// practitioner intelligence for security operators

Covert observations
from inside the wire.

CVE research, red team methodology, healthcare security, and the practitioner's path to the CISO seat — written by someone doing the work.

CVE Research

FortiBleed: What the June 2026 Campaign Tells Us About Internet-Facing Appliance Risk

Mass credential exfiltration from internet-exposed FortiGate management interfaces. IOC analysis and a validated patch-check methodology.

8 min
CISO Track

From Block Everything to Risk-Based Enablement: Safely Deploying GenAI in a Healthcare Environment

How a block-everything security posture breaks down when the business demands GenAI — and a framework for enabling it without putting PHI at risk.

~12 min
CISO Track

Red Team Engineer to Director in a Compressed Window: What Nobody Tells You About Fast Advancement

Moving from individual contributor to security director in a fraction of the expected timeline. The struggles, the identity shift, and what I'd tell myself at the start.

~10 min
CVE Research

Client-Side Auth Bypass in Legacy AngularJS Clinical Applications

How CVE-2019-10768 prototype pollution enables authorization bypass in AngularJS 1.x — and a safe demonstration methodology for developer briefings.

~11 min
Identity

Building a TAP Verification System on Entra ID: Architecture and Lessons

Risk-scored phish-resistant identity verification with Temporary Access Passes, Teams live agent escalation, and a full RBAC admin panel.

~14 min
Healthcare

HIPAA DLP in Practice: Configuring Netskope for PHI Protection at Scale

The gap between a DLP policy document and a DLP policy that actually works in a clinical environment.

~12 min