Rrathsarainrr-cyber.hashnode.dev·1d ago · 19 min readOpenID Connect: The Identity Layer OAuth Was MissingBy the time I actually heard the word OIDC, I'd already been through OAuth and PKCE conversations I hadn't fully understood, years apart from each other, and this one arrived even later than those. It00
Rrathsarainrr-cyber.hashnode.dev·Aug 15 · 10 min readWhat We Got: From Cloud Security Platform to Operational CapabilityA few months after the operationalizing work covered in the last article, it stopped being a project. It became part of how we worked. This article is about what changed once that happened. The Metri00
Rrathsarainrr-cyber.hashnode.dev·Aug 14 · 31 min readUnderstanding OAuth 2.0: Delegation, Grant Types, and the Attacks That Actually HappenThe first time I heard the term OAuth, I didn't know what it meant. I was in a conversation with a DBA lead about something adjacent to authentication and authorization, and he mentioned, almost in pa00
Rrathsarainrr-cyber.hashnode.dev·Aug 6 · 15 min readIdentity Foundations: Everything Before OAuthBefore any protocol makes sense on its own terms, a few things underneath it need to be settled first: what authentication and authorization actually are as distinct concepts, how identity gets carrie13N
Rrathsarainrr-cyber.hashnode.dev·Aug 5 · 9 min readIdentity Was the Gap I Did Not Know I HadI had worked across cloud security engineering, vulnerability assessment, penetration testing, and application security. I had reviewed IAM configurations across multiple cloud platforms, flagged over11N
HSHarshal Shahindelvingwithharshal.hashnode.dev·Jul 28 · 7 min readRAG Security: Threats, Attack Vectors, and Best Practices for Enterprise AIRetrieval Augmented Generation (RAG) has become the backbone of enterprise AI applications, enabling Large Language Models (LLMs) to provide accurate, context aware responses using organizational data00
Rrathsarainrr-cyber.hashnode.dev·Jul 22 · 9 min readEverything Passed. Then the End-to-End Ping Failed.I dedicated my final year project to an unsung hero. Stanislav Petrov, the Soviet lieutenant colonel who prevented nuclear war by deciding not to trust a system that told him it was certain. My superv10
Rrathsarainrr-cyber.hashnode.dev·Jul 19 · 8 min readI Built What I Thought Was a Secure App. Here's Everything I Got Wrong.During the final year of my undergraduate studies, my team submitted a cloud-based banking application as part of our Network and Cloud Security coursework. We had competition. Two other teams were bu10
Rrathsarainrr-cyber.hashnode.dev·Jul 18 · 14 min readOperationalising It: Making Prisma Cloud Actually UsefulAfter the Rollout: The Work That Actually Starts Deploying Prisma Cloud took months. Making it operational took longer. By the time CWPP was live across OCI and GCP and CSPM was covering all four clou11N
Rrathsarainrr-cyber.hashnode.dev·Jun 26 · 17 min readThree Vendors, One Verdict: Evaluating CSPM and CWPP at Enterprise ScaleA Note Before This Goes Further Everything in this article reflects a specific environment: an OCI-majority estate, thirty compartments, fifty-plus business units, and compliance obligations across IS10