Oodufuwababajide77inkay-security-labs.hashnode.dev·2d ago · 4 min read Why CVSS Isn't a Measure of RiskWhen a new critical CVE drops, security teams often rush to patch any system with a 9.0+ CVSS score. However, prioritizing vulnerability remediation strictly by its Common Vulnerability Scoring System00
MLManju Lalwaniinmavericksec.hashnode.dev·Aug 16 · 4 min readTRACE — Enterprise Risk Closure FrameworkA structured loop for moving from alert closure to risk closure in enterprise SOC operations. Applies to findings closed as false positives, expected activity, or benign behaviour where the underlying00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 4 · 5 min readIm Not A Full Stack Ten Year Senior... But Who Cares? I'm Not a Full-Stack Developer — and It Stopped Mattering. I'll open with the receipt, since that's the currency around here: six months ago I couldn't read a conditional. Today I ship security toolin00
SMScott McMahaninaitransformeronline.hashnode.dev·Jul 2 · 2 min readAI SecOps AutomationAI is transforming security operations by helping organizations detect threats faster, reduce manual work, and improve incident response. As alert volumes continue to grow, security teams need automat00
WWhatDoesKmean?inloggar.hashnode.dev·Jun 8 · 3 min readHow a single OOTB macro can cause massive Alert Fatigue If you use CrowdStrike Falcon, you're probably familiar with the built-in macros designed to save us time. But lately, our team was chasing down a string of persistent false positives from the default00
OOmnithiuminomnithium.hashnode.dev·Jun 1 · 15 min readSecuring the Agent Fleet: How Agentic AI Powers Autonomous AISecOpsThe Blind Spot in Enterprise AI Security Can your SIEM detect a prompt injection that tricks an agent into exfiltrating data? It can't. And that's the problem. Traditional security operations tools we00
KBKrishna Bagalinblog.krishnabagal.com·May 27 · 8 min readI Built an Open-Source Vulnerability Scanner with a Real-Time Dashboard — Because Nothing Else Did It AllThe Problem That Started It All If you run servers, write code, or manage containers, you already know the uncomfortable truth: vulnerabilities, exposed secrets, and misconfigurations are everywhere. 93KVS
SMSubhanshu Mohan Guptainblogs.subhanshumg.com·May 11 · 11 min readThe agentic SOC is hereThree vendor agentic-SOC platforms in Q1 2026. One platform-engineering charter that decides whether they work. Microsoft Sentinel AI shipped. Splunk Agentic SOC launched at RSAC. Google SecOps and T60
EAErdem Arslaninerdem.work·Mar 8 · 6 min readBuilding a Deterministic Security Buffer for Modern APIsMost security tooling for APIs forces teams into a bad choice. Either you put a decision-heavy control directly in the runtime path and accept the risk that security logic becomes an availability prob00
OAOgaga Agofureinblog.gagofure.com·Feb 16 · 2 min read🔐 Small Misconfigurations, Big ConsequencesIn security engineering, it's rarely the complex systems that bring organisations to their knees. More often, the real damage starts with something deceptively small: a missing IAM policy, an outdated dependency, a misconfigured firewall rule. These ...00