<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Akash Bishnoi — Blog &amp; Writeups</title>
    <link>https://theakash.eu.cc/blog</link>
    <atom:link href="https://theakash.eu.cc/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Security writeups and engineering notes — offensive security, AppSec, and AI.</description>
    <language>en</language>
    <lastBuildDate>Sat, 18 Jul 2026 00:55:58 GMT</lastBuildDate>
    <item>
      <title>Hardening HTTP Security Headers: From F to A+</title>
      <link>https://theakash.eu.cc/blog/hardening-http-security-headers</link>
      <guid>https://theakash.eu.cc/blog/hardening-http-security-headers</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>AppSec</category>
      <description>A practical, header-by-header walkthrough of turning a leaky default web response into a locked-down A+ — with copy-paste config and the reasoning behind each directive.</description>
    </item>
    <item>
      <title>The OWASP Top 10, Explained by Exploitation</title>
      <link>https://theakash.eu.cc/blog/owasp-top-10-by-exploitation</link>
      <guid>https://theakash.eu.cc/blog/owasp-top-10-by-exploitation</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <category>Offensive Security</category>
      <description>The OWASP Top 10 sticks better when you see how each category actually gets exploited. A field guide from the attacker&apos;s chair — and the fix from the defender&apos;s.</description>
    </item>
    <item>
      <title>Building an AI Triage Layer for a SOC</title>
      <link>https://theakash.eu.cc/blog/ai-triage-layer-for-soc</link>
      <guid>https://theakash.eu.cc/blog/ai-triage-layer-for-soc</guid>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <category>AI + Security</category>
      <description>Alert fatigue is a data problem, not a staffing one. How I designed an LLM-assisted triage layer that ranks, clusters, and explains security alerts — without letting the model make security decisions.</description>
    </item>
  </channel>
</rss>