A practical walkthrough of how I run STRIDE threat models on web applications and APIs — from DFD decomposition to writing actionable mitigations developers can actually implement
Discover the 5 pillars of data governance that engineers must master to build secure, compliant, and reliable data pipelines. Learn how to protect trust, meet regulations, and ensure quality from the start
Learn how to turn governance principles into a working architecture. This guide shows how to embed compliance and security into every stage of a data pipeline — from ingestion to orchestration.
See how to implement a secure, governed data pipeline on AWS with Glue, PySpark, and S3 — detecting and redacting sensitive data before it becomes a compliance risk
Embed security and privacy controls into every stage of your AWS data pipeline. Learn GDPR-aligned, security-by-design strategies for encryption, access control, and data anonymization
Description There are various Facebook products like Ads Manager, Business Manager, Messenger Payments, etc. which requires an user to add some payment method to their Facebook account which can be credit card, debit card, paypal, etc.
The story I came across a note New: Videos in Comments! written by Bob Baldwin who works at Facebook. This note was about Facebook launching it’s new feature of commenting using videos.
Description I was able to fool Facebook’s Graph Search and bypass privacy restrictions and extract sensitive information about user’s applications and pages. I was able to get applications used by any user, regardless of privacy settings set to Only Me and also I was able to get Pages liked by user, regardless of privacy settings set to Only Me
Description The endpoint /me/links is undocumented. We cannot find documentation about how to deal with this endpoint. But combining few api calls we can create unpublished posts.