<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>After the Code, the Structure Remains on After the Code</title><link>https://windshock.github.io/en/</link><description>Recent content in After the Code, the Structure Remains on After the Code</description><generator>Hugo -- 0.145.0</generator><language>en-US</language><lastBuildDate>Mon, 10 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://windshock.github.io/en/index.xml" rel="self" type="application/rss+xml"/><item><title>Does Hiring the World's Best Hackers Improve Security?</title><link>https://windshock.github.io/en/post/2026-08-10-does-hiring-world-best-hackers-improve-security/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-08-10-does-hiring-world-best-hackers-improve-security/</guid><description>Bringing world-class hackers and a CTF research ecosystem into an organization can make it stronger, but real security improvement requires turning offensive capability into governance and structural change.</description></item><item><title>Finding Vulnerabilities Is Not the Same as Building Attack Scenarios</title><link>https://windshock.github.io/en/post/2026-08-03-attack-path-synthesizer/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-08-03-attack-path-synthesizer/</guid><description>A practical method for modeling vulnerabilities as attacker-relevant security state transitions and combining human intuition with bounded AI search</description></item><item><title>AI Package and Container Registry Boundaries: Egress Control Architecture for AI Runtimes</title><link>https://windshock.github.io/en/post/2026-07-27-ai-package-egress-boundary-architecture/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-07-27-ai-package-egress-boundary-architecture/</guid><description>Package and container registry proxies are active trust boundaries for AI runtimes. This report turns incident evidence, public SSRF history, and runtime observations into an artifact egress control architecture.</description></item><item><title>Cryptography Guide for Practical Security Professionals</title><link>https://windshock.github.io/en/post/2026-06-16-crypto-learning-guide/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-06-16-crypto-learning-guide/</guid><description>In practical cryptography, failures often occur in the design—combining randomness, key management, operating modes, error handling, and authentication—rather than in the algorithms themselves. This post outlines criteria for auditing cryptographic implementations from the perspective of security assessors and reversers.</description></item><item><title>From a Security Development Spec for Small LLMs to Regression Tests and Fuzzing Validation</title><link>https://windshock.github.io/en/post/2026-06-08-security-spec-test-repair-fuzzing/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-06-08-security-spec-test-repair-fuzzing/</guid><description>This article explains how I split an XSS security development specification for small local models into core/verify/dev/test overlays, and what I learned while connecting LLM-based judgment to regression-test generation and Jazzer/Jazzer.js fuzzing seeds.</description></item><item><title>A Critical Reading of Structural Ethics in Cybersecurity Policy: Korea's 2025 Whole-of-Government Information Protection Plan</title><link>https://windshock.github.io/en/post/2026-05-24-structural-ethics-cybersecurity-policy-korea/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-24-structural-ethics-cybersecurity-policy-korea/</guid><description>A reading of Korea&amp;#39;s 2025 whole-of-government information protection plan through the structural parallel between the Nightingale myth and the white-hacker discourse. Policy is moving from dependence on individual ethics toward structural accountability, but the transition is not complete.</description></item><item><title>The Moment AI Truly Becomes New: Not When It Finds the Answer, but When It Rewrites the Problem</title><link>https://windshock.github.io/en/post/2026-05-24-ai-problem-reframing-cross-domain-reasoning/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-24-ai-problem-reframing-cross-domain-reasoning/</guid><description>Through the Nightingale myth, the white-hacker discourse, the Sterbenz lemma, and browser exploit reasoning, this essay argues that the real change LLMs bring lies not in knowledge retrieval but in problem reframing.</description></item><item><title>The Real Battleground of National AI Strategy Is Not Just GPU Count</title><link>https://windshock.github.io/en/post/2026-05-24-ai-national-strategy-control-plane/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-24-ai-national-strategy-control-plane/</guid><description>The decisive front in national AI strategy is not GPU count alone, but who controls and can prove the flow of data, models, agents, permissions, logs, and verification running on top of those GPUs.</description></item><item><title>An Audit Workflow Survives Only When It Absorbs Misses — Eight Reinforcements to sec-audit-static v2.0</title><link>https://windshock.github.io/en/post/2026-05-19-sec-audit-static-feedback-loop/</link><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-19-sec-audit-static-feedback-loop/</guid><description>I designed sec-audit-static workflow v2.0, ran it against a real auth-server codebase, and missed two things. This is the record of how those misses were folded back into the tool — through v2.8.</description></item><item><title>Security Controls Aren't Lacking — They're Inconvenient: Why Security Needs Customer Context</title><link>https://windshock.github.io/en/post/2026-05-11-adaptive-security-customer-context/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-11-adaptive-security-customer-context/</guid><description>Security controls already exist. The real problem is that we cannot decide which customer, at which moment, deserves how much friction. As the closing chapter of the CAPTCHA·ATO series, this post is about moving from quantity of controls to context of controls — adaptive security as an operational discipline.</description></item><item><title>Can the Market Move Governance?</title><link>https://windshock.github.io/en/post/2026-05-07-market-can-move-security-governance/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-07-market-can-move-security-governance/</guid><description>Policy is not the only thing that creates change. Once external actors — insurers, customers, supply chains, evaluation services, security SaaS — start pricing the cost, governance eventually follows.</description></item><item><title>MCP Is Repeating the History of RPC Security</title><link>https://windshock.github.io/en/post/2026-05-07-mcp-is-repeating-rpc-security-history/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-07-mcp-is-repeating-rpc-security-history/</guid><description>MCP security risks are not about prompt injection. They stem from the same configuration-to-execution escalation pattern that has plagued RPC, local security software, and CI/CD pipelines for decades.</description></item><item><title>How Do We Measure Adaptive Capability?</title><link>https://windshock.github.io/en/post/2026-05-04-adaptive-security-metrics-and-ciso-template/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-04-adaptive-security-metrics-and-ciso-template/</guid><description>To move from compliance capability to adaptive capability, what do we measure? This post proposes MTTA, MTTP, MTRS, and a minimal execution template for the field.</description></item><item><title>Supply Chain Security Does Not End with SBOM: Governing AI Development Tools and Automation Connections</title><link>https://windshock.github.io/en/post/2026-05-02-ai-development-tools-supply-chain-governance/</link><pubDate>Sat, 02 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-02-ai-development-tools-supply-chain-governance/</guid><description>AI IDEs, MCP, and automation connectors are not merely developer convenience tools. They are supply-chain assets that affect the trust path of how code is written, reviewed, and shipped.</description></item><item><title>Security Assessment Becomes a Development Process, Not an Outsourced Event</title><link>https://windshock.github.io/en/post/2026-05-01-security-assessment-as-development-process/</link><pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-05-01-security-assessment-as-development-process/</guid><description>AI-era security assessment is not primarily about reducing outsourcing cost. It is about embedding repeatable verification into the development process while separating automation candidates from human judgment.</description></item><item><title>The AI Slop Paradox: Why Triage Gets Harder When Vulnerabilities Get Easier to Find</title><link>https://windshock.github.io/en/post/2026-04-30-ai-slop-vulnerability-triage/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-30-ai-slop-vulnerability-triage/</guid><description>AI lowers the cost of finding vulnerability candidates, but it also increases low-quality reports, duplicates, and false positives. In the AI slop era, triage quality becomes the core security operation.</description></item><item><title>Why Korean Security Governance Does Not Change</title><link>https://windshock.github.io/en/post/2026-04-30-why-korean-security-governance-does-not-change/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-30-why-korean-security-governance-does-not-change/</guid><description>A game-theoretic analysis of why Korean security governance stays stuck when NIS, KISA, the Board of Audit, the security industry, CISOs, and policy agencies are each acting rationally.</description></item><item><title>Beyond CVE Response: AI-Era Vulnerabilities Move Before They Get Numbers</title><link>https://windshock.github.io/en/post/2026-04-29-after-cve-response-ai-vulnerability/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-29-after-cve-response-ai-vulnerability/</guid><description>AI-era vulnerability response cannot wait for a CVE number. Pre-CVE signals such as issues, commits, PoCs, write-ups, and patch traces now have to be mapped against internal exposure earlier.</description></item><item><title>Korean Security Governance Is Accelerating in the Wrong Direction in the AI Era</title><link>https://windshock.github.io/en/post/2026-04-26-ai-security-governance-korea/</link><pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-26-ai-security-governance-korea/</guid><description>Korean security governance in the AI era needs to change not the title of any one agency, but the behavior that evaluation rewards.</description></item><item><title>After the Code, the Structure Remains</title><link>https://windshock.github.io/en/post/2026-04-21-after-the-code-the-structure-remains/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-21-after-the-code-the-structure-remains/</guid><description>The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.</description></item><item><title>Why Security Knowledge Transfer Fails — and What to Design Instead</title><link>https://windshock.github.io/en/post/2026-04-21-security-knowledge-to-default-design/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-21-security-knowledge-to-default-design/</guid><description>An organizational design report that reframes the security–DevOps problem from failed knowledge transfer to default design, interfaces, exception handling, and alignment.</description></item><item><title>How I Turned 228 Endpoints into 5 Clusters</title><link>https://windshock.github.io/en/post/2026-04-15-security-code-clustering/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-15-security-code-clustering/</guid><description>A practical account of applying dataflow-based clustering to a real codebase — reducing 228 endpoints to 5 reviewable clusters, and finding an RCE chain in the cross-section.</description></item><item><title>Why Account Takeover Never Ends — Dismantling the ATO Supply Chain</title><link>https://windshock.github.io/en/post/2026-04-07-dismantling-ato-supply-chain/</link><pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-07-dismantling-ato-supply-chain/</guid><description>How Korea&amp;#39;s CaaS supply chain reproduces itself through the recycling loop of points, gift cards, and crypto — and why defending against it requires reading the entire behavioral network, not just the login page.</description></item><item><title>Structure Builders Will Outlast Vulnerability Finders</title><link>https://windshock.github.io/en/post/2026-04-02-security-from-sense-to-structure/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-04-02-security-from-sense-to-structure/</guid><description>18 years of vulnerability hunting distilled into one insight: the shift from individual instinct to scalable structure — and what AI means for those left standing.</description></item><item><title>The CAPTCHA That Became a Free Automatic Door for Hackers — A Bypass PoC and Defense Strategy</title><link>https://windshock.github.io/en/post/2026-03-30-captcha-bypass-poc-defense-strategy/</link><pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-03-30-captcha-bypass-poc-defense-strategy/</guid><description>A practical look at an audio CAPTCHA bypass PoC built with Playwright, Whisper, and Page-Agent, plus the login defenses that still matter after CAPTCHA falls.</description></item><item><title>Security Diagnostics Reports Die Upon Publication</title><link>https://windshock.github.io/en/post/2026-03-17-security-testing-as-code/</link><pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-03-17-security-testing-as-code/</guid><description>We point out the limitations of traditional security diagnostic reports and share the necessity and practical application cases of &amp;#39;Security Testing as Code&amp;#39;, managing diagnostic results not as &amp;#39;documents&amp;#39; but as &amp;#39;executable code (PoC)&amp;#39;.</description></item><item><title>WAF/IPS/IDS Detection Gap Analysis and Remediation Direction</title><link>https://windshock.github.io/en/post/2026-03-13-waf-ips-ids-detection-gap-analysis/</link><pubDate>Fri, 13 Mar 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-03-13-waf-ips-ids-detection-gap-analysis/</guid><description>Structural analysis of WAF, IPS, and IDS detection gaps from parsing discrepancies, with a practical remediation taxonomy.</description></item><item><title>Contracts vs Security Governance — Contracts Enforce. Governance Decides.</title><link>https://windshock.github.io/en/post/2026-02-13-contract-vs-security-governance/</link><pubDate>Fri, 13 Feb 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-02-13-contract-vs-security-governance/</guid><description>Why security governance must drive decisions before contracts enforce them—a structural reframing for security leadership.</description></item><item><title>eIDAS 2.0 vs. Korea’s Digital Identity System: A Comparative Analysis</title><link>https://windshock.github.io/en/post/2026-01-19-digital-identity-eidas2-korea/</link><pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-01-19-digital-identity-eidas2-korea/</guid><description>Comparative analysis of EU eIDAS 2.0 wallet-based identity and Korea&amp;#39;s mobile ID system across governance, privacy, and operations.</description></item><item><title>Amadey Malware: A Comparative Study of Static Detection vs Memory-Based Detection</title><link>https://windshock.github.io/en/post/2026-01-07-amadey-static-vs-memory-detection/</link><pubDate>Wed, 07 Jan 2026 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2026-01-07-amadey-static-vs-memory-detection/</guid><description>Comparing static vs memory-based malware detection using Amadey, showing why runtime YARA rules outperform file-hash approaches.</description></item><item><title>The Visibility Principle: How Internal Vulnerability Visibility Shapes Remediation Behavior</title><link>https://windshock.github.io/en/post/2025-12-29-the-visibility-principle/</link><pubDate>Mon, 29 Dec 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-12-29-the-visibility-principle/</guid><description>How transparent internal vulnerability visibility drives remediation through accountability and deterrence without formal punishment.</description></item><item><title>Attack Surface Management in 2025: Why Continuous Visibility is Essential</title><link>https://windshock.github.io/en/post/2025-12-22-attack-surface-management-in-2025-why-continuous-visibility-is-essential/</link><pubDate>Mon, 22 Dec 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-12-22-attack-surface-management-in-2025-why-continuous-visibility-is-essential/</guid><description>Why continuous attack surface management is critical in 2025, covering AI-driven discovery, shadow IT, and zero trust integration.</description></item><item><title>The Gap Between CISO Strategy and Execution: The WAF Debate and Field Leadership Report</title><link>https://windshock.github.io/en/post/2025-06-30-ciso-strategy-execution/</link><pubDate>Mon, 30 Jun 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-06-30-ciso-strategy-execution/</guid><description>A comprehensive report presenting a roadmap for practical security improvement and field leadership, centered around the debate on WAF and the gap between philosophy and execution.</description></item><item><title>The Limitations of 'Secure' SSRF Patches: Advanced Bypasses and Defense-in-Depth</title><link>https://windshock.github.io/en/post/2025-06-25-ssrf-defense/</link><pubDate>Wed, 25 Jun 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-06-25-ssrf-defense/</guid><description>A deep dive into why common SSRF defense code is often incomplete, real-world bypasses, and practical, layered mitigation strategies for developers and security engineers.</description></item><item><title>Exception Serialization Patterns in OpenStack Nova: Theoretical RCE Risks and Lessons Learned</title><link>https://windshock.github.io/en/post/2025-06-10-rce-via-exception-serialization-in-openstack-nova/</link><pubDate>Tue, 10 Jun 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-06-10-rce-via-exception-serialization-in-openstack-nova/</guid><description>Theoretical RCE risks in OpenStack Nova&amp;#39;s exception serialization via oslo.messaging, with PoC scenarios and defense patterns.</description></item><item><title>Endpoint Security Evasion (2020–2025): From EDR Bypass to EDR Kill</title><link>https://windshock.github.io/en/post/2025-05-28-endpoint-security-evasion-techniques-20202025/</link><pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-05-28-endpoint-security-evasion-techniques-20202025/</guid><description>A technical analysis of how BYOI, BYOVD, DLL hijacking, and service abuse shifted endpoint attacks from EDR bypass to EDR kill between 2020 and 2025.</description></item><item><title>SPOF in Cybersecurity: From History to Strategy, a Graph-Based Analysis</title><link>https://windshock.github.io/en/post/2025-05-15-spof-analysis-in-cybersecurity/</link><pubDate>Thu, 15 May 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-05-15-spof-analysis-in-cybersecurity/</guid><description>Graph-based analysis of Single Points of Failure in cybersecurity, using weighted path enumeration to identify critical infrastructure nodes.</description></item><item><title>Dicer Module Vulnerability Mitigation Guide: CVE-2022-24434</title><link>https://windshock.github.io/en/post/2025-05-12-cve-cve-2022-24434-dicer/</link><pubDate>Mon, 12 May 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-05-12-cve-cve-2022-24434-dicer/</guid><description>Mitigation guide for CVE-2022-24434 in the Dicer module affecting Multer and Express, with practical dependency chain fixes.</description></item><item><title>How I Managed Unmaintained Open Source with Gmail and Snyk Alerts</title><link>https://windshock.github.io/en/post/2025-05-12-managing-unmaintained-open-source-with-snyk-and-gmail/</link><pubDate>Mon, 12 May 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-05-12-managing-unmaintained-open-source-with-snyk-and-gmail/</guid><description>Automating Snyk vulnerability alert management with Google Apps Script and Gmail when official API access falls short.</description></item><item><title>Human Insight and Artificial Intelligence: Dialogue at an Impossible Crossroads</title><link>https://windshock.github.io/en/post/2025-05-07-ai-insight-vs-human/</link><pubDate>Wed, 07 May 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-05-07-ai-insight-vs-human/</guid><description>Can AI achieve enlightenment? Exploring the asymmetry between human insight and machine repetition, with technical and philosophical limits.</description></item><item><title>Detection Frameworks and Latest Methodologies for eBPF-Based Backdoors</title><link>https://windshock.github.io/en/post/2025-04-29-ebpf-backdoor-detection-framework/</link><pubDate>Mon, 28 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-29-ebpf-backdoor-detection-framework/</guid><description>How eBPF-based backdoors evade traditional detection, and modern frameworks like Tracee and LKRG that counter kernel-level threats.</description></item><item><title>In-Depth Report on Telecommunication Security: SKT Breach and Global Case Studies</title><link>https://windshock.github.io/en/post/2025-04-28-telecom-security-breach-analysis/</link><pubDate>Mon, 28 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-28-telecom-security-breach-analysis/</guid><description>In-depth analysis of the 2025 SKT breach, telecom authentication mechanisms, and 5G SA vs NSA security architecture differences.</description></item><item><title>CVE-2019-17570 Apache XML-RPC Vulnerability Analysis Report</title><link>https://windshock.github.io/en/post/2025-04-24-cve-2019-17570-apache-xmlrpc/</link><pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-24-cve-2019-17570-apache-xmlrpc/</guid><description>Technical analysis of CVE-2019-17570 deserialization RCE in Apache XML-RPC, with patch comparison and secure implementation guidance.</description></item><item><title>Is Your Data in the Cat's Paws?</title><link>https://windshock.github.io/en/post/2025-04-21-expert-personal-data-report/</link><pubDate>Mon, 21 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-21-expert-personal-data-report/</guid><description>Analysis of the 2025 KakaoPay breach exposing 40M users&amp;#39; data, and why formal consent fails without AI-based DPIA and civic oversight.</description></item><item><title>There’s No Such Thing as a Free Lunch, But Security Was Free</title><link>https://windshock.github.io/en/post/2025-04-17-theres-no-such-thing-as-a-free-lunch-but-security-was-free/</link><pubDate>Thu, 17 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-17-theres-no-such-thing-as-a-free-lunch-but-security-was-free/</guid><description>The CVE system nearly collapsed in 2025. Who should fund public cybersecurity infrastructure when free-riding is no longer sustainable?</description></item><item><title>In the AI Era, Employees Are Isolated and Organizations Thrive</title><link>https://windshock.github.io/en/post/2025-04-07-evil-management-manual/</link><pubDate>Mon, 07 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-07-evil-management-manual/</guid><description>A satirical critique of how AI-era organizations isolate employees through async workflows and data-driven control to suppress solidarity.</description></item><item><title>The Place of Humans: Declaring the Creator’s Rights in the Age of AI</title><link>https://windshock.github.io/en/post/2025-04-03-human-place-in-ai-age/</link><pubDate>Thu, 03 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-03-human-place-in-ai-age/</guid><description>A philosophical essay on human authorship and creativity in the AI era, declaring the creator&amp;#39;s rights over machine-generated output.</description></item><item><title>Common Security Myths Developers Tell Themselves</title><link>https://windshock.github.io/en/post/2025-04-01-common-security-myths-developers-tell-themselves/</link><pubDate>Tue, 01 Apr 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-04-01-common-security-myths-developers-tell-themselves/</guid><description>Debunking developer security myths around responsibility deflection, tech overconfidence, and risk underestimation with real-world examples.</description></item><item><title>How to Block ECH and Mitigate DoH in Enterprise Networks</title><link>https://windshock.github.io/en/post/2025-03-31-dnsmasq-ech-doh-block/</link><pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-03-31-dnsmasq-ech-doh-block/</guid><description>A hands-on guide using dnsmasq to filter SVCB and HTTPS records for disabling ECH and enforcing central DNS policies. Notes that DoH requires separate network-layer policies.</description></item><item><title>XML-RPC Security Vulnerabilities Analysis and Mitigation Strategies</title><link>https://windshock.github.io/en/post/2025-03-28-xml-rpc-security-vulnerabilities-analysis-and-mitigation-strategies/</link><pubDate>Fri, 28 Mar 2025 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2025-03-28-xml-rpc-security-vulnerabilities-analysis-and-mitigation-strategies/</guid><description>Comprehensive analysis of XML-RPC security flaws including RCE, XXE, and DDoS, with mitigation strategies and a Python PoC exploit.</description></item><item><title>Review of Citrix Security Policy Effectiveness</title><link>https://windshock.github.io/en/post/2024-11-05-review-of-citrix-security-policy-effectiveness/</link><pubDate>Tue, 05 Nov 2024 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2024-11-05-review-of-citrix-security-policy-effectiveness/</guid><description>Citrix administrators apply security policies to each user’s VDI (Virtual Desktop Infrastructure) through Citrix Group Policy. However, certain structural vulnerabilities in Citrix CSE (Citrix Service Engine) and the Citrix VDI Agent allow for potential bypassing of these security policies.</description></item><item><title>KPIs Can Cause Incidents!!!</title><link>https://windshock.github.io/en/post/2024-06-20-kpi-causes-accidents/</link><pubDate>Thu, 20 Jun 2024 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2024-06-20-kpi-causes-accidents/</guid><description>Real cases where manipulated KPI metrics led to cybersecurity incidents, exposing the dangers of metric-driven security management.</description></item><item><title>Common Misconceptions of Security Assessors</title><link>https://windshock.github.io/en/post/2024-06-16-common-misconceptions-of-security-assessors/</link><pubDate>Sun, 16 Jun 2024 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2024-06-16-common-misconceptions-of-security-assessors/</guid><description>Three common misconceptions that weaken security assessments and strategies to build repeatable, effective vulnerability evaluation.</description></item><item><title>Can Development Culture Influence Security Levels?</title><link>https://windshock.github.io/en/post/2024-05-22-can-development-culture-influence-security-levels/</link><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2024-05-22-can-development-culture-influence-security-levels/</guid><description>Exploring how development culture shapes code security, with practical examples using static analysis tools like Joern.</description></item><item><title>Bypassing citrix policy is not a vulnerability, but it can be a violation of the law</title><link>https://windshock.github.io/en/post/2023-04-27-bypassing-citrix-policy-is-not-a-vulnerability-but-it-can-be-a-violation-of-the-law/</link><pubDate>Thu, 27 Apr 2023 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2023-04-27-bypassing-citrix-policy-is-not-a-vulnerability-but-it-can-be-a-violation-of-the-law/</guid><description>How Citrix VDI policies can be bypassed via registry manipulation—a legal risk analysis with detection and mitigation strategies.</description></item><item><title>Strengthening cybersecurity through government ngos and bug bounty programs</title><link>https://windshock.github.io/en/post/2023-04-18-strengthening-cybersecurity-through-government-ngos-and-bug-bounty-programs/</link><pubDate>Tue, 18 Apr 2023 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2023-04-18-strengthening-cybersecurity-through-government-ngos-and-bug-bounty-programs/</guid><description>How government NGOs and bug bounty programs strengthen cybersecurity, with insights on security taxes and public-private collaboration.</description></item><item><title>Security threats and mitigation strategies for java reflection</title><link>https://windshock.github.io/en/post/2019-09-03-security-threats-and-mitigation-strategies-for-java-reflection/</link><pubDate>Tue, 03 Sep 2019 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2019-09-03-security-threats-and-mitigation-strategies-for-java-reflection/</guid><description>The **Java Reflection API** is a powerful tool that allows dynamic manipulation of classes, methods, and interfaces at runtime. However, due to its flexibility, it introduces significant security risks, as attackers can exploit it to gain unauthorized access to systems. In this article, we will explore the security threats posed by Java Reflection and outline strategies to mitigate these risks.</description></item><item><title>About the XSSAudit</title><link>https://windshock.github.io/en/post/2019-08-08-about-the-xssaudit/</link><pubDate>Thu, 08 Aug 2019 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/post/2019-08-08-about-the-xssaudit/</guid><description>Why Google removed XSSAudit from Chrome and what it means for web security—analyzing the shift from XSS filters to CSP.</description></item><item><title>About</title><link>https://windshock.github.io/en/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://windshock.github.io/en/about/</guid><description>This site tracks how security findings become durable change across code, method, and governance.</description></item></channel></rss>