No security testing in CI/CD pipeline “It works on my machine” response to security concerns Developers sharing passwords via Slack/email SQL query without parameterized inputs Missing security headers (CSP, HSTS, etc.) "We don’t have time for security" excuse No input validation on user input API key exposed in a public repository Using eval() in production code Default passwords still in use Disabled MFA on an admin account No logging or monitoring for security events Unpatched critical vulnerability in production Lack of RBAC (everyone is an admin) Logging sensitive data in plaintext Outdated dependency with known CVEs Ignoring security warnings in dependency scans Lack of rate limiting on APIs Hardcoded credentials in source code Open source library without a security review Public S3 bucket with sensitive data Exposing sensitive environment variables in logs Unencrypted database storage for PII Merging code with critical security issues No security testing in CI/CD pipeline “It works on my machine” response to security concerns Developers sharing passwords via Slack/email SQL query without parameterized inputs Missing security headers (CSP, HSTS, etc.) "We don’t have time for security" excuse No input validation on user input API key exposed in a public repository Using eval() in production code Default passwords still in use Disabled MFA on an admin account No logging or monitoring for security events Unpatched critical vulnerability in production Lack of RBAC (everyone is an admin) Logging sensitive data in plaintext Outdated dependency with known CVEs Ignoring security warnings in dependency scans Lack of rate limiting on APIs Hardcoded credentials in source code Open source library without a security review Public S3 bucket with sensitive data Exposing sensitive environment variables in logs Unencrypted database storage for PII Merging code with critical security issues
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
No security testing in CI/CD pipeline
“It works on my machine” response to security concerns
Developers sharing passwords via Slack/email
SQL query without parameterized inputs
Missing security headers (CSP, HSTS, etc.)
"We don’t have time for security" excuse
No input validation on user input
API key exposed in a public repository
Using eval() in production code
Default passwords still in use
Disabled MFA on an admin account
No logging or monitoring for security events
Unpatched critical vulnerability in production
Lack of RBAC (everyone is an admin)
Logging sensitive data in plaintext
Outdated dependency with known CVEs
Ignoring security warnings in dependency scans
Lack of rate limiting on APIs
Hardcoded credentials in source code
Open source library without a security review
Public S3 bucket with sensitive data
Exposing sensitive environment variables in logs
Unencrypted database storage for PII
Merging code with critical security issues