
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Benson - Security Engineer</title>
      <link>https://bmacharia.com//blog</link>
      <description>The enigma of security engineering is mastering the art of anticipating the unknown.</description>
      <language>en-us</language>
      <managingEditor>bm@bmacharia.com (Benson Macharia)</managingEditor>
      <webMaster>bm@bmacharia.com (Benson Macharia)</webMaster>
      <lastBuildDate>Sun, 16 Nov 2025 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://bmacharia.com//feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://bmacharia.com//blog/devsecops-pipeline-sca</guid>
    <title>Part 3: Software Composition Analysis (SCA) with Trivy</title>
    <link>https://bmacharia.com//blog/devsecops-pipeline-sca</link>
    <description>Conducting Software Composition Analysis (SCA) in a Jenkis DevSecOps pipeline with Trivy</description>
    <pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>DevSecOps</category><category>Trivy</category><category>SCA</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/devsecops-pipeline-sast</guid>
    <title>Part 2: Static Application Security Testing (SAST) with Semgrep</title>
    <link>https://bmacharia.com//blog/devsecops-pipeline-sast</link>
    <description>Static Application Security Testing (SAST) in a Jenkis DevSecOps pipeline with Semgrep</description>
    <pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>DevSecOps</category><category>Semgrep</category><category>SAST</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/aws-security-architecture-for-pci-dss-v4</guid>
    <title>Designing a PCI DSS v4 Compliant Environment on AWS</title>
    <link>https://bmacharia.com//blog/aws-security-architecture-for-pci-dss-v4</link>
    <description>A guide to building a secure AWS Cloud environment for PCI DSS v4 compliance</description>
    <pubDate>Sun, 15 Jun 2025 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>PCI DSS</category><category>AWS</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/prompt-injection-llms</guid>
    <title>Beyond the Prompt: The #1 Security Risk in LLMs</title>
    <link>https://bmacharia.com//blog/prompt-injection-llms</link>
    <description>Prompt injection in LLMs, security implications and recommended mitigations</description>
    <pubDate>Tue, 05 Nov 2024 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>LLM</category><category>AI</category><category>Injection</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/aws-bedrock-api-token-based-authentication</guid>
    <title>AWS Bedrock: Securing LLMs with Token-Based Authentication</title>
    <link>https://bmacharia.com//blog/aws-bedrock-api-token-based-authentication</link>
    <description>Implementing token-based authentication for an AWS bedrock API on AWS SAM</description>
    <pubDate>Sat, 17 Aug 2024 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>IAM</category><category>AI</category><category>LLM</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/devsecops-pipeline-secrets-detection</guid>
    <title>Part 1: Secrets Detection in a DevsecOps Jenkins Pipeline</title>
    <link>https://bmacharia.com//blog/devsecops-pipeline-secrets-detection</link>
    <description>Configuring secrets detection in a Jenkis DevSecOps pipeline</description>
    <pubDate>Fri, 10 May 2024 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>DevSecOps</category><category>Compliance</category><category>Secrets Management</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/aws-sam-secrets-manager</guid>
    <title>Secure Secrets Management on AWS SAM with Secrets Manager</title>
    <link>https://bmacharia.com//blog/aws-sam-secrets-manager</link>
    <description>Quick guide to managing secrets for serverless applications with AWS Secrets Manager</description>
    <pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>Secrets Management</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/eks-cloudwatch-logging</guid>
    <title>API Logging on EKS with Cloudwatch</title>
    <link>https://bmacharia.com//blog/eks-cloudwatch-logging</link>
    <description>A guide to configure API logging on EKS with AWS Cloudwatch</description>
    <pubDate>Tue, 07 Feb 2023 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>Logging</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/cis-hardened-aws-ami</guid>
    <title>Creating a CIS Level 1 Hardened AWS AMI</title>
    <link>https://bmacharia.com//blog/cis-hardened-aws-ami</link>
    <description>Simple guide for creating a CIS hardened AWS AMI</description>
    <pubDate>Fri, 08 Jul 2022 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>Compliance</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/cloud-for-data-protection-compliance</guid>
    <title>Leveraging Cloud for Data Protection Compliance</title>
    <link>https://bmacharia.com//blog/cloud-for-data-protection-compliance</link>
    <description>Insights on using Cloud for Data Protection Compliance</description>
    <pubDate>Fri, 01 Jul 2022 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Cloud</category><category>Data Privacy</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/secure-android-user-sessions</guid>
    <title>Securing Android Application User Sessions</title>
    <link>https://bmacharia.com//blog/secure-android-user-sessions</link>
    <description>A guide to building secure user sessions on Android applications</description>
    <pubDate>Wed, 25 May 2022 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>IAM</category><category>Secrets Management</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/spring-boot-auth</guid>
    <title>Spring Boot Authentication and Authorization</title>
    <link>https://bmacharia.com//blog/spring-boot-auth</link>
    <description>A guide to building secure user authentication and authorization in Java Spring Boot</description>
    <pubDate>Tue, 17 May 2022 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>IAM</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/php-type-juggling</guid>
    <title>Authentication Bypass Through PHP Type Juggling</title>
    <link>https://bmacharia.com//blog/php-type-juggling</link>
    <description>Demonstrating authentication bypass by exploiting PHP Type Juggling</description>
    <pubDate>Sat, 14 May 2022 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>IAM</category><category>Bug Bounty</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/exploiting-blind-sql-injection</guid>
    <title>Exploiting Time-Based Blind SQL Injection With SQLMap</title>
    <link>https://bmacharia.com//blog/exploiting-blind-sql-injection</link>
    <description>Demonstrating time-based blind SQL injection exploitation with SQLMap</description>
    <pubDate>Mon, 07 Jun 2021 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Injection</category><category>Bug Bounty</category>
  </item>

  <item>
    <guid>https://bmacharia.com//blog/host-header-injection-account-takeover</guid>
    <title>Account Takeover Through Host Header Injection</title>
    <link>https://bmacharia.com//blog/host-header-injection-account-takeover</link>
    <description>Demonstrating account takeover through host header injection</description>
    <pubDate>Thu, 04 Mar 2021 00:00:00 GMT</pubDate>
    <author>bm@bmacharia.com (Benson Macharia)</author>
    <category>Injection</category><category>Bug Bounty</category>
  </item>

    </channel>
  </rss>
