ブログ

blog

writeups from four primary tracks.

9 posts
  1. 25 September 2026
    cybersecurity

    Close Your Eyes and Verify

    An AI agent had valid credentials and still deleted a production database mid-freeze. What if being allowed to act had to be proven, every time, without ever revealing the secret?

  2. 24 September 2026
    cybersecurity

    AI Against AI in the Inbox

    Phishing got good because attackers started using AI to write it. What happens when you fight back with AI of your own, and where does it still fall short?

  3. 6 August 2026
    cybersecurity

    Getting in tune with bash

    I thought I already knew bash. Turns out knowing and doing don't share a zip code.

  4. 25 May 2026
    cybersecurity

    From Three Years of Sales to Junior Pentester: Notes From a Career Pivot

    Three years in sales, training for a different career after hours. Here's what the jump actually looked like.

  5. 18 May 2026
    home lab

    Building a Personal Second Brain With Obsidian and Claude Code

    I curate the sources. An LLM agent does the reading, the summarising, and the bookkeeping. Six months in, here's what actually held up.

  6. 10 May 2026
    full-stack

    From PHP and Bootstrap to Next.js and Tailwind

    PHP isn't dead. I'm leaving it anyway, and it's not for the reason you'd guess.

  7. 2 May 2026
    full-stack

    PHP Patterns That Actually Hold Up Under a Pentest

    I spent a year writing PHP, then a year breaking it. Most of what I wrote didn't survive the second half.

  8. 22 April 2026
    cybersecurity

    ZAP Fuzzer vs. Burp Intruder for Anti-CSRF Token Brute-Force

    Burp is the default. It stops being the right one the moment a login form rotates its CSRF token on every request.

  9. 15 April 2026
    cybersecurity

    From One SQL Injection to a Root Shell on bWAPP

    One error-based SQLi parameter. That's all it took to walk out with a root shell.