Open source library without a security review Merging code with critical security issues No logging or monitoring for security events No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Hardcoded credentials in source code No input validation on user input “It works on my machine” response to security concerns SQL query without parameterized inputs Lack of RBAC (everyone is an admin) Unpatched critical vulnerability in production Missing security headers (CSP, HSTS, etc.) Outdated dependency with known CVEs Lack of rate limiting on APIs Disabled MFA on an admin account Logging sensitive data in plaintext Developers sharing passwords via Slack/email Using eval() in production code Default passwords still in use API key exposed in a public repository Unencrypted database storage for PII Exposing sensitive environment variables in logs Public S3 bucket with sensitive data "We don’t have time for security" excuse Open source library without a security review Merging code with critical security issues No logging or monitoring for security events No security testing in CI/CD pipeline Ignoring security warnings in dependency scans Hardcoded credentials in source code No input validation on user input “It works on my machine” response to security concerns SQL query without parameterized inputs Lack of RBAC (everyone is an admin) Unpatched critical vulnerability in production Missing security headers (CSP, HSTS, etc.) Outdated dependency with known CVEs Lack of rate limiting on APIs Disabled MFA on an admin account Logging sensitive data in plaintext Developers sharing passwords via Slack/email Using eval() in production code Default passwords still in use API key exposed in a public repository Unencrypted database storage for PII Exposing sensitive environment variables in logs Public S3 bucket with sensitive data "We don’t have time for security" excuse
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Open source library without a security review
Merging code with critical security issues
No logging or monitoring for security events
No security testing in CI/CD pipeline
Ignoring security warnings in dependency scans
Hardcoded credentials in source code
No input validation on user input
“It works on my machine” response to security concerns
SQL query without parameterized inputs
Lack of RBAC (everyone is an admin)
Unpatched critical vulnerability in production
Missing security headers (CSP, HSTS, etc.)
Outdated dependency with known CVEs
Lack of rate limiting on APIs
Disabled MFA on an admin account
Logging sensitive data in plaintext
Developers sharing passwords via Slack/email
Using eval() in production code
Default passwords still in use
API key exposed in a public repository
Unencrypted database storage for PII
Exposing sensitive environment variables in logs
Public S3 bucket with sensitive data
"We don’t have time for security" excuse