• 11 Sep 2026

    I pen tested a web app built with Claude Code…The real security risks weren’t in the code.

    The barrier to building software has collapsed. I’m starting to see the security consequences firsthand. A couple of months ago, I tested a web application built entirely with Claude Code. An application handling sensitive financial data. No traditional dev team. No large engineering processes. Just people with a clear vision iterating with AI until the application did what they wanted. A few years ago, that wouldn’t have made any sense. ...

    Continue Reading...
  • 28 Feb 2024

    3 resources to help with the SEC’s cybersecurity ruling on incident reporting

    There's been a lot of buzz in recent months regarding the new US Securities and Exchange Commission (SEC) cybersecurity ruling involving incident resporting. Check out the following resources I created for the folks at web application and API vulnerability scanning vendor Probely. We help you cut through the noise and understand what really matters in the context of incident reporting/response and, especially, its impact on overall application security. SEC Cybersecurity ...

    Continue Reading...