Lack of RBAC (everyone is an admin) Merging code with critical security issues Public S3 bucket with sensitive data “It works on my machine” response to security concerns Outdated dependency with known CVEs No input validation on user input Exposing sensitive environment variables in logs Using eval() in production code Disabled MFA on an admin account Default passwords still in use No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Hardcoded credentials in source code Developers sharing passwords via Slack/email Unpatched critical vulnerability in production API key exposed in a public repository Unencrypted database storage for PII Missing security headers (CSP, HSTS, etc.) No logging or monitoring for security events SQL query without parameterized inputs Open source library without a security review Logging sensitive data in plaintext Lack of rate limiting on APIs "We don’t have time for security" excuse Lack of RBAC (everyone is an admin) Merging code with critical security issues Public S3 bucket with sensitive data “It works on my machine” response to security concerns Outdated dependency with known CVEs No input validation on user input Exposing sensitive environment variables in logs Using eval() in production code Disabled MFA on an admin account Default passwords still in use No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Hardcoded credentials in source code Developers sharing passwords via Slack/email Unpatched critical vulnerability in production API key exposed in a public repository Unencrypted database storage for PII Missing security headers (CSP, HSTS, etc.) No logging or monitoring for security events SQL query without parameterized inputs Open source library without a security review Logging sensitive data in plaintext Lack of rate limiting on APIs "We don’t have time for security" excuse
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Lack of RBAC (everyone is an admin)
Merging code with critical security issues
Public S3 bucket with sensitive data
“It works on my machine” response to security concerns
Outdated dependency with known CVEs
No input validation on user input
Exposing sensitive environment variables in logs
Using eval() in production code
Disabled MFA on an admin account
Default passwords still in use
No security testing in CI/CD pipeline
Ignoring security warnings in dependency scans
Hardcoded credentials in source code
Developers sharing passwords via Slack/email
Unpatched critical vulnerability in production
API key exposed in a public repository
Unencrypted database storage for PII
Missing security headers (CSP, HSTS, etc.)
No logging or monitoring for security events
SQL query without parameterized inputs
Open source library without a security review
Logging sensitive data in plaintext
Lack of rate limiting on APIs
"We don’t have time for security" excuse