The Secure Cookie

The Secure Cookie

Home
Academy
Archive
About
🍪#7 A Developer-Friendly Approach to Security in CI/CD Pipelines
Illustrating secure delivery workflows with minimal friction for developers.
Nov 18 • 
Ferran

October 2025

🍪#6 From Dev to Prod and How Runtime Environments Shape the SDLC
Clarifying the differences between Development, Test, Staging, and Production environments.
Oct 28 • 
Ferran
🍪#5 The Final Step to Secure File Uploads
Managing file size, storage, and permissions to build resilient and secure upload features.
Oct 16 • 
Ferran
Your Company Needs More (Good) Digital Nomads
Why letting your team work from paradise might be smarter than you think.
Oct 9 • 
Ferran
🍪#4 Turning WAFs into a VirusTotal-like Platform for File Content Validation
As a security engineer, working with low-budget projects has sometimes driven my growth.
Oct 2 • 
Ferran

September 2025

🍪#3 Why File Type Validation is Always an Untrusted Check
Attackers turn file type validation into an easy bypass.
Sep 25 • 
Ferran
🍪#2 How To Sanitize A Filename
A developer's guide to practical defenses against unsafe file names in file upload features.
Sep 18 • 
Ferran
🍪#1 The Dangers of Insecure File Uploads
From RCE to data leaks—the risks behind insecure file handling.
Sep 9 • 
Ferran
Hello from The Secure Cookie
An introduction to me and to this newsletter. And why secure coding is more than just following AI hints.
Sep 5 • 
Ferran
© 2025 Ferran · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture