How We Turned 'Are We Affected?' Into a Five-Minute Answer
How we went from "which repo uses this library?" being a two-day fire drill to a five-minute query — and what we're building next.
I'm Yogendra. I started out breaking into systems for a living — red team, exploits, the whole "try harder" grind — before switching sides to defend a fintech platform used by millions. These days I spend more time reading pull requests than writing exploits, but the instinct is the same: find the flaw before someone with worse intentions does. This is where I write down what that actually looks like — the wins, the near-misses, and the things nobody puts in a case study.
Secure design, threat modeling, and the gap between "secure on paper" and production.
Exploitation, tooling and adversary tradecraft, explained from first principles.
Building and tuning detections that survive contact with a real attacker.
CI/CD security, SAST/SCA, SBOM and supply chain security embedded into the pipeline.
Catching risk in design and code review, before it ever reaches production.
IAM, WAFs, CSPM and hardening AWS/GCP environments at scale.
Turning manual triage and reviews into fast, repeatable, in-workflow tooling.
Prioritization, tradeoffs, and building security programs that scale with the business.
How we went from "which repo uses this library?" being a two-day fire drill to a five-minute query — and what we're building next.
From attack surface to audit trail — what actually matters, and what you can skip.
Posts grouped by topic, for going deeper on one area at a time.
No spam, no fluff — just deep-dives on security engineering when they're published.
Free forever. Unsubscribe anytime.