<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Kodesec Blog</title><link>https://kodesec.com/blog</link><description>Security-first engineering, offensive testing and an open security academy.</description><language>en</language><item><title>DevOps for Business: Resilient Infrastructure</title><link>https://kodesec.com/blog/devops-for-business-resilient-infrastructure</link><guid>https://kodesec.com/blog/devops-for-business-resilient-infrastructure</guid><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Cloud &amp; DevOps</category><description>DevOps is the discipline that turns your technology from a fragile, manual process into a repeatable, observable, and recoverable system.</description></item><item><title>Broken Access Control: The #1 OWASP Vulnerability That Can Sink a Business</title><link>https://kodesec.com/blog/broken-access-control-business-guide</link><guid>https://kodesec.com/blog/broken-access-control-business-guide</guid><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><category>Application Security</category><description>Broken Access Control is the digital version of a hotel key card that accidentally opens every room in the building instead of just one.</description></item><item><title>Claude Code, Decoded: The Full Project Structure of an Agent-Ready Repo</title><link>https://kodesec.com/blog/claude-code-decoded-project-structure</link><guid>https://kodesec.com/blog/claude-code-decoded-project-structure</guid><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>Engineering</category><description>Most people dump everything into one CLAUDE.md. The real power is in the structure. Here's how rules, commands, skills, agents, and hooks turn a repo into something you can actually direct, not just prompt.</description></item><item><title>Bangladesh's Data Breach Crisis: Every Major NID Leak From 2023 to 2026, and Why the New Law Still Won't Stop the Next One</title><link>https://kodesec.com/blog/bangladesh-nid-data-breach-2026</link><guid>https://kodesec.com/blog/bangladesh-nid-data-breach-2026</guid><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>Breach Analysis</category><description>Bangladesh's NID database has been leaked or resold at least seven times since 2023. A comprehensive breakdown of every major leak from 2023 to 2026, the 'shadow copy' problem, and analysis of the new Data Protection Act.</description></item><item><title>The Cost of Assuming Your Network Is Secure</title><link>https://kodesec.com/blog/the-cost-of-assuming-your-network-is-secure</link><guid>https://kodesec.com/blog/the-cost-of-assuming-your-network-is-secure</guid><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>Network Security</category><description>Why flat networks and over-trusted perimeter devices make breaches catastrophic — and what SMEs can do about it.</description></item><item><title>GitHub RCE Vulnerability (CVE-2026-3854): How a Single Git Push Could Compromise Millions of Repositories</title><link>https://kodesec.com/blog/github-rce-cve-2026-3854-git-push-exploit</link><guid>https://kodesec.com/blog/github-rce-cve-2026-3854-git-push-exploit</guid><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>Vulnerability Research</category><description>A critical GitHub vulnerability (CVE-2026-3854) allowed attackers to achieve remote code execution using a single git push. Learn how the exploit works, its impact on GitHub Enterprise Server, and how to protect your systems.</description></item><item><title>Shwapno Data Breach 2026: 4 Million Customers Exposed in Major Bangladesh Cyberattack</title><link>https://kodesec.com/blog/shwapno-data-breach-2026</link><guid>https://kodesec.com/blog/shwapno-data-breach-2026</guid><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>Breach Analysis</category><description>A detailed analysis of the Shwapno data breach impacting 4 million customers in Bangladesh. Explore the attack timeline, ransomware links, root causes, and key security lessons.</description></item><item><title>Vercel OAuth Breach (April 2026): How a Supply Chain Attack Exposed Customer Secrets</title><link>https://kodesec.com/blog/vercel-oauth-breach</link><guid>https://kodesec.com/blog/vercel-oauth-breach</guid><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>Breach Analysis</category><description>A detailed technical analysis of the April 2026 Vercel OAuth supply chain breach. Learn how a stolen token led to internal access, environment variable exposure, and widespread credential risk.</description></item></channel></rss>