What is a Vibe Coding Harness?
Research LocalStack Feature / Capability LocalStack Floci Primary Purpose AWS cloud service emulation for local development/testing Lightweight AWS emulator focused on speed and open-source usage License Business Source License (BSL) / restricted community model MIT License Open Source Partially Fully Auth Token Required Yes for newer community usage models No Free Tier Restrictions Increasing restrictions/features… Continue reading What is a Vibe Coding Harness?
Using LLMs for Application Security
DevSecOps Pipeline to Run Time security DevSecOps — Security Capabilities AI Autofix Static Code Analysis (SAST) Secrets Detection Malware Protection AI Autofix Infrastructure as Code Code Quality Containers AI Autofix Open Source Dependencies (SCA) Open Source License Risks Outdated Software Cloud & K8s Posture Management Virtual Machine Scanning Container & K8s Runtime Scanning AI Pentesting… Continue reading Using LLMs for Application Security
CAMLIS (Conference on Applied Machine Learning in Information Security)
CAMLIS (Conference on Applied Machine Learning in Information Security) is an independent, practitioner-focused cybersecurity conference dedicated to the real-world application of machine learning and artificial intelligence in information security. CAMLIS brings together researchers, security practitioners, and industry professionals from academia, government, and the private sector to share applied research, operational case studies, and field-tested techniques.… Continue reading CAMLIS (Conference on Applied Machine Learning in Information Security)
MITRE ATLAS Matrix Overview
The ATLAS Matrix is part of MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems), a knowledge base that documents how adversaries can attack AI and machine-learning (ML) systems across their full lifecycle. It applies the same structured, adversary-centric approach used by MITRE ATT&CK, but is purpose-built for AI systems. The matrix organizes real-world and theoretical… Continue reading MITRE ATLAS Matrix Overview
ISO/IEC 42001: Implementing an Artificial Intelligence Management System (AIMS)
Executive summary ISO/IEC 42001 is the first international management system standard dedicated to artificial intelligence. It provides a structured, auditable framework to govern AI systems across their lifecycle. For organisations using AI in production, the standard addresses growing regulatory pressure, operational risk, and accountability expectations by embedding AI governance, risk management, and continual improvement into… Continue reading ISO/IEC 42001: Implementing an Artificial Intelligence Management System (AIMS)
What Is security.txt and Why It Matters for Websites
The security.txt file is a standardized mechanism that allows organizations to clearly communicate how security vulnerabilities should be reported for their website or online service. It acts as a single, authoritative source of truth for security researchers, ethical hackers, and automated tools looking to disclose vulnerabilities responsibly. Purpose of security.txt The primary goal of security.txt… Continue reading What Is security.txt and Why It Matters for Websites
Understanding Bash Reverse Shells and Port Listeners
Reverse shells are a common technique in penetration testing to gain remote interactive access to a machine. They rely on the target system initiating an outbound connection to an operator-controlled host. One of the simplest examples uses Bash and the /dev/tcp interface. What the Command Does This command tells Bash to: When successful, the remote… Continue reading Understanding Bash Reverse Shells and Port Listeners
Lightboard Effect using Wacom
You can create a lightboard effect in Zoom using a Wacom tablet through two primary methods: using the built-in Zoom Whiteboard feature for simple digital inking, or by using Open Broadcaster Software (OBS) Studio with a physical lightboard for a professional “transparent glass” effect. and use Picture-in-Picture Mode. You can purchase your own, or do this virtually for better… Continue reading Lightboard Effect using Wacom
Threat Modelling Manfiesto
Introduction Threat modelling enables security teams to answer four core questions: This process helps organizations reduce risk, demonstrate due diligence, improve controls, and ensure readiness if a breach occurs. 1. What Are We Working On? This stage defines context and establishes the scope of the analysis. Frameworks and Methodologies Common threat modelling methods include: Identify… Continue reading Threat Modelling Manfiesto