No input validation on user input Default passwords still in use Open source library without a security review “It works on my machine” response to security concerns SQL query without parameterized inputs No security testing in CI/CD pipeline Ignoring security warnings in dependency scans No logging or monitoring for security events Developers sharing passwords via Slack/email Outdated dependency with known CVEs Using eval() in production code Unpatched critical vulnerability in production Lack of rate limiting on APIs "We don’t have time for security" excuse Public S3 bucket with sensitive data Disabled MFA on an admin account Lack of RBAC (everyone is an admin) Exposing sensitive environment variables in logs API key exposed in a public repository Unencrypted database storage for PII Hardcoded credentials in source code Logging sensitive data in plaintext Merging code with critical security issues Missing security headers (CSP, HSTS, etc.) No input validation on user input Default passwords still in use Open source library without a security review “It works on my machine” response to security concerns SQL query without parameterized inputs No security testing in CI/CD pipeline Ignoring security warnings in dependency scans No logging or monitoring for security events Developers sharing passwords via Slack/email Outdated dependency with known CVEs Using eval() in production code Unpatched critical vulnerability in production Lack of rate limiting on APIs "We don’t have time for security" excuse Public S3 bucket with sensitive data Disabled MFA on an admin account Lack of RBAC (everyone is an admin) Exposing sensitive environment variables in logs API key exposed in a public repository Unencrypted database storage for PII Hardcoded credentials in source code Logging sensitive data in plaintext Merging code with critical security issues Missing security headers (CSP, HSTS, etc.)
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
No input validation on user input
Default passwords still in use
Open source library without a security review
“It works on my machine” response to security concerns
SQL query without parameterized inputs
No security testing in CI/CD pipeline
Ignoring security warnings in dependency scans
No logging or monitoring for security events
Developers sharing passwords via Slack/email
Outdated dependency with known CVEs
Using eval() in production code
Unpatched critical vulnerability in production
Lack of rate limiting on APIs
"We don’t have time for security" excuse
Public S3 bucket with sensitive data
Disabled MFA on an admin account
Lack of RBAC (everyone is an admin)
Exposing sensitive environment variables in logs
API key exposed in a public repository
Unencrypted database storage for PII
Hardcoded credentials in source code
Logging sensitive data in plaintext
Merging code with critical security issues
Missing security headers (CSP, HSTS, etc.)