# AppSec Engineering

Security architecture, authorization patterns, and engineering practices that make products harder to break.

### [How was Uber hacked, and what can we learn from the incident?](/content/blog/how-was-uber-hacked-and-what-can-we-learn-from-the-incident/index.html)

A technical breakdown of the 2022 Uber breach: how dark web credentials, MFA fatigue attacks, and lateral movement through internal tooling led to full corporate access.

### [Hacking apps using NoSQL Injection](/content/blog/hacking-apps-using-nosql-injection/index.html)

Hacking apps using NoSQL Injection

### [Microservices Authorization using Open Policy Agent and Traefik (API Gateway)](/content/blog/microservices-authorization-using-open-policy-agent-and-trae/index.html)

Microservices Authorization using Open Policy Agent and Traefik (API Gateway)
