Perspectives on application security, cloud risk and the operational work of protecting digital services.
A technical analysis of CVE-2026-71309, a path traversal in rclone's restic-compatible REST server (rclone serve restic). A URL path starting with ../ could escape the operator's published root and read, create, overwrite, or delete objects outside it, depending on the storage backend. We break down the root cause (treating path canonicalization as containment), why the outcome depended on the backend, how exploitation worked, and the fix in rclone 1.75.0.
A practical guide to understanding internet-facing assets, ownership drift, discovery gaps, and the operational case for continuous visibility.
Where major web security controls overlap, where they stop, and how to build layered protection without assigning impossible expectations to one tool.
The browser is an execution environment, not a passive display. Learn how script trust, page changes, and outbound destinations shape client-side risk.
A technical workflow for turning domains, certificates, services, technologies, and exposures into evidence-backed attack-surface findings.
A disciplined approach to policy precedence, inspection modes, bot controls, staged enforcement, exceptions, and evidence-based tuning.
Why request volume alone is not enough, and how multiple behavioral signals support more reliable challenge, score, and blocking decisions.
How script inventory, authorization, integrity baselines, change detection, and investigation evidence support payment-page security work.
Three complementary control families for constraining browser execution, detecting script changes, and observing where page data travels.
A transparent model for combining asset churn, severity, persistence, ownership confidence, and remediation delay into one directional metric.
An original operating model for connecting exposed assets, inbound decisions, browser-side changes, and outbound behavior during triage.