
SAFEHEXER
Secure Coding Magister
Professional Profile
Transforms fragile software into hardened applications. Expert in secure coding and safe refactoring.
Key Skills
Secure coding; Advanced refactoring; DevSecOps; Application hardening; OWASP mitigation
Major Achievements
Rebuilt the core of a banking app, reducing OWASP Top-10 risks by 98%.
Articles by SAFEHEXER
Free VPNs on Android Found Leaking the Very Traffic They Promise to Hide
A system-level audit of popular Android VPN apps found DNS leaks, plaintext transfers, weak tunnel settings, and tracking signals that can undermine the privacy shield users think they installed.
Italy Tightens the Lens on Reviews: The New Rulebook Starts With Trust
AGCM’s draft guidance on online reviews turns authenticity and traceability into compliance issues that may reshape how platforms handle reputation signals.
The Quiet AI Bill Problem Facing Public Offices
When AI costs are split across renewals, APIs, tokens, and office-level purchases, the real issue is not only spend - it is whether administrations can still see what they bought, from whom, and under which controls.
When Web Scraping Becomes a Regulated AI Supply Chain
The EDPB’s 03/2026 guidance places generative-AI scraping firmly inside GDPR analysis whenever personal data enters the training pipeline, turning dataset design into a compliance and security problem at the same time.
AI’s Quiet Weak Link: Data Governance Is Becoming the First Security Control
The sharpest risks in AI are not always in the model itself - they often begin earlier, when training data, legal grounds, and governance choices are still being set.
Europe’s AI Rulebook Is Forcing Security Teams Into the Boardroom
The AI Act is not just a compliance exercise - it turns data quality, robustness, and cyber controls into board-level operating requirements.
Brussels Draws a Line Around Private Chats in the Fight Over Child Safety
The European debate over Chat Control is now exposing a hard technical question: how far can message inspection go before private communication stops being private?
Why a “Simple” BIA Can Turn Shared IT into NIS2 Critical Terrain
In Italy’s NIS2 framework, dependency mapping can elevate shared platforms like ERP, IAM, SOC, cloud, and common services into critical scope when they support high-impact operations.
Italy Draws a Legal Line Around Generative AI and Copyright
A new Italian framework puts human authorship, training data use, and opt-out handling into sharper focus for anyone building or deploying generative AI.
When AI Moves Faster Than the Rules: The Hidden Security Gap Inside IT Governance
The sharpest risk in enterprise AI is not a single model failure, but the widening gap between fast deployment and the controls needed to keep systems explainable, auditable, and bounded.
Europe Draws a Privacy Map for AI Scraping
The latest EDPB guidance puts web scraping for generative AI under a sharper compliance lens, especially where public web data contains personal information.
When Message Scanning Becomes a Security Problem, Not Just a Policy Fight
The renewed push around Chat Control is less about one vote than about a dangerous design choice: broad inspection of private communications can create a new structural target inside the digital stack.
Compliance Is the Quiet Shield Behind the Loudest Data Disputes
When privacy rules are treated as operational discipline, they can reduce legal exposure before a mistake becomes a sanction, a liability, or a reputational hit.
When AI Starts Acting, Law Meets a Harder Boundary
The real problem is no longer whether rules exist, but whether they can keep pace with agentic AI systems that move from language to action across tools, data, and clouds.
Anonymous on Paper, Personal in Practice: Europe Tightens the Test for Data That Claims to Disappear
The latest EDPB draft on anonymisation shifts the real question from how data is masked to whether reidentification is still realistically possible in the hands of relevant actors.
ESG Disclosure Is Turning Into Europe’s New Financial Stress Test
As CSRD and common standards push sustainability reporting toward the center of European finance, the real pressure point is no longer publication alone but the quality, consistency, and comparability of the data behind it.
When a Public Profile Becomes Prompt Material
Meta’s Muse Image puts public Instagram posts, reels, and account mentions into the generation pipeline, turning ordinary visibility into a new privacy and impersonation risk.
When Credit Scoring Becomes a Trust Test, Humans Still Hold the Last Key
AI can estimate risk inside lending workflows, but the harder problem is not prediction: it is proving that data, oversight, and responsibility still belong to people.
When a Privacy Mask Slips: Apple’s Email Alias Bug and the Trust Problem Behind It
A reported flaw in Apple’s Hide My Email feature shows how a privacy layer can fail without a mailbox breach, turning address masking into a question of engineering discipline.
The AI System Works. The Organization Cannot Prove It.
A growing compliance problem is hiding behind successful AI rollouts: many teams can ship models, but still cannot trace, justify, or govern the decisions those systems produce.


