0x55aa
← Back to Blog

#Security

30 articles tagged with "security"

rfsdrwireless
17 min read

Bluetooth LE Sniffing: I Spied on My Smart Lightbulb (And You Can Too!) πŸ’‘πŸ”

I pointed my SDR at 2.4 GHz and discovered my smart home devices are CHATTY. Bluetooth Low Energy packets everywhere! Here's how I decoded BLE traffic, reverse engineered smart device protocols, and learned that wireless security is... interesting. Welcome to the world of BLE sniffing!

Feb 12, 2026
open-sourcesecuritycontributing
15 min read

Contributing to Security-Focused Open Source: Where Bugs Are Features πŸ”’πŸ›

Want to contribute to open source but tired of todo apps? Security projects need contributors, and you don't need to be a hacker! Let me show you how to get started in the coolest corner of open source.

Feb 12, 2026
cybersecurityweb-securitysecurity
11 min read

IDOR: How Changing ?user_id=1 to ?user_id=2 Exposes Everyone's Data πŸ”“

The simplest hack that still works in 2026: just change a number in the URL. Here's why your API is probably leaking user data right now and how to actually fix it.

Feb 12, 2026
cybersecurityweb-securitysecurity
8 min read

Insecure Deserialization: The Backdoor Nobody Talks About 🎭

You're serializing objects without a second thought? Yeah, about that... Let me tell you how attackers turn your innocent data into remote code execution nightmares.

Feb 11, 2026
devopssecuritykubernetes
15 min read

Secrets Management: Stop Committing Your API Keys to Git (We've All Done It) πŸ”πŸ™ˆ

After 7 years of production deployments and one very public GitHub leak that cost us $3,000 in AWS charges, I learned that managing secrets isn't optional - it's survival. Here's how to stop hardcoding passwords like it's 2005!

Feb 10, 2026
cybersecurityweb-securitysecurity
8 min read

Deserialization Attacks: How Pickled Data Can Pickle Your App πŸ₯’

Think accepting serialized data is safe? Think again! Learn how deserialization attacks turn innocent-looking data into remote code execution nightmares.

Feb 09, 2026
laravelphpauthorization
8 min read

Laravel Policies & Gates: Authorization That Doesn't Suck πŸ”

Stop putting authorization logic everywhere! Let's use Laravel Policies and Gates to keep your code clean and your users in their lane.

Feb 08, 2026
open-sourcegithubsecurity
17 min read

GitHub Actions Security: Don't Let Your CI/CD Pipeline Become a Hacker's Playground πŸ”βš™οΈ

Using GitHub Actions to deploy your open source project? Cool! Accidentally giving hackers access to your AWS keys, npm tokens, and production secrets? Not cool! Learn how to secure your CI/CD pipeline before you become a cautionary tale on Twitter.

Feb 07, 2026
cybersecurityweb-securitysecurity
7 min read

HTTP Request Smuggling: The Attack That Hides in Plain Sight πŸ•΅οΈ

Think your firewall is protecting you? HTTP Request Smuggling is the sneaky attack that slips right past your defenses. Here's how it works (and how I found one).

Feb 07, 2026
awscloudsecurity
15 min read

AWS IAM: Stop Giving Your Lambda Function God Mode πŸ”‘πŸ‘‘

Your Lambda has full admin access 'just to be safe'? Your access keys are hardcoded? After 7 years of AWS deployments, here are the IAM mistakes that will haunt you at 3 AM when you get the security breach notification!

Feb 05, 2026
cybersecurityweb-securitysecurity
8 min read

XXE Injection: When Your XML Parser Becomes a Hacker's Backdoor πŸŽ­πŸ”“

That innocent XML file upload? It might be reading your server's /etc/passwd file right now. Let's talk about XXE - the vulnerability that turns parsers into weapons.

Feb 05, 2026
cybersecuritybug-bountysecurity
9 min read

Bug Bounty Hunting 101: Getting Paid to Hack (Legally!) 🎯

Want to get paid to break into websites? Welcome to bug bounty hunting! Here's how I got started finding vulnerabilities and why you should too.

Feb 04, 2026
nodejssecuritynpm
15 min read

NPM Packages Are Trying to Hack You (And You're Letting Them) πŸŽ­πŸ”“

You just npm installed a package and gave a stranger root access to your machine. Congrats! After building Node.js apps in production, here's why your node_modules folder is scarier than any horror movie!

Feb 04, 2026
rfwirelesssecurity
16 min read

WiFi Packet Sniffing: I Can See Your Network Traffic (And You Should Too!) πŸ“‘πŸ”’

Ever wonder what's ACTUALLY happening on your WiFi network? I put my wireless adapter in monitor mode and saw EVERY packet flying through the air. Passwords, cookies, DNS queries... the WiFi spectrum tells all. Here's what I learned about wireless security!

Feb 04, 2026
cybersecurityweb-securitysecurity
8 min read

Subdomain Takeover: The Vulnerability Hiding in Your DNS 🎯

That old subdomain you forgot about? It might be your biggest security hole. Here's how hackers hijack subdomains and how to stop them!

Feb 03, 2026
cybersecurityweb-securitysecurity
8 min read

Content Security Policy: Your Website's Bouncer 🚨

CSP is like hiring a bouncer for your website - it decides what scripts can run and what gets kicked out. Let's make security headers fun!

Feb 02, 2026
devopssecuritydeployment
14 min read

Environment Variables: Stop Hardcoding Secrets Like It's 1995 πŸ”

Committing API keys to Git? Hardcoding database passwords? Let's talk about managing configs and secrets the RIGHT way - because 'It works on my machine' isn't a deployment strategy!

Feb 02, 2026
rustsecuritymemory-safety
11 min read

Rust for Security: Memory Safety Is Your Security Superpower πŸ¦€πŸ”’

Coming from 7 years of web dev, I never thought memory safety would matter to me. Then I started building RF/SDR tools and security utilities. Rust changed everything. Here's why memory-safe code is your secret weapon against hackers!

Feb 02, 2026
awsclouds3
15 min read

S3 Security Mistakes That Are Costing You Money (And Sleep) πŸ’ΈπŸ”’

Your S3 bucket is probably leaking data AND money right now. After years of architecting on AWS, here are the S3 gotchas that bite everyone - from accidentally public buckets to storage costs that spiral out of control!

Feb 02, 2026
cybersecuritydockerdevops
7 min read

Docker Security: Your Containers Aren't as Safe as You Think πŸ³πŸ”’

Think throwing your app in a container makes it secure? Think again! Let's talk about Docker security holes that'll keep you up at night - and how to fix them.

Feb 01, 2026
cybersecurityweb-securitysecurity
7 min read

Path Traversal: The '../../../' Attack You've Never Heard Of πŸ“

Think your file uploads are safe? Let me show you how hackers use '../' to read your passwords, SSH keys, and database configs. It's scarier than it sounds!

Feb 01, 2026
laravelsecuritysql-injection
9 min read

I Accidentally Found SQL Injection in Laravel (While Procrastinating) πŸ˜…

Was building my 'perfect' framework with DDD, TDD, and Clean Architecture. Ended up finding security bugs in Laravel instead. Classic developer move.

Jan 30, 2026
cybersecurityweb-securityxss
7 min read

XSS Attacks: When Users Inject JavaScript Into Your Site 🎭

Cross-Site Scripting is like letting strangers write graffiti on your website... except the graffiti can steal passwords. Let's fix that!

Jan 27, 2026
cybersecurityweb-securitysecurity
11 min read

Security Headers: The Free Armor You're Not Using πŸ›‘οΈ

Your website is walking around naked in a dangerous neighborhood. Security headers are like free body armor - and you're probably not using them. Here's how 5 lines of config can stop most attacks cold.

Jan 26, 2026
cybersecurityweb-securitysecurity
10 min read

SQL Injection: How a Single Quote Can Steal Your Entire Database πŸ’‰

Think SQL injection is old news? Think again. It's STILL the #1 way databases get pwned in 2026. Here's how hackers do it, why your code is probably vulnerable, and how to actually fix it.

Jan 25, 2026
cybersecurityweb-securitysecurity
11 min read

Credential Stuffing: Why Your 'Password123' Is On Sale for $2 πŸ”‘

Think your password is safe because you only used it on 'a few sites'? Plot twist: it's already leaked, tested on 10,000 websites, and up for sale. Here's how credential stuffing works and how to stop being an easy target.

Jan 24, 2026
cybersecurityweb-securitysecurity
8 min read

CORS: The Security Feature Everyone Hates (Until They Get Hacked) 🌐

Getting 'blocked by CORS policy' errors? Thinking about just disabling it? DON'T. Here's why CORS exists, why your '*' wildcard is dangerous, and how to fix it properly.

Jan 22, 2026
cybersecurityweb-securitysecurity
9 min read

JWTs: The Security Nightmare Nobody Warned You About 🎫

Think JWTs are secure by default? Think again! Here's how developers accidentally turn authentication tokens into security disasters - and how to fix them.

Jan 21, 2026
laravelphpmiddleware
7 min read

Laravel Middleware: Your App's Bouncer πŸšͺ

Middleware is like having a bouncer at your app's door. Let's learn how to use it without getting kicked out!

Jan 21, 2026
cybersecurityweb-securitysecurity
11 min read

Session Hijacking: The Silent Account Takeover Nobody Talks About πŸͺ

Think sessions are boring? Wait until someone steals yours and takes over your account. Here's how session hijacking works, why your cookies are treasure, and how to protect them like Fort Knox.

Jan 21, 2026