~3 sessions a week: read the lesson (~15 min) + run and change its section of sec/demo.py (~25 min). Tick lessons off — progress is saved in this browser.
Injection, XSS and CSP, cookies/CSRF/CORS/SSRF. Lab: try the crafted input on both queries; change the CSP; add a URL to the SSRF guard.
Authentication, OAuth/OIDC, authorization. Lab: verify passwords; break each token check; try Katrina's record as Dipika.
Secrets and KMS, IAM and networks, encryption. Lab: scan your own files; shrink a policy; check a TLS config.
Kubernetes RBAC, secrets and network policies, admission. Lab: add a binding; write a default-deny; fix the rejected pod.
Dependencies, signing/SBOM/provenance, pipeline threats. Lab: audit a requirements file; tamper with an artifact; walk the leak runbook.
AI and agent security, then the capstone.
Next: the IAM school goes deep on cloud identity, the System Design school puts security into every box, and the School portal has the rest.