Grant Fritchey in AI AI built my WordPress plugin. Here’s what worked – and what went wrong (building an app with AI, part five) Learn what happens when you try building a working WordPress plugin for your app with AI - featuring plugin creation,... 20 July 2026 9 min read
Fabiano Amorim in SQL Server How SQL Server maintenance becomes an attack path – and what to do about it How trigger hijacking, msdb exposure, and over-privileged database users create SQL Server attack paths — plus how to detect and... 17 July 2026 25 min read
Grant Fritchey in AI I let AI build my API. Here’s what happened (building an app with an AI LLM, part four) Learn how to use Microsoft CoPilot and GitHub Copilot to build a secure REST API— covering Azure deployment, PostgreSQL integration,... 13 July 2026 8 min read
Grant Fritchey in AI AI can build the pipeline, but don’t trust it for security (building an app with an AI LLM, part three) Learn what happens when you let GitHub Copilot and VSCode set up database migrations and a GitHub Actions pipeline on... 06 July 2026 8 min read 1
Fabiano Amorim in SQL Server Exposing a SQL injection vulnerability you’ve never heard of (what it is, how it works, and key takeaways) How a Unicode lookalike character bypassed REPLACE-based sanitization in a trusted SQL Server system procedure - and what it teaches... 19 June 2026 11 min read 31
Dejan Lukić in Security, Privacy & Compliance How to anonymize PII in LLM pipelines (5 key techniques explained) LLMs ingest everything, including PII. Learn five anonymization techniques (masking, pseudonymization, redaction & more) to protect sensitive data across your... 15 June 2026 7 min read 11
Chisom Kanu in Databases It’s 2026. Why are databases still failing GDPR compliance audits? GDPR erasure failures are often database engineering problems, not legal ones. Learn how relational schema design, backup retention, and audit... 11 June 2026 13 min read 1
Lukas Vileikis in Databases 4 CVEs are affecting Valkey databases. Here’s everything you need to know (and what you should do, right now, to protect yours) 4 CVEs currently affect Valkey databases. Learn what they are, which Valkey versions are vulnerable, and what you should do... 19 May 2026 7 min read 11
Fabiano Amorim in SQL Server SQL Server security vulnerabilities you weren’t aware of: how tampered indexed-view metadata can break cross-database isolation Indexed view tampering in SQL Server backups can expose cross-database data after restore. Learn how restore-boundary attacks work and how... 18 May 2026 18 min read 2
Simple Talk Editor in Security, Privacy & Compliance In 2026, engineering teams are quietly accepting more risk. Here’s why 11 takeaways from the Simple Talk podcast on security vs speed in databases: why teams misjudge risk, how AI amplifies... 17 May 2026 4 min read 22
Lukas Vileikis in PostgreSQL PostgreSQL is removing MD5 authentication for passwords. Here’s what it means for your databases PostgreSQL is phasing out MD5 authentication across versions 18–21, replacing it with SCRAM-SHA-256. Here's what it means for your database... 15 May 2026 7 min read 3
Dejan Lukić in Security, Privacy & Compliance How to build a privacy-aware analytics layer with SQL (4 top techniques) Learn how to build privacy-aware analytics with SQL using masking, aggregation, and pseudonymization. Stay GDPR-compliant without exposing PII.… 13 May 2026 11 min read 21
Fabiano Amorim in SQL Server Cross-database ownership chaining in SQL Server: security risks, behavior, and privilege escalation explained Learn how cross-database ownership chaining works in SQL Server, how permissions are evaluated, and why it can introduce security risks... 13 April 2026 12 min read 2
Lukas Vileikis in Security, Privacy & Compliance Everything you need to know about MongoBleed (CVE-2025-14847) Learn what MongoBleed (CVE-2025-14847) is, how the vulnerability leaks MongoDB server memory, which versions are affected, and how to protect... 08 April 2026 6 min read 11
Umair Shahid in Cloud Why the cloud is not a disaster recovery strategy for your critical databases Cloud isn’t a disaster recovery plan. Learn why multi-AZ and managed services aren’t enough, and how RTO, RPO, backups, and... 13 March 2026 8 min read 21
Lukas Vileikis in Security, Privacy & Compliance How to secure MySQL and PostgreSQL in the world of AI Learn how AI is transforming database security and discover best practices to secure MySQL and PostgreSQL against AI-driven threats, faster... 04 March 2026 11 min read 11
Greg Low in SQL Server Why disabling the SQL Server sa account still matters in 2026 Disabling the SQL Server sa account isn’t outdated advice. Learn why attackers still target sa and what modern SQL Server... 26 February 2026 5 min read 51
Lukas Vileikis in Security How to keep your databases secure in 2026: a complete guide Learn top strategies for securing your databases against emerging security threats. Discover best practices for access control, encryption, monitoring and... 27 January 2026 10 min read 2
Fabiano Amorim in SQL Server Exploiting SQL Server Date Correlation Optimization: How Tampered Backups Enable Cross‑Database Data Leaks This article reveals a critical SQL Server flaw: attackers can weaponize Date Correlation Optimization (DCO) views in restored backups to... 07 January 2026 19 min read 2
Greg Low in SQL Server 15 Practical Tips for Securing SQL Server 15 practical, high-impact steps for securing your SQL Server environment.… 28 November 2025 5 min read 22