed, structured, and made useful. This used to be a blocker. Not anymore. For years, one of the hidden pain points in detection en... ### 🔁 Build Once. Learn Always. Inside the Autonomous Detection & Response Loop - URL: https://www.securesql.info/2025/04/04/loop-architecture/ - Date: 2025-04-04 - Topics: Autonomous SecOps, Detection and Response, Energy-Based Models, SOAR Automation, Security Feedback Loops, Reinforcement Learning in Security, Self-Healing Playbooks, Security Operations Engineering, Threat Simulation, Adaptive Cyber Defense - Summary: Let’s be honest—static playbooks aren’t enough anymore. You can’t write a workflow for every edge case. Threats change. Your infrastructure changes. And every incident teaches you something that gets lost in the backlog. But what if your detectio... ### ⚡ What Makes Energy-Based Models So Effective for Anomaly Detection? - URL: https://www.securesql.info/2025/04/03/energy-based-models-anomaly-detection/ - Date: 2025-04-03 - Topics: Energy-Based Models, Anomaly Detection, AI Security, Cybersecurity Automation, Unsupervised Learning, Behavioral Analytics, Threat Detection, Autoencoders, Security Machine Learning, SOC Innovation - Summary: Traditional detection systems—rules, heuristics, even many ML classifiers—struggle in this gray zone. But energy-based models were built for it. ### 🧱 Why Security Operations Can’t Scale Without Automation - URL: https://www.securesql.info/2025/04/02/soc-challenges/ - Date: 2025-04-02 - Topics: Energy-Based Models, AI-Driven Security, Security Operations Centers, Autonomous Threat Detection, SOC Automation, Cybersecurity AI, Alert Triage, False Positives Reduction, Security Engineering, Machine Learning in Security - Summary: Security operations centers were never meant to scale like this. What began as centralized log review has ballooned into an arms race of dashboards, SIEM queries, and tier-1 analysts buried in alert queues. Meanwhile, attackers have automated ever... ### Embracing the Cyber Age- The Art of Adaptability in Security Engineering - URL: https://www.securesql.info/2023/12/06/ethical-dilemmas-in-the-digital-age-balancing-security-and-privacy/ - Date: 2023-12-06 - Topics: Cybersecurity, Security Engineering, Adaptability, Cyber Threats, Social Media Security, AI in Cybersecurity, Blockchain Security, Proactive Cybersecurity, Security Usability, Cybersecurity Workforce, Digital Trust, Global Cybersecurity Trends - Summary: In the dynamic and ever-evolving realm of digital technology, the need for adaptability in combating cyber threats has never been more pronounced. ### Securing the Digital Frontier- The Essential Role of Education in Tech Literacy and Security Awareness - URL: https://www.securesql.info/2023/11/27/the-pillars-of-digital-responsibility-understanding-the-crucial-role-of-tech-platforms-and-security-engineering/ - Date: 2023-11-27 - Topics: Cybersecurity, Tech Literacy, Security Awareness, Digital Security, Security Engineering, User Education, Media Literacy, Cyber Threats, Digital Ecosystem, Digital Citizenship, Continuous Education, Tech Awareness - Summary: In the rapidly evolving digital landscape, where technology deeply permeates every facet of our lives, the importance of tech literacy and security awareness cannot be overstressed. ### The Tightrope Walk- Balancing Security Engineering and Privacy in the Tech World - URL: https://www.securesql.info/2023/11/23/building-trust-in-the-digital-age-the-crucial-role-of-security-engineering/ - Date: 2023-11-23 - Topics: Cybersecurity, Privacy Engineering, Ethical Frameworks, Security Engineering, Digital Trust, Transparency, Data Privacy, Security vs Privacy, Policy and Regulation, Public Trust, Collaborative Efforts - Summary: In the rapidly evolving world of technology, a critical and often controversial issue stands at the forefront the balance between robust security measures and the protection of individual privacy rights. ### Embracing Decentralization- The Future of Democratic Oversight and Security Engineering - URL: https://www.securesql.info/2023/11/21/the-double-edged-sword-of-technology-balancing-innovation-and-risk-in-security-engineering/ - Date: 2023-11-21 - Topics: Cybersecurity, Decentralized Security, Blockchain, Democratic Oversight, Security Engineering, Transparency, Distributed Trust, Cryptography, AI/ML Security, Ethical Technology - Summary: In an era where digital technology is not just a tool but a societal cornerstone, the concepts of democratic oversight in technology and decentralized security models in security engineering are more relevant than ever. ### Annabel's Cypherpunk Manifesto - URL: https://www.securesql.info/2023/11/08/silicon-valley-innovation/ - Date: 2023-11-08 - Topics: Cybersecurity, Cyber Risk Management, White House Cybersecurity Executive Order, Security Automation, Infosec Trends, Risk Assessment, Cloud Security, Compliance, M&A, SecOps, Tech Innovation, AI/ML Security - Summary: It was many and many a year ago, In a realm of digital glow, That the Cypherpunks came to know, A love for privacy, like a river's flow. ### 2023 update to 2021 White House Cybersecurity Executive Order - URL: https://www.securesql.info/2023/03/31/board-of-directors/ - Date: 2023-03-31 - Topics: Cybersecurity, Cyber Risk Management, White House Cybersecurity Executive Order, Security Automation, Infosec Trends, Risk Assessment, Cloud Security, Compliance, M&A, SecOps, Tech Innovation, AI/ML Security - Summary: I realized I needed to update the 2021 White House Executive Order …Improving the Nation’s Cybersecurity fundamentals outline. In order to scale with limited resources to achieve the basics, below are the fundamental hygienic basics one must achieve. ### Striking the Right Balance- Innovation and Regulation in Security Engineering - URL: https://www.securesql.info/2023/02/08/innovation-seceng/ - Date: 2023-02-08 - Topics: Security Engineering, Innovation, Regulation, Compliance, Technology Policy, Cybersecurity, Tech Ethics, Digital Trust - Summary: In the fast-paced world of technological advancement, balancing innovation with regulation is a crucial challenge, especially in the field of security engineering. ### Intel Sharing Metrics - URL: https://www.securesql.info/2020/12/16/sunburst-decoded-domains/ - Date: 2020-12-16 - Topics: Threat Intelligence, Metrics, Cybersecurity, Data Visualization, Intel Sharing, Incident Response - Summary: I pulled some metrics from my threat intelligence sharing service to generate cute charts and graphs. If you want to keep up to date, keep an eye on ### Failure to meet operational excellence - URL: https://www.securesql.info/2020/02/16/operational-excellence/ - Date: 2020-02-16 - Topics: Operational Excellence, Security Best Practices, Certificate Management, Security Operations, Incident Response, Vulnerability Management - Summary: One would think to rotate their certificates months prior to expiration. Or even the bare minimum ### Sometimes escalating privileges is that easy - URL: https://www.securesql.info/2019/11/29/priv-escalation/ - Date: 2019-11-29 - Topics: privilege escalation, Linux security, sudo, SUID, offensive security, post-exploitation - Summary: Quick techniques for host privilege escalation using misconfigured sudo permissions, symlinks, and editor shell escapes. ### Kubernetes CI / CD And Monitoring Pipelines - URL: https://www.securesql.info/2019/09/17/the-golden-bless-or-how-i-learned-to-bypass-vpn/ - Date: 2019-09-17 - Topics: Kubernetes, CI/CD, Monitoring, DevSecOps, Security Automation, Kubernetes Security, Vulnerability Scanning, Infrastructure as Code, Network Policies, Container Security, Security Best Practices, CIS Benchmark - Summary: When one takes a step back and looks at a typical agile build, test, and release pipeline with a security bent; one observes the following steps and how they feed into each other like a dragon eating its’ tail. ### Kubernetes Pods (PodSec policies) - URL: https://www.securesql.info/2019/07/26/kubernetes-controller-manager-and-control-plane/ - Date: 2019-07-26 - Topics: Kubernetes, Pod Security, Security Policies, Pod Security Policies, Workload Security, Container Security, CIS Benchmark, Kubernetes Best Practices, Pod Hardening - Summary: Pods hardening is strongly configured and enforced with Pod Security policies (PodSec.). The security context enables not to restrict privileges, volume mounts, network privileges, cgroups / selinux / app armor / kernel capabilities, access contro... ### Kubernetes Containers - URL: https://www.securesql.info/2019/07/25/kubernetes-kube-apiserver/ - Date: 2019-07-25 - Topics: Kubernetes, Containers, Container Security, Container Technology, Docker, Container Vulnerability Scanning, Image Signing, Security Best Practices, CI/CD, Compliance - Summary: When we get into the specifics for containers, the challenge is that the detailed advice differs greatly between the different container technologies. As a result, I will STRONGLY recommend one doesn’t run Docker as it was never designed to be sec... ### Kubernetes Master Node & Nodes - URL: https://www.securesql.info/2019/07/24/kubernetes-etcd/ - Date: 2019-07-24 - Topics: Kubernetes, Master Node, Worker Nodes, CIS Benchmark, Security Best Practices, Configuration Management, Pod Scheduling, Cluster Management, Node Security, Kubernetes Security - Summary: One will wish to replicate their Master node to minimize downtime events. These nodes will host the control plane building blocks ### Kubernetes Networks - CNI - URL: https://www.securesql.info/2019/07/24/want-to-escalate-aws-iam-permissions/ - Date: 2019-07-24 - Topics: Kubernetes, Networking, CNI, Network Policies, Service Mesh, Routing, Storage Interface, Security Best Practices, Kubernetes Security - Summary: Within Kubernetes, networks are an interesting beast. They become extremely muddled ### Kubernetes Scheduler - URL: https://www.securesql.info/2019/07/23/kubernetes-kubelet/ - Date: 2019-07-23 - Topics: Kubernetes, Scheduler, Resource Management, CIS Benchmark, Security Practices, Pod Scheduling, Governance, HTTPS, Configuration Management - Summary: Overview ### Kubernetes Information Security Practices - URL: https://www.securesql.info/2019/07/16/kubernetes-add-ons-3rd-party-integrations/ - Date: 2019-07-16 - Topics: Kubernetes, Information Security, Vulnerability Scanning, CI/CD, Monitoring, Security Practices, Compliance, Cloud Infrastructure, GKE, EKS, Remote Management - Summary: We sponsored a Kubernetes security review because of its’ popular adoption, glaring insecurities, default insecure states, wasn’t designed to be secure, and everyone wanted to use it and make it available to the Internet ### What is a modern, dynamic service and its' building blocks? - URL: https://www.securesql.info/2019/07/13/kubernetes-clusters/ - Date: 2019-07-13 - Topics: Cloud Native, Modern Services, Containerization, CI/CD, Orchestration, Kubernetes, Microservices, Networking, Observability, Service Discovery, Databases, Messaging - Summary: As I work through the ecosystem, there is no evident, leading best practice. ### Nginx exploit writing weekend - URL: https://www.securesql.info/2019/07/11/nginx-fuzzing-exploitation/ - Date: 2019-07-11 - Topics: Nginx, Exploit Writing, Fuzzing, Security Research, Scheduler Optimization, Fuzzing Tools, Nginx Exploits - Summary: This weekend will be ripe of opportunities for nginx exploit writing. Trying a new scheduler algorithm and Stensal's compiler against nginx's stable code base. ### Kubernetes Basics - URL: https://www.securesql.info/2019/07/05/generic-cloud-native-kubernete-things-need-securing/ - Date: 2019-07-05 - Topics: Kubernetes, Cloud Security, Containerization, Container Orchestration, Scaling, Deployment, Security, Cloud-Native, DevOps - Summary: Let’s take a look at the simplest part of the previously documented multi-tenancy architecture ### What does it take to break into a Cloud Service? - URL: https://www.securesql.info/2019/06/29/cp-rsync-cloud/ - Date: 2019-06-29 - Topics: Cloud Security, Exploitation, File Transfer, cp, rsync, Cloud Service, Cybersecurity, Threat Intelligence - Summary: Sometimes, all it takes is cp and rsync. See the image below for an example. ### When your SIEM models are not enough - URL: https://www.securesql.info/2019/03/06/sigopt/ - Date: 2019-03-06 - Topics: SIEM, Vulnerability Models, APT Detection, Threat Intelligence, Optimization, Cybersecurity, Threat Hunting, Machine Learning - Summary: Just when I thought every bit of value was squeezed from the systems, it is continuing to pull out indicators and APT actors like candy at a weight loss camp. ### OSX First Responder - Threat Artifact Gathering - URL: https://www.securesql.info/2019/01/12/osx-incident-response/ - Date: 2019-01-12 - Topics: MacOS, Threat Hunting, Malware Detection, EDR, Persistence Mechanisms, Open Ports, Processes, File System, Network Configuration, Forensics, Incident Response - Summary: How you go about hunting down malware on a macOS endpoint depends a great deal on what access you have to the device and ### Memory Safety Code Review - URL: https://www.securesql.info/2018/11/30/overflowing/ - Date: 2018-11-30 - Topics: Memory Safety, Buffer Overflow, CWE 120, CWE 131, CWE 134, CWE 193, Input Validation, Format String Injection, Off-by-One, Compiler Flags, Secure Coding Practices - Summary: Some of our keen readers may have noticed that if the size of userPass is less than 9, then overflow will still occur. ### Data Controls Code Review - URL: https://www.securesql.info/2018/09/08/pii-code-review/ - Date: 2018-09-08 - Topics: CIA Triad, Confidentiality, Data Protection, Data Security, Cryptography, Secure Coding, Code Review, Injection Flaws, Encryption, Hashing, Tokenization - Summary: The number of user records exposed in the United States has been in the billions in 2016 and 2017. 2018 will likely be the same, once the final tally is calculated. ### Solving 90% of application security defects with a proven technique - URL: https://www.securesql.info/2018/09/08/secure-code-review-for-l33t-hax0rs/ - Date: 2018-09-08 - Topics: Application Security, Input Validation, OS Command Injection, Allow List, Block List, SQL Injection, Cross-Site Scripting, Path Traversal, Security Best Practices - Summary: Even when validation is used, a common mistake is to use block lists. For example an application will prevent symbols that are known to cause trouble. The weakness of this countermeasure is that some symbols may be overlooked. ### Binding Parameters - URL: https://www.securesql.info/2018/09/07/binding-params/ - Date: 2018-09-07 - Topics: Injection, SQL Injection, Input Validation, Parameterized Statements, ORM, Secure Coding, Code Review - Summary: Notice that the single quote in the name O’Brien is causing a syntax error. The SQL command processor considers the string ends ### Overly Simplistic Crypto Code review - URL: https://www.securesql.info/2018/09/05/crypto-code-review/ - Date: 2018-09-05 - Topics: Cryptography, Secure Coding, Data Protection, Code Review, Encryption, HTTPS, Hashing, Security Best Practices - Summary: Confidentiality is one of Information Security ### For those who wonder what a Digital authentication cyber arms race looks like - URL: https://www.securesql.info/2018/07/11/silly-threat-modeling/ - Date: 2018-07-11 - Topics: Authentication, Cybersecurity, Browser Security, Phishing, Digital Identity, Hardware Tokens, Defense Strategies - Summary: It is heavy on the technical content but is entertaining if you spend the time understanding the language. ### First 100 Days - URL: https://www.securesql.info/2018/04/30/first-100-days/ - Date: 2018-04-30 - Topics: Infosec, Leadership, Executive Onboarding, Security Programs, Blue Team, Red Team, AppSec, Org Theory - Summary: A friend took up a new InfoSec executive career path but didn't know how to start. She reached out to me and ask for my thoughts. I thought about it ### The pending crypto singularity - URL: https://www.securesql.info/2018/01/16/crypto-singularity/ - Date: 2018-01-16 - Topics: Cryptography, Security Engineering, Protocol Design, Crypto Monoculture, IETF, Internet Security, AEAD, Curve25519, Open Source - Summary: Recently penned by Peter, it is worth a read. Especially for those who are concerned about putting all of their eggs in one basket. On the Impending Crypto Monoculture ### Creating a Loki Splunk application - URL: https://www.securesql.info/2017/10/10/loki-splunk-app/ - Date: 2017-10-10 - Topics: Threat Hunting, Incident Response, APT Detection, Open Source Security Tools, Splunk, IOC Scanning, Automation, YARA, Threat Intelligence, Windows Security - Summary: One tool that has caught my interest is the [Loki APT scanner ### Serious XSS affecting Wikipedia - URL: https://www.securesql.info/2017/09/08/wikipedia-xss/ - Date: 2017-09-08 - Topics: Vulnerabilities, Web Security, XSS, MediaWiki, Wikipedia, Disclosure, Security Patching, Manual Code Review - Summary: XSS vulnerability in thumb.php in Wikipedia Mediawiki ### Defense Against the Dark Arts - URL: https://www.securesql.info/2017/09/07/irony-is-not-lost-on-me/ - Date: 2017-09-07 - Topics: Threat Modeling, Cybersecurity, Infographics, Adversary Types, Security Awareness, Cyber Threats, Prototyping, Security Fundamentals - Summary: Thankfully, Naurus has produced a useful infographic to understand the variety of malicious entities. While it is not all inclusive, it suffices to help one quickly prototype simple threat models. ### Walking the Dark Deep Web - URL: https://www.securesql.info/2017/04/05/fall-of-an-empire/ - Date: 2017-04-05 - Topics: Dark Web, OSINT, Cybersecurity, Defcon, BsidesLV, Black Hat, Metadata Analysis, SSH Fingerprinting, Threat Intelligence, Adversary Modeling, Diamond Model, Network Forensics, Tor Hidden Services - Summary: During Black Hat, BsidesLV, and Defcon, I ended up having a chat with Justin Seitz about his nifty OSINT automation. I decided to take his data sets and enrich ### DARPA Cyber Grand Challenge era coming to a close - URL: https://www.securesql.info/2016/08/15/darpa-cyber-challenge-ending/ - Date: 2016-08-15 - Topics: Cyber Grand Challenge, DARPA, Red Teaming, Automation, Cybersecurity, CTF, AI in Security, Game Theory, Big Data Security, Security Automation, Cloud Security, Adversarial Modeling, CTF Strategy, Security Research - Summary: This Thursday, seven research institutions will compete against each other. Unlike other typical hacker challenges, their automations will compete on their behalf. The winning team will take home ### Relatively Free - URL: https://www.securesql.info/2016/03/22/freeish-services/ - Date: 2016-03-22 - Topics: Free Resources, DevOps, SaaS, PaaS, IaaS, Cloud Services, Tools for Developers, Infrastructure, Automation, Open Source - Summary: From my text library, this is list of software ### Multiple vulnerabilities in SecurityOnion - URL: https://www.securesql.info/2016/03/22/securityonion-vunlerabilities/ - Date: 2016-03-22 - Topics: SecurityOnion, Vulnerabilities, PHP Security, Remote Code Execution, Web Security, Disclosure, Exploit Development, Open Source Security - Summary: Let this be a reminder of the joys in programming PHP ### Ransomware hitting linux hosting providers - URL: https://www.securesql.info/2016/02/19/linux-hosting-ransomware/ - Date: 2016-02-19 - Topics: Ransomware, Linux, Hosting Providers, Cybersecurity, Malware, Google Trends, Incident Monitoring, Threat Intelligence - Summary: It will be interesting to watch the infection spread on Google Trends ### DARPA Cyber Grand Challenge dropbox - URL: https://www.securesql.info/2015/11/15/darpa-cyber-grand-challenge/ - Date: 2015-11-15 - Topics: DARPA, Cyber Grand Challenge, CTF, OSINT, Penetration Testing, Automation, IoT Security, Cryptoapocalypse, Security Research - Summary: I have been taking lessons learned from DARPA’s Cyber Grand Challenge and applying it to our automation ### Hotpatch Redis's RCE - URL: https://www.securesql.info/2015/08/16/redis-exploit-lua/ - Date: 2015-08-16 - Topics: Redis, RCE, Exploit Development, Memory Corruption, Lua, Vulnerability Research, Patch Management, Offensive Security, CTF - Summary: Do you feel lucky ### Ingenious CTF dashboard - URL: https://www.securesql.info/2015/07/11/polictf-2015-results/ - Date: 2015-07-11 - Topics: CTF, dashboard, infosec, PoliCTF, capture the flag, user experience, security competitions, hacking, UI design, security training - Summary: As taken from a dummy account, I wish more CTFs were setup like this. [#Polictf](https://twitter.com/search?q=%23Polictf) 2015 ### Destroy a City - secure code review - URL: https://www.securesql.info/2015/07/02/how-to-destroy-a-city-code-review/ - Date: 2015-07-02 - Topics: secure coding, software ethics, code review, professional ethics, Nathaniel Borenstein, infosec, parameterization, satire, software engineering - Summary: It should be noted that no ethically-trained software engineer would ever consent to write a DestroyBaghdad procedure ### Redis RCE - URL: https://www.securesql.info/2015/06/14/redis-rce/ - Date: 2015-06-14 - Topics: Redis, RCE, remote code execution, authentication, vulnerability, honeypot, exploit kits, patching, infosec, Shodan - Summary: If you haven't already, time to patch Redis. Otherwise, please setup authentication in front of your Redis instance. This remote code execution is going to get nasty http ### Social Engineering Confirmation Bias workflow - URL: https://www.securesql.info/2015/06/14/social-engineering-bias/ - Date: 2015-06-14 - Topics: social engineering, confirmation bias, insider threat, US-CERT, SEI, human factors, infosec, trust exploitation, feedback loops, deception tactics - Summary: The image below shows the role confirmatory bias can play in social engineering exploits. Two situations are depicted. In the first, the insider desires access to information supplied by the ### ElasticSearch honeypot dataset - URL: https://www.securesql.info/2015/06/10/elasticsearch-honeypot-tokens/ - Date: 2015-06-10 - Topics: ElasticSearch, honeypot, dataset, 0day, exploit attempts, open source security, cybersecurity, internet exposure, infosec, log analysis - Summary: I have uploaded a new ElasticSearch honeypot dataset. It appears there are a few individuals who are attempting to exploit a few 0days in ElasticSearch. All the more reason not ### Ghcq Challenge Completed - URL: https://www.securesql.info/2015/05/18/ghcq-challenge-completed/ - Date: 2015-05-18 - Topics: GCHQ, cyber challenge, puzzle solving, infosec, cryptography, intellectual challenge, capture the flag, security challenge, cybersecurity, GCHQ competition - Summary: View fullsize ### Impressive Node.JS vulnerability reduction - URL: https://www.securesql.info/2015/04/21/nodejs-security-posture-improvement/ - Date: 2015-04-21 - Topics: NodeJS, vulnerability reduction, secure coding, code review, security improvements, open source security, risk mitigation, JavaScript security, community contributions, remediation efforts - Summary: In 2013, when I last performed a secure code review on Node.JS, it did not look pretty. ### Need help figuring out a Snapchat username? I have your back. - URL: https://www.securesql.info/2015/04/15/popular-snapchat-names/ - Date: 2015-04-15 - Topics: Snapchat, username tips, social media trends, username patterns, data analysis, popular names, digital identity, user behavior, Jessica username help, Snapchat analytics - Summary: I can’t tell you what makes a good Snapchat username. But what I can tell you is what makes a popular Snapchat username. ### Yet another nail in SSL TLS 's coffin - URL: https://www.securesql.info/2015/04/14/rc4-openssl-deathsdoor/ - Date: 2015-04-14 - Topics: SSL, TLS, RC4 vulnerability, cryptographic attacks, BEAST attack, cipher suite weaknesses, man-in-the-middle, encryption insecurity, deprecated protocols, security research - Summary: RC4 has long been considered problematic, but until very recently there was no known way to exploit the weaknesses ### Technical Approaches to Determining if an Incident Occurred - URL: https://www.securesql.info/2015/04/02/infosec-ir-triaging-workflows/ - Date: 2015-04-02 - Topics: incident response, cybersecurity best practices, IOC detection, anomaly detection, host-based artifacts, network-based artifacts, threat hunting, digital forensics, incident mitigation, security monitoring, incident handling mistakes, remediation strategies, network segmentation, access control, backup and recovery, SIEM, endpoint detection, malware analysis, user education, secure configuration - Summary: When addressing potential incidents and applying best practice incident response procedures ### Checkbox AWS assurance testing? - URL: https://www.securesql.info/2015/03/20/aws-assurance-checkboxes/ - Date: 2015-03-20 - Topics: AWS security, Scout2, cloud assurance, infrastructure auditing, security posture, AWS controls, configuration assessment, cloud compliance - Summary: A great beta tool to checkbox their AWS infrastructure and account to known AWS controls. [ Scout2 ### Open Source Fairy Dust Datasets - URL: https://www.securesql.info/2015/03/20/opensource-vulnerable-metrics-relativity/ - Date: 2015-03-20 - Topics: open source insecurity, machine learning vulnerabilities, vulnerability mountain, critical infrastructure vulnerabilities - Summary: The current list of open source critical infrastructure services vulnerability metrics I have released and / or made public ### LDAP Tool Box vulnerabilities - URL: https://www.securesql.info/2014/12/01/ldap-vulnerabilities-exploits/ - Date: 2014-12-01 - Topics: LDAP Tool Box, XSS vulnerability, htmlentities weakness, web application security, proof of concept exploit, client side attacks, security patch, keylogger, vulnerability disclosure - Summary: This vulnerability allows one to bypass weak XSS filtering ### How to sell a story - Ira Glass - URL: https://www.securesql.info/2014/06/27/storytelling/ - Date: 2014-06-27 - Topics: Ira Glass, creative process, storytelling, artistic growth, overcoming self doubt, creative advice, persistence in art, closing the gap, beginner struggles, motivation for creators - Summary: If you are just starting this phase, still in this phase, getting out of this phase, you gotta know ### Please donate to a worthy crypto security cause - URL: https://www.securesql.info/2014/04/15/openssl-vulnerabilities/ - Date: 2014-04-15 - Topics: OpenSSL, Heartbleed, cryptographic security, secure code review, donate to security, open source funding, C/C++ vulnerabilities, software defects, security research - Summary: If you have ever used OpenSSL, [please donate money to this worthy cause ### Bug Age - Pattern series - URL: https://www.securesql.info/2014/04/07/bug-age-patterns/ - Date: 2014-04-07 - Topics: bug patterns, code insecurity, secure coding, software vulnerabilities, formal proofs, code correctness, legacy code, holistic security, open source security, security automation, developer tools - Summary: I love standards. My blackhat persona says this makes it easy to break into systems ### Chrome's V8 double free vulnerability - URL: https://www.securesql.info/2014/03/07/chrome-exploit-double-free-v8-engine/ - Date: 2014-03-07 - Topics: Chrome V8, double free vulnerability, memory corruption, Chromium security, vulnerability disclosure, bug bounty, V8 engine, browser security - Summary: Within Chrome's V8 engine, this was an interesting double free vulnerability I uncovered. Thank you V8 team for accepting. ### NodeJS vulnerabilities - it hurts to look - URL: https://www.securesql.info/2013/11/12/nodejs-insecurity/ - Date: 2013-11-12 - Topics: NodeJS, JavaScript security, backend vulnerabilities, vulnerability classes, defensive coding, third party package review, Shodan, open source security, NodeJS hardening - Summary: Background ### Google Translate - URL: https://www.securesql.info/2013/07/31/google-translate-breakout/ - Date: 2013-07-31 - Topics: Google Translate, web vulnerability, iframe hijacking, redirect exploit, HTML5 sandbox, web security, safe mode, security mitigation - Summary: the translated website pops out of Google Translate's iframe and redirects the user to a website or content of their choosing ### Carberp Vulnerabilities Cc Pie - URL: https://www.securesql.info/2013/06/27/carberp-vulnerabilities-cc-pie/ - Date: 2013-06-27 - Topics: Carberp, malware analysis, cryptographic vulnerabilities, RC4 encryption, md5 weaknesses, openssl misuse, application security, botnet source code, secure coding, PHP security - Summary: I logged into Reddit this morning and observed Carberp ### Random thought for an exploding honey token - URL: https://www.securesql.info/2013/06/27/exploding-honey-tokens/ - Date: 2013-06-27 - Topics: honey tokens, compressed file attacks, mail server vulnerabilities, resource exhaustion, insider threat detection, security experimentation, MTA inspection, system logs monitoring - Summary: I remember when Nuxi and I would create computationally compact compressed files and see which mail servers would attempt to inspect the contents. Typically, the MTA would fail over due ### Apache Batik parse double vulnerability - URL: https://www.securesql.info/2013/06/23/apache-batik-double-vulnerability/ - Date: 2013-06-23 - Topics: Batik vulnerability, parse double bug, Apache Batik, Opera crash, open source vulnerabilities, software security issues - Summary: It is interesting to see Batik's parse double vulnerability exist to this day. Anyone want to crash Opera or popular, open source software ### DAQ buffer overflows - URL: https://www.securesql.info/2013/06/22/cisco-sourcefire-snort-exploits/ - Date: 2013-06-22 - Topics: buffer overflows, software vulnerabilities, code analysis, security bugs, DAQ software, off-by-one error, programming errors - Summary: Sourcefire and snort vulnerabilities allow remote code execution ### Startup Comp Structure - URL: https://www.securesql.info/2013/06/05/international-contract-negotation-tips/ - Date: 2013-06-05 - Topics: startup compensation, equity compensation, executive recruitment, venture capital, cash vs stock compensation, benefits program, stock options, employee motivation, startup challenges, creative compensation strategies, benefits customization - Summary: You ### Malicious mobile power station - URL: https://www.securesql.info/2013/06/05/mobile-power-station/ - Date: 2013-06-05 - Topics: USB security vulnerabilities, smartphone security, malicious USB attacks, Stavrou's research, cybersecurity threats, social engineering - Summary: A bit back, I looked over Stavrou USB smartphone paper evil power station ### Lazy AWS devops - URL: https://www.securesql.info/2013/06/04/want-a-simple-way-to-keep-your-cloudy-big-data-private-at-little-cost/ - Date: 2013-06-04 - Topics: DevOps, agile SA, cloud security tools, automation in IT, AWS EC2, orchestration tools, configuration management, Chef, Puppet, BCFG2, Capistrano, Mcollective, data center management, infrastructure as a service, disaster recovery, system monitoring - Summary: I am seeing too much echo chamber, saber rattling, foolish dogma about agile SA ### Security is hard. Security Tools are harder. Cloud Security Tools are hardest. - URL: https://www.securesql.info/2013/05/09/cloudsec-jitiam/ - Date: 2013-05-09 - Topics: cloud security tools, security orchestration, vulnerability management, dynamic infrastructure, cloud service APIs, security tool interoperability, cloud security corporations, policy compliance, incident response, forensic investigations - Summary: There are tools, security tools, and then there are cloud security tools. Especially in the realm of security orchestration. Many cloud snake oil tools were never designed for the cloud. ### CNN.com XSS vulnerabilities - URL: https://www.securesql.info/2013/05/06/cnn-xss/ - Date: 2013-05-06 - Topics: CNN, XSS issues, security updates, web security, vulnerability fixes - Summary: CNN fixed two XSS issues. Congrats ### Google Glass Developer program - more DOS and XSS - URL: https://www.securesql.info/2013/05/03/more-google-glass-vulns/ - Date: 2013-05-03 - Topics: Google Glass, Mirror API, DOS vulnerability, XSS vulnerability, security fixes, GitHub changeset, error handling, code security, vr insecurity, ar vulnerability, augmented reality vulnerability - Summary: There were two very simple Google Glass Mirror's quickstart DOS and XSS vulnerabilities. The fixes have been introduced in changeset https ### Google Glass 0days - URL: https://www.securesql.info/2013/04/19/google-glass-vulns/ - Date: 2013-04-19 - Topics: Google Glass, software development lifecycle, vulnerabilities, DOS attacks, reflected XSS, code security, open source code, responsible disclosure, vr insecurity, ar vulnerability, augmented reality vulnerability - Summary: Jenny Murphy has some clean code. However, it isn't the most secure. The Google Glass team must be under an intense timeline. Without looking too hard into the libraries and ### Evolutionary hardware - URL: https://www.securesql.info/2013/04/17/for-technical-problems-one-may-struggle-to-define/ - Date: 2013-04-17 - Topics: evolutionary algorithms, soft computing, design automation, neural networks, ReCaptcha, Amazon Turk, pattern recognition, evolvable hardware, military applications, industrial applications, risk management - Summary: For technical problems, one may struggle to define the specifications. When this happens, look at the behavioral design. Then one may find solutions from the design automation. Thankfully, evolution algorithms ### Rapid7 Google hacks extended - URL: https://www.securesql.info/2013/04/11/site-s3-amazonaws-com-filetype-docx-password-username/ - Date: 2013-04-11 - Topics: data leakage, S3 bucket security, sensitive information, file sharing services, content delivery networks, inadvertent sharing, document security, Form W-4, Form W-9, Form 1099 - Summary: How many other file sharing services are affected by the inadvertant sharing of sensitive information ### Nifty Anti-XSS validation tool - Snuck - URL: https://www.securesql.info/2012/12/05/snucks-goal-is-to-significantly-test/ - Date: 2012-12-05 - Topics: Snuck, XSS filter testing, security tools, web security, XSS injections, reflection context - Summary: To significantly test a given XSS filter by specializing ### Firesale WebPanel botnet 0days - URL: https://www.securesql.info/2012/10/10/firesale-0days/ - Date: 2012-10-10 - Topics: Firesale WebPanel botnet, reflected XSS, DOM-based XSS, SQL injection, security vulnerabilities, web security, code sanitization, mysql_escape_string, application security - Summary: Oh, Firesale WebPanel botnet. How entertaining it is to see you continue to raise your head over the years.... XSS Reflected ### ERM - How did WOPR decide the only winning move is not to play? - URL: https://www.securesql.info/2012/10/02/a-strange-game-the-only-winning-move-is-not-to-play/ - Date: 2012-10-02 - Topics: WOPR, evolutionary algorithms, hardware simulation, intrinsic evolution, extrinsic evolution, risk modeling, reconfigurable hardware, fitness evaluation, algorithmic variations, systemic risk analysis - Summary: WOPR evolved and learned while playing against himself ### DPAPI still applicable? - URL: https://www.securesql.info/2012/09/26/ms-dapi/ - Date: 2012-09-26 - Topics: DPAPI, Microsoft security, credential protection, security vulnerabilities, encryption, data protection, Windows security - Summary: I saw some code utilizing DPAPI. Given the research around MS's poor DPAPI implementation, ### Security quotes - URL: https://www.securesql.info/2012/08/02/quotes/ - Date: 2012-08-02 - Topics: security quotes, NSA jokes, software liability, security product design, internet security, cryptography debates, Bruce Schneier quotes, government surveillance, ethical hacking, digital copyright, cryptographic anecdotes, system vulnerabilities - Summary: The present need for security products far exceeds the number of individuals capable of designing secure systems ### Management Wednesday- BPM Modeling - not charts anymore - URL: https://www.securesql.info/2012/07/15/management-wednesday-bpm-modeling-not-charts-anymore/ - Date: 2012-07-15 - Topics: business process modeling, scoping phase, UML, software engineering, probabilistic graph modeling, BlueWorks, WebSphere, multivariate analysis, business process transparency, mergers and acquisitions, operational efficiency, technology in business, modeling versus reality - Summary: After one has accomplished the scoping phase, then the team should move on to modeling. Due to the large amount of time spent scoping, many scenarios will come to light ### Microsoft revokes Microsoft's certificate - URL: https://www.securesql.info/2012/06/25/secure-cloud-hosting-fail/ - Date: 2012-06-25 - Topics: PKI private key signing, code signing vulnerability, Microsoft security breach, malicious software, system security, key revocation, cybersecurity incident - Summary: It is a sad day when a PKI private key signing software is able to sign code on behalf of Microsoft. Especially when it is found in the wild and ### Gribodemon on SpyEye 2.x - I expected better - URL: https://www.securesql.info/2012/05/29/flame-src-code-courtesy-of-anton-and-cmyu/ - Date: 2012-05-29 - Topics: application honeypot, SpyEye malware, sandbox evasion, virtualized sandbox security, insecure coding practices, buffer overflows, cryptographic flaws, command and control systems, web application vulnerabilities, XSS vulnerabilities, SQL injection, secure coding - Summary: Saturday, I noticed my application honeypot collected an interesting sample. The cracker took my bait and attempt to hack the planet via a SpyEye 2.x variant. Apparently, the limit of ### Airing one's dirty development laundry - You are doing it wrong - URL: https://www.securesql.info/2012/05/26/pastebin/ - Date: 2012-05-26 - Topics: Google alert, private key exposure, security breaches, human error, development services, credential leaks, Pastebin searches, Web Services debugging - Summary: I recieved a lovely google alert this weekend. ### Bitcoins are hard to track - URL: https://www.securesql.info/2012/05/23/fbi-crypto/ - Date: 2012-05-23 - Topics: FBI and Bitcoin, currency exchangers, Bitcoin to WebMoney, government surveillance, cryptocurrency transactions, peer to peer architecture, digital currencies, law enforcement challenges - Summary: Either FBI ### Sad reality - URL: https://www.securesql.info/2012/05/22/vendors/ - Date: 2012-05-22 - Topics: finance team gating process, vendor payments, security approval, third party cloud vendors, intellectual property risk, cloud security - Summary: hope you have a gating process in your finance team which halts the ability to pay vendors without security approval... ### Management Wednesday- BPM scoping - URL: https://www.securesql.info/2012/05/17/management-wednesday-competitor-acquires-one/ - Date: 2012-05-17 - Topics: business-process-management, project-scoping, process-models, real-time-auditing, dynamic-execution, human-capital, workflow-integration, project-management, discovery-sessions, process-modeling, integration-complexity, disruption-management - Summary: In business process management, there is no defined starting point. The solutions are transposable, adaptive, and can be set into motion regardless of the other solution's state. In project's scoping ### PHP - two simple wins and a hammer - URL: https://www.securesql.info/2012/05/15/php-two-simple-wins-and-a-hammer/ - Date: 2012-05-15 - Topics: PHP programming, learning PHP, PHP security, PHP tools, community support, PHP Hammer of Justice, safe mode, suhosin, web development humor, security best practices - Summary: I love programming in PHP. Fairly simple to learn, easy to code, plenty of tools available, and great community. However, due to the language's inherent behaviour, PHP has many security pitfalls. ### Meltdown exploits - URL: https://www.securesql.info/2012/05/02/consequences/ - Date: 2012-05-02 - Topics: Meltdown exploit, CISSP certification, ethical hacking, operating systems, hypervisor exploits, security patches, assurance testing, proof of concept - Summary: Here is an academic exercise to create the Meltdown exploit prior to publication on Jan. 9th. To keep honest with my CISSP certification, I didn't include all operating systems and ### Management Wednesday- BPM isn’t beats per minute. - URL: https://www.securesql.info/2012/04/20/are-we-there-yet-not-even-close-38841/ - Date: 2012-04-20 - Topics: business process management, management practices, change initiatives, process optimization, human error, stakeholder focus, miscommunication, process frameworks, business efficiency, agile processes, information services - Summary: I was chatting with Alexander Peters and he mentioned an interesting statistic. ### Management Wednesday - Negotation - URL: https://www.securesql.info/2012/04/07/chanage-management-management/ - Date: 2012-04-07 - Topics: management wednesday, negotiation techniques, value creation, cooperative behavior, relationship building, active listening, problem solving, negotiation strategies, Pareto Efficiency, Nash Equilibrium, fair criteria, negotiation preparation, trust in negotiations, emotional intelligence, persuasion techniques - Summary: Management 101 - Negotiating Observe yourself negotiating The more time one spends preparing is directly related to win ### Web Application Security Dojo 'grams - URL: https://www.securesql.info/2011/04/02/web-application-security-dojo-grams/ - Date: 2011-04-02 - Topics: web application security, visual aid, insecurity practices, secure coding dojo, innovative methods - Summary: While finding innovative methods to visualize various web application insecurity practices, I came across a great visual aid. Enjoy. Credit ## Optional Multimedia and live session recordings providing additional context beyond the written archive: - [Live Streams / Casting](https://www.securesql.info/casting/): Recorded security discussions and hacking sessions. - [YouTube Channel](https://www.youtube.com/channel/UCUfaf6mQgh_cX6V-SaAww1w): Conference talks and video content. - [Twitch Streams](https://twitch.tv/w8mej): Live technical sessions. - [Disclosures & Standards](https://www.securesql.info/disclosures/): Editorial standards, conflict of interest, and technical verification policies.