Securing https://www.securing.pl/en/ Thu, 24 Sep 2026 08:04:33 +0000 en-US hourly 1 https://www.securing.pl/wp-content/uploads/2020/09/favicon.png Securing https://www.securing.pl/en/ 32 32 From Attack Vectors to Defenses: Kubernetes Hardening https://www.securing.pl/en/hardening-kubernetes/ Thu, 24 Sep 2026 08:04:31 +0000 https://www.securing.pl/?p=21970 Kubernetes has become the backbone of modern cloud-native infrastructure, enabling teams to deploy, scale, and manage containerized applications with remarkable efficiency. However, with great power comes great complexity, and keeping Kubernetes secure can be a challenging task. In this article, I will show how simple, low-effort security settings can help protect your cluster from disaster.

The post From Attack Vectors to Defenses: Kubernetes Hardening appeared first on Securing.

]]>
CVE-2025-54419: How two bugs combine to break SAML authentication in Node-SAML 5.0.1 https://www.securing.pl/en/cve-2025-54419-how-two-bugs-combine-to-break-saml-authentication-in-node-saml-5-0-1/ Tue, 04 Aug 2026 06:49:59 +0000 https://www.securing.pl/?p=21681 A deep dive into the root causes of CVE-2025-54419: a SAML signature verification bypass involving a C14N spec deviation in XML Processing Instructions and a parser differential.

The post CVE-2025-54419: How two bugs combine to break SAML authentication in Node-SAML 5.0.1 appeared first on Securing.

]]>
CVE-2026-36162, CVE-2026-36163: Bypassing CSP to exploit Stored XSS in LiquidFiles https://www.securing.pl/en/bypassing-csp-to-exploit-stored-xss-in-liquidfiles/ Wed, 01 Jul 2026 09:33:52 +0000 https://www.securing.pl/?p=21257 A stored cross-site scripting (XSS) vulnerability was identified in LiquidFiles 4.2.7. A low-privileged attacker could execute arbitrary JavaScript code in the context of a victim's browser. The attack chain bypasses any Content Security Policy (CSP) configured on the application, including the default policy.

The post CVE-2026-36162, CVE-2026-36163: Bypassing CSP to exploit Stored XSS in LiquidFiles appeared first on Securing.

]]>
OpenID Connect Nonce explained: Where it matters and where it doesn’t. Replay attack revisited https://www.securing.pl/en/openid-connect-nonce-explained/ Tue, 09 Jun 2026 06:44:01 +0000 https://www.securing.pl/?p=21239 The nonce is rarely implemented and often misunderstood. Take a closer look at the OIDC nonce, replay attacks, and whether the nonce deserves more attention than it gets in modern OIDC flows.

The post OpenID Connect Nonce explained: Where it matters and where it doesn’t. Replay attack revisited appeared first on Securing.

]]>
Security testing programme – 25 years of experience in a nutshell https://www.securing.pl/en/security-testing-program-25-years-of-experience-in-a-nutshell/ Tue, 19 May 2026 08:28:50 +0000 https://www.securing.pl/?p=21325 In cybersecurity, a one-off penetration test is merely a snapshot - it captures the state of security at a single, specific point in time. For modern organisations with extensive application portfolios, this is not enough. The foundation of real resilience is a repeatable and structured testing programmeme.

The post Security testing programme – 25 years of experience in a nutshell appeared first on Securing.

]]>
Software developers in a digital crosshair https://www.securing.pl/en/software-developers-in-a-digital-crosshairs/ Tue, 21 Apr 2026 06:57:02 +0000 https://www.securing.pl/?p=20626 I speak about threats that software developers have faced since around 2019. In 2024, I had a break and at the end of 2025, I decided to revisit the topic. Below is a summary of what was happening in 2025 regarding both old and new threats and observed attacks.

The post Software developers in a digital crosshair appeared first on Securing.

]]>
Where should you begin with mobile application security requirements? https://www.securing.pl/en/where-should-you-begin-with-mobile-application-security-requirements/ Wed, 01 Apr 2026 06:27:00 +0000 https://www.securing.pl/?p=20431 Starting a mobile project sounds easy. In most cases, the client knows what the application should do, and designers know how it should look and feel. Problems arise with non-functional requirements – how the application should operate and behave. One category of these non-functional requirements is security, and it turns out it’s not that difficult to find!

The post Where should you begin with mobile application security requirements? appeared first on Securing.

]]>
Conditional UI in WebAuthn. Passkey autofill https://www.securing.pl/en/conditional-ui-in-webauthn-passkey-autofill/ Mon, 02 Mar 2026 10:02:00 +0000 https://www.securing.pl/?p=20213 Passkeys are rapidly becoming the new standard for authentication, and users are already enjoying their smooth, password free experience. But can logging in with a passkey be even simpler? Yes - thanks to Conditional UI, a WebAuthn feature that brings passkey autofill to life without the security risks we once faced with password autocomplete.

The post Conditional UI in WebAuthn. Passkey autofill appeared first on Securing.

]]>
MCP security hot potato https://www.securing.pl/en/mcp-security-hot-potato/ Wed, 04 Feb 2026 09:20:57 +0000 https://www.securing.pl/?p=20111 This overview covers new MCP security risks, including real-world vulnerabilities, malicious server actions, and attack methods such as Tool Poisoning, Rug Pulls, and Tool Shadowing. It also offers practical tips for keeping MCP servers and clients secure.

The post MCP security hot potato appeared first on Securing.

]]>
From .mlmodel to encrypted .mlmodelc: How Apple Encrypts and Delivers ML Models https://www.securing.pl/en/from-mlmodel-to-mlmodelc-how-apple-encrypts-and-delivers-ml-models/ Wed, 21 Jan 2026 13:03:51 +0000 https://www.securing.pl/?p=19909 Apple's Core ML allows developers to deploy machine learning models in iOS apps using formats such as .mlmodel, .mlpackage, and the compiled .mlmodelc format, which supports encryption. This article examines how Xcode integrates AES-128 encryption and FairPlay DRM, along with metadata, padding, and obfuscation to secure models. It also explores reverse engineering challenges, detailing the core ML compiler, protobuf key exchange, and runtime access via LLDB and Frida Trace – insights valuable to mobile engineers and security professionals working with iOS ML infrastructure.

The post From .mlmodel to encrypted .mlmodelc: How Apple Encrypts and Delivers ML Models appeared first on Securing.

]]>