Independent writing · Security engineering

Ideas for building a more secure web.

Writing on advanced web security, proactive security engineering, AI, and secure-by-design architecture.

Latest writing

View the archive
AISec EN

The Reality Shift in Vulnerability Management

The Signal Behind the Noise Skepticism toward AI security announcements is reasonable. The industry has seen enough hype. But this shift is not about positioning. It is about volume, capability, and what you can measure…

Read article
blackhat trainings
AppSec EN

Announcing My Black Hat USA 2026 Trainings

Last year at DEF CON 33, I ran a 4-hour workshop on browser defenses. The response afterwards was incredibly motivating. Many participants told me two things: this was the kind of training they wished had existed earlier…

Read article
AppSec EN

Recap of Hacker Summer Camp 2025

Two weeks after DEFCON, I’m still buzzing from an unforgettable week in Vegas — one that kicked off at the Tuscany for my very first BSidesLV. And wow, what an experience. In this recap, I’ll take you through: BSidesLV…

Read article