Offensive Engineering

Offensive Engineering

Home
Newsletter Issues
Live Sessions
InfoSec Relations
About
Offensive Eng #5: Nobody Has Built a Way to Take Access Back
Dan DeCloss on what he would hand an agent, what stays with security practitioners, and why an agent's credentials cannot be pulled mid-engagement
Sep 3 • Shant E. Jena
OWASP API Security Top 10 Vulnerabilities and How to Fix Each One
A hands-on walkthrough of broken authorization, weak token validation, SSRF and shadow APIs, with the vulnerable code beside the version that corrects…
Sep 2 • Shant E. Jena

July 2026

Offensive Eng #4: Cloud Security Crosses Into Machine Scale
Michael Clark and Crystal Morin on the four-hour exploitation window, an identity layer that is 97% machine, and the automated response almost nobody…
Jul 27 • S Pattnaik and Shant E. Jena

May 2026

Offensive Eng #3: Securing Agentic AI Against Data Leakage
Mahesh Goyal on agentic AI governance, cryptographic identity, and why existing security architectures were not built for this
May 22 • S Pattnaik and Shant E. Jena
Offensive Eng #2: Attacking the Cloud Control Plane
Siri Varma Vegiraju on control plane compromise, identity misconfiguration, and the access paths security owners consistently overlook
May 13 • S Pattnaik and Shant E. Jena

April 2026

Offensive Eng #1: Agents with Offensive Capability
Albert Ziegler on autonomous security agents, offensive architecture, and the governance gap
Apr 23 • Puspita Pradhan, Shant E. Jena, and S Pattnaik
© 2026 InfoSec Relations · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture