Read more about the article The Cyber Resilience Act: Security Is the Product Now
Cyber Resilience Act CE mark circuit board obligations

The Cyber Resilience Act: Security Is the Product Now

From 2027 connected products without CRA-backed security lose the CE mark and the EU market. EN 303 645 already draws the floor: no default passwords, disclosure policy, update transparency. The real work is turning security into a documented lifecycle — threat models, SBOMs, tested updates — instead of a checkbox before the ceremony.

Continue ReadingThe Cyber Resilience Act: Security Is the Product Now
Read more about the article The Exposed .git Mistake We Keep Finding After 10 Years
Exposed git directory terminal session

The Exposed .git Mistake We Keep Finding After 10 Years

One curl request to /.git/HEAD hands attackers your full source, every commit ever made, deleted files, and usually a working credential. A decade of research says this mistake is not aging out. Here is the exploit chain — and the three-layer fix.

Continue ReadingThe Exposed .git Mistake We Keep Finding After 10 Years
Read more about the article HTTP Request Smuggling: One Request, Two Interpretations
HTTP request smuggling elegant envelope desync

HTTP Request Smuggling: One Request, Two Interpretations

Your front end and your back end disagree about where one request ends and the next begins. The smuggled prefix slides under the WAF, defeats the rate limiter, and poisons the cache under someone else else URL. How CL-TE and TE-CL desyncs work, and the configuration discipline that closes them.

Continue ReadingHTTP Request Smuggling: One Request, Two Interpretations