“It works on my machine” response to security concerns Default passwords still in use No logging or monitoring for security events Unencrypted database storage for PII Lack of RBAC (everyone is an admin) No security testing in CI/CD pipeline Merging code with critical security issues Using eval() in production code SQL query without parameterized inputs No input validation on user input API key exposed in a public repository "We don’t have time for security" excuse Disabled MFA on an admin account Lack of rate limiting on APIs Outdated dependency with known CVEs Ignoring security warnings in dependency scans Exposing sensitive environment variables in logs Logging sensitive data in plaintext Open source library without a security review Missing security headers (CSP, HSTS, etc.) Unpatched critical vulnerability in production Hardcoded credentials in source code Public S3 bucket with sensitive data Developers sharing passwords via Slack/email “It works on my machine” response to security concerns Default passwords still in use No logging or monitoring for security events Unencrypted database storage for PII Lack of RBAC (everyone is an admin) No security testing in CI/CD pipeline Merging code with critical security issues Using eval() in production code SQL query without parameterized inputs No input validation on user input API key exposed in a public repository "We don’t have time for security" excuse Disabled MFA on an admin account Lack of rate limiting on APIs Outdated dependency with known CVEs Ignoring security warnings in dependency scans Exposing sensitive environment variables in logs Logging sensitive data in plaintext Open source library without a security review Missing security headers (CSP, HSTS, etc.) Unpatched critical vulnerability in production Hardcoded credentials in source code Public S3 bucket with sensitive data Developers sharing passwords via Slack/email
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
“It works on my machine” response to security concerns
Default passwords still in use
No logging or monitoring for security events
Unencrypted database storage for PII
Lack of RBAC (everyone is an admin)
No security testing in CI/CD pipeline
Merging code with critical security issues
Using eval() in production code
SQL query without parameterized inputs
No input validation on user input
API key exposed in a public repository
"We don’t have time for security" excuse
Disabled MFA on an admin account
Lack of rate limiting on APIs
Outdated dependency with known CVEs
Ignoring security warnings in dependency scans
Exposing sensitive environment variables in logs
Logging sensitive data in plaintext
Open source library without a security review
Missing security headers (CSP, HSTS, etc.)
Unpatched critical vulnerability in production
Hardcoded credentials in source code
Public S3 bucket with sensitive data
Developers sharing passwords via Slack/email