Browsed by
Category: Publications

Secure-by-design FP&A: Automating Planning Without Expanding the Fraud Surface

Secure-by-design FP&A: Automating Planning Without Expanding the Fraud Surface

Originally published by Finance Alliance on February 24, 2026. In this article, I examine the security implications of FP&A automation and why security needs to be incorporated into financial planning systems from the design stage rather than added after deployment. The article covers data lineage, excessive permissions, segregation of duties, generative AI risks, integration and API security, machine identities, and the controls required to automate financial planning without increasing the organization’s fraud surface. Read the full article on Finance Alliance →

Investigation of a Courier Brand Impersonation Scam: A Case Study of the CDEK Delivery Fraud

Investigation of a Courier Brand Impersonation Scam: A Case Study of the CDEK Delivery Fraud

Research article published in  The American Journal of Engineering and Technology  on January 15, 2026. My research presents a case study of a courier-brand impersonation and phishing campaign targeting users through a fraudulent CDEK delivery flow. The investigation reconstructs the attack chain from the initial social engineering interaction through the malicious web infrastructure used to capture sensitive financial information. The study examines domain impersonation, TLS infrastructure, phishing-page design, social-engineering techniques, and the interaction flow used by the attackers. It also…

Read More Read More

Identity Is the New Root Access: Rethinking Zero Trust in DevOps Environments

Identity Is the New Root Access: Rethinking Zero Trust in DevOps Environments

Originally published as an interview with SecuritySenses on November 13, 2024. I spoke with SecuritySenses about cloud detection engineering and the challenge of turning growing volumes of security telemetry into meaningful and actionable detections. The discussion covers detection engineering as a continuous engineering discipline, cloud-native telemetry, detection-as-code, reducing alert noise, continuous validation, and the role AI can play in helping security teams identify and investigate threats. Read the full interview on SecuritySenses →

How AI Is Redefining Cyber Attack and Defense Strategies

How AI Is Redefining Cyber Attack and Defense Strategies

Originally published by  AI Accelerator Institute on July 28, 2025. In this article, I examine how artificial intelligence is changing both sides of cybersecurity: providing attackers with new capabilities while giving defenders new ways to detect, investigate, and respond to threats. The article covers AI-generated phishing and deepfakes, automated attacks, AI-assisted threat detection, the evolution of the Security Operations Center, AI security agents, and the growing importance of AI red teaming. Read the full article on AI Accelerator Institute →

AI-Driven Cloud Detection Engineering: Turning Security Telemetry Into Action

AI-Driven Cloud Detection Engineering: Turning Security Telemetry Into Action

Originally published as an interview with SecuritySenses on November 13, 2024. I spoke with SecuritySenses about cloud detection engineering and the challenge of turning growing volumes of security telemetry into meaningful and actionable detections. The discussion covers detection engineering as a continuous engineering discipline, cloud-native telemetry, detection-as-code, reducing alert noise, continuous validation, and the role AI can play in helping security teams identify and investigate threats. Read the full interview on SecuritySenses →

Unmasking CDEK Delivery Scam: A Step-by-Step Investigation (English version)

Unmasking CDEK Delivery Scam: A Step-by-Step Investigation (English version)

After a colleague fell victim to the same CDEK delivery scam I investigated several years ago, I decided to translate my findings for a wider audience. Original article (in Russian) is available here. We’ve all been there: anxiously awaiting a package and then receiving a seemingly legitimate message about a delivery issue. But what if that message is a trap? Recently, I encountered a sophisticated phone phishing scam using the CDEK(popular delivery company in Belarus and Russia) name, and I…

Read More Read More