Technical Writing

Tech Blog

Cloud security, identity, infrastructure, and research. Deep dives, tools, and practical guidance.

GCP Professional Cloud Security Engineer: 2025 Study Resources Update
28 Sep 2025 · 3 min read · study · exam

GCP Professional Cloud Security Engineer: 2025 Study Resources Update

Updated resources, exam lessons, and study guidance for the GCP Professional Cloud Security Engineer certification in 2025

SPADE: Side-channel Platform Abuse and Data Exfiltration
10 Sep 2025 · 7 min read · saas · cloud-security

SPADE: Side-channel Platform Abuse and Data Exfiltration

SPADE describes how adversaries can abuse trusted SaaS-hosted runtimes like Google Colab to exfiltrate data and evade CASB, EDR, and proxy controls - bypassing enterprise defenses via unexpected channels.

Announcing ISDF – Intune Stateful Device Fingerprinting
4 Sep 2025 · 5 min read · microsoft · cybersecurity

Announcing ISDF – Intune Stateful Device Fingerprinting

Earlier this year, I published OuttaTune – a deep dive into how Conditional Access (CA) depends on device-sourced metadata and the risks of trusting values that endpoints themselves can assert. While the community …

Turn On, Tune In, Cop Out: The sorta, not-really, fix for OuttaTune from Microsoft
4 Aug 2025 · 4 min read · microsoft · intune

Turn On, Tune In, Cop Out: The sorta, not-really, fix for OuttaTune from Microsoft

Highlighting Microsoft’s documentation and UX tweaks--and the remaining unfixed vulnerability

Secure Google Cloud Authentication in Python: Avoiding CI/CD Pitfalls with Service Accounts
2 Jul 2025 · 6 min read · google-cloud · python

Secure Google Cloud Authentication in Python: Avoiding CI/CD Pitfalls with Service Accounts

Learn how to avoid common anti-patterns when authenticating to Google Cloud using service accounts in Python--especially in CI/CD pipelines like Azure DevOps. This post walks through better practices for secure, reusable credential handling, complete with code examples.

Security Amnesia: When Habit Becomes a Vulnerability
17 Jun 2025 · 4 min read · human-factors · cybersecurity

Security Amnesia: When Habit Becomes a Vulnerability

How action slips and repetitive workflows create security risks -- and why it's time to design for the human brain, not against it.