Blog

Field notes for building safer software.

Public-safe writing on product security, offensive practice, AI-assisted security work, and the craft of communicating risk clearly.

HTB CWEE: Course And Certification Review

My experience with Hack The Box's Senior Web Penetration Tester path and CWEE exam, including the course, exam timeline, reporting, and lessons learned.

Web SecurityOffensive SecurityCertification

Product Security Engineers Should Practice Exploitation

Exploitation practice is not theater. It is how defenders learn which assumptions fail, what evidence matters, and how to recommend fixes engineers can use.

Product SecurityOffensive SecuritySecure Engineering

How I Use AI To Open New Paths In Vulnerability Research

AI can surface useful vulnerability research paths when you give it context, steer the work, and validate the evidence yourself.

AI SecurityVulnerability ResearchProduct Security

MCPs And Agent Skills Are A Supply Chain Problem

Useful automation still needs provenance, review, least privilege, and an assumption that helpful tools can be hostile.

AI SecuritySupply Chain

AI Can Speed Up Security Work, But It Cannot Replace Judgment

AI is useful as acceleration. It still needs context, validation, and a human willing to say no.

AI SecurityAppSec

How Hands-On Exploitation Made Me Better At Product Security

Offensive practice helps defenders reason about product behavior, not just vulnerability categories.

Product SecurityOffensive Security