Open source library without a security review “It works on my machine” response to security concerns Public S3 bucket with sensitive data Merging code with critical security issues API key exposed in a public repository Outdated dependency with known CVEs SQL query without parameterized inputs Developers sharing passwords via Slack/email Default passwords still in use Disabled MFA on an admin account No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Unpatched critical vulnerability in production Lack of rate limiting on APIs Hardcoded credentials in source code Missing security headers (CSP, HSTS, etc.) Using eval() in production code "We don’t have time for security" excuse No input validation on user input Logging sensitive data in plaintext Exposing sensitive environment variables in logs Lack of RBAC (everyone is an admin) No logging or monitoring for security events Unencrypted database storage for PII Open source library without a security review “It works on my machine” response to security concerns Public S3 bucket with sensitive data Merging code with critical security issues API key exposed in a public repository Outdated dependency with known CVEs SQL query without parameterized inputs Developers sharing passwords via Slack/email Default passwords still in use Disabled MFA on an admin account No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Unpatched critical vulnerability in production Lack of rate limiting on APIs Hardcoded credentials in source code Missing security headers (CSP, HSTS, etc.) Using eval() in production code "We don’t have time for security" excuse No input validation on user input Logging sensitive data in plaintext Exposing sensitive environment variables in logs Lack of RBAC (everyone is an admin) No logging or monitoring for security events Unencrypted database storage for PII
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Open source library without a security review
“It works on my machine” response to security concerns
Public S3 bucket with sensitive data
Merging code with critical security issues
API key exposed in a public repository
Outdated dependency with known CVEs
SQL query without parameterized inputs
Developers sharing passwords via Slack/email
Default passwords still in use
Disabled MFA on an admin account
No security testing in CI/CD pipeline
Ignoring security warnings in dependency scans
Unpatched critical vulnerability in production
Lack of rate limiting on APIs
Hardcoded credentials in source code
Missing security headers (CSP, HSTS, etc.)
Using eval() in production code
"We don’t have time for security" excuse
No input validation on user input
Logging sensitive data in plaintext
Exposing sensitive environment variables in logs
Lack of RBAC (everyone is an admin)
No logging or monitoring for security events
Unencrypted database storage for PII