Open sourcelibrarywithout asecurityreview“It works onmy machine”response tosecurityconcernsPublic S3bucket withsensitivedataMergingcode withcriticalsecurityissuesAPI keyexposedin a publicrepositoryOutdateddependencywith knownCVEsSQL querywithoutparameterizedinputsDeveloperssharingpasswordsviaSlack/emailDefaultpasswordsstill in useDisabledMFA onan adminaccountNo securitytesting inCI/CDpipelineIgnoringsecuritywarnings independencyscansUnpatchedcriticalvulnerabilityin productionLack ofratelimiting onAPIsHardcodedcredentialsin sourcecodeMissingsecurityheaders(CSP, HSTS,etc.)Usingeval() inproductioncode"We don’thave timefor security"excuseNo inputvalidationon userinputLoggingsensitivedata inplaintextExposingsensitiveenvironmentvariables inlogsLack ofRBAC(everyone isan admin)No loggingor monitoringfor securityeventsUnencrypteddatabasestorage forPIIOpen sourcelibrarywithout asecurityreview“It works onmy machine”response tosecurityconcernsPublic S3bucket withsensitivedataMergingcode withcriticalsecurityissuesAPI keyexposedin a publicrepositoryOutdateddependencywith knownCVEsSQL querywithoutparameterizedinputsDeveloperssharingpasswordsviaSlack/emailDefaultpasswordsstill in useDisabledMFA onan adminaccountNo securitytesting inCI/CDpipelineIgnoringsecuritywarnings independencyscansUnpatchedcriticalvulnerabilityin productionLack ofratelimiting onAPIsHardcodedcredentialsin sourcecodeMissingsecurityheaders(CSP, HSTS,etc.)Usingeval() inproductioncode"We don’thave timefor security"excuseNo inputvalidationon userinputLoggingsensitivedata inplaintextExposingsensitiveenvironmentvariables inlogsLack ofRBAC(everyone isan admin)No loggingor monitoringfor securityeventsUnencrypteddatabasestorage forPII

Software Engineering COP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Open source library without a security review
  2. “It works on my machine” response to security concerns
  3. Public S3 bucket with sensitive data
  4. Merging code with critical security issues
  5. API key exposed in a public repository
  6. Outdated dependency with known CVEs
  7. SQL query without parameterized inputs
  8. Developers sharing passwords via Slack/email
  9. Default passwords still in use
  10. Disabled MFA on an admin account
  11. No security testing in CI/CD pipeline
  12. Ignoring security warnings in dependency scans
  13. Unpatched critical vulnerability in production
  14. Lack of rate limiting on APIs
  15. Hardcoded credentials in source code
  16. Missing security headers (CSP, HSTS, etc.)
  17. Using eval() in production code
  18. "We don’t have time for security" excuse
  19. No input validation on user input
  20. Logging sensitive data in plaintext
  21. Exposing sensitive environment variables in logs
  22. Lack of RBAC (everyone is an admin)
  23. No logging or monitoring for security events
  24. Unencrypted database storage for PII