Fixing Cloudflare WARP Error CF_FAILED_TO_SET_MTLS in Posture Only Mode

Fixing Cloudflare WARP Error CF_FAILED_TO_SET_MTLS in Posture Only Mode

If you are trying to run the Cloudflare One Client (formerly WARP) in Posture only mode and keep getting the following error, this post may save you some troubleshooting time: CF_FAILED_TO_SET_MTLS I ran into this while trying to build what should have been a fairly simple Cloudflare Zero Trust configuration. The requirements were: Enroll corporate devices into Cloudflare Zero Trust. Use an Access token-based onboarding flow. Collect device posture information such as disk encryption, firewall status, OS information, and other endpoint…

Read More Read More

Github Commit Signing

Github Commit Signing

Git commit signing provides a way to cryptographically associate a commit with a signing key. Without commit signing, a Git commit contains an author name and email address, but those fields alone do not prove that the person shown as the author actually created the commit. Signed commits add an additional verification layer. GitHub can verify a cryptographic signature against a signing key registered with the user’s GitHub account and display successfully verified commits with the Verified status. This guide…

Read More Read More

Implement Cloud Security Fundamentals on Google Cloud: Challenge Lab: GSP342

Implement Cloud Security Fundamentals on Google Cloud: Challenge Lab: GSP342

? Lab Reference: Implement Cloud Security Fundamentals on Google Cloud: Challenge Lab (Lab Code: GSP342). A concise walkthrough to complete the GSP342 challenge lab with a 100% score. The following configuration settings are used throughout this guide: export PROJECT_ID=”qwiklabs-gcp-01-8c1086536ffa” export REGION=”us-west1″ export ZONE=”us-west1-b” export CUSTOM_ROLE=”orca_storage_editor_330″ export SA_NAME=”orca-private-cluster-410-sa” export CLUSTER_NAME=”orca-cluster-412″ Architecture Requirements IAM: Dedicated service account with least-privilege logging/monitoring roles and a custom storage role. Network: Private GKE cluster with public endpoints disabled, restricted to the orca-jumphost management IP. Step 1:…

Read More Read More

Secrets Management for DevOps Teams

Secrets Management for DevOps Teams

Secrets are everywhere in modern environments: API keys, database passwords, access tokens, service accounts, SSH keys, certificates, signing keys, cloud credentials, CI/CD tokens, and so on. The problem usually starts when these credentials are treated just as configuration values. Someone creates an API key, puts it into a pipeline variable, another person copies it into a .env file, somebody else uses the same key in another application, and a year later nobody knows where the key is used or who…

Read More Read More

Secure-by-design FP&A: Automating Planning Without Expanding the Fraud Surface

Secure-by-design FP&A: Automating Planning Without Expanding the Fraud Surface

Originally published by Finance Alliance on February 24, 2026. In this article, I examine the security implications of FP&A automation and why security needs to be incorporated into financial planning systems from the design stage rather than added after deployment. The article covers data lineage, excessive permissions, segregation of duties, generative AI risks, integration and API security, machine identities, and the controls required to automate financial planning without increasing the organization’s fraud surface. Read the full article on Finance Alliance →

Investigation of a Courier Brand Impersonation Scam: A Case Study of the CDEK Delivery Fraud

Investigation of a Courier Brand Impersonation Scam: A Case Study of the CDEK Delivery Fraud

Research article published in  The American Journal of Engineering and Technology  on January 15, 2026. My research presents a case study of a courier-brand impersonation and phishing campaign targeting users through a fraudulent CDEK delivery flow. The investigation reconstructs the attack chain from the initial social engineering interaction through the malicious web infrastructure used to capture sensitive financial information. The study examines domain impersonation, TLS infrastructure, phishing-page design, social-engineering techniques, and the interaction flow used by the attackers. It also…

Read More Read More

Identity Is the New Root Access: Rethinking Zero Trust in DevOps Environments

Identity Is the New Root Access: Rethinking Zero Trust in DevOps Environments

Originally published as an interview with SecuritySenses on November 13, 2024. I spoke with SecuritySenses about cloud detection engineering and the challenge of turning growing volumes of security telemetry into meaningful and actionable detections. The discussion covers detection engineering as a continuous engineering discipline, cloud-native telemetry, detection-as-code, reducing alert noise, continuous validation, and the role AI can play in helping security teams identify and investigate threats. Read the full interview on SecuritySenses →

How AI Is Redefining Cyber Attack and Defense Strategies

How AI Is Redefining Cyber Attack and Defense Strategies

Originally published by  AI Accelerator Institute on July 28, 2025. In this article, I examine how artificial intelligence is changing both sides of cybersecurity: providing attackers with new capabilities while giving defenders new ways to detect, investigate, and respond to threats. The article covers AI-generated phishing and deepfakes, automated attacks, AI-assisted threat detection, the evolution of the Security Operations Center, AI security agents, and the growing importance of AI red teaming. Read the full article on AI Accelerator Institute →

AI-Driven Cloud Detection Engineering: Turning Security Telemetry Into Action

AI-Driven Cloud Detection Engineering: Turning Security Telemetry Into Action

Originally published as an interview with SecuritySenses on November 13, 2024. I spoke with SecuritySenses about cloud detection engineering and the challenge of turning growing volumes of security telemetry into meaningful and actionable detections. The discussion covers detection engineering as a continuous engineering discipline, cloud-native telemetry, detection-as-code, reducing alert noise, continuous validation, and the role AI can play in helping security teams identify and investigate threats. Read the full interview on SecuritySenses →

Unmasking CDEK Delivery Scam: A Step-by-Step Investigation (English version)

Unmasking CDEK Delivery Scam: A Step-by-Step Investigation (English version)

After a colleague fell victim to the same CDEK delivery scam I investigated several years ago, I decided to translate my findings for a wider audience. Original article (in Russian) is available here. We’ve all been there: anxiously awaiting a package and then receiving a seemingly legitimate message about a delivery issue. But what if that message is a trap? Recently, I encountered a sophisticated phone phishing scam using the CDEK(popular delivery company in Belarus and Russia) name, and I…

Read More Read More