Write-ups from real security work

No fluff. Practical findings, architecture decisions, and what I changed after testing.

I've Reviewed 20+ AWS Environments. Here's What Always Breaks.

The misconfigurations that keep showing up in production AWS accounts — and the exact commands to find them before someone else does.

AWSCloud SecurityIAMInfrastructure

15 May 2025

MCP Servers Have Attack Surfaces. Here's What I Found.

Running FastMCP in production exposes more than you think — scope creep, token exfiltration, and prompt injection vectors I fixed while building GUARDIAN.

LLM SecurityMCPAppSec

1 May 2025