

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>https://some-natalie.dev/</id>
  <title>Some Natalie's corner of the internet</title>
  <subtitle>Things I'm learning, working on, or thinking about.  All opinions and snark my own.</subtitle>
  <updated>2026-08-08T02:31:54-04:00</updated>
  <author>
    <name>Natalie Somersall</name>
    <uri>https://some-natalie.dev/</uri>
  </author>
  <link rel="self" type="application/atom+xml" href="https://some-natalie.dev/feed.xml"/>
  <link rel="alternate" type="text/html" hreflang="en"
    href="https://some-natalie.dev/"/>
  <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator>
  <rights> © 2026 Natalie Somersall </rights>
  <icon>/assets/img/favicons/favicon.ico</icon>
  <logo>/assets/img/favicons/favicon-96x96.png</logo>


  
  <entry>
    <title>Container Escapes 101</title>
    <link href="https://some-natalie.dev/container-escapes-workshop/" rel="alternate" type="text/html" title="Container Escapes 101" />
    <published>2026-08-07T00:00:00-04:00</published>
  
    <updated>2026-08-07T00:00:00-04:00</updated>
  
    <id>https://some-natalie.dev/container-escapes-workshop/</id>
    <content type="text/html" src="https://some-natalie.dev/container-escapes-workshop/" />
    <author>
      <name>Natalie Somersall</name>
    </author>

  
    
  

  <summary>Welcome to Container Escapes 101 at the AppSec Village at DEF CON 34!!   🎯 Goal: to have a working knowledge of container escapes and how each security measure or risk maps to potential for exploitation.  With actual exploits … mostly of misconfigurations or the “rough edges” of containers.  Where we’re going     There’s a lot of hard-earned lessons at the weird intersection of how a no-longer-...</summary>

  </entry>

  
  <entry>
    <title>You didn't 'miss the boat' on AI in cybersecurity</title>
    <link href="https://some-natalie.dev/blog/starting-ai-cyber/" rel="alternate" type="text/html" title="You didn&amp;apos;t &amp;apos;miss the boat&amp;apos; on AI in cybersecurity" />
    <published>2026-04-20T00:00:00-04:00</published>
  
    <updated>2026-04-21T22:48:13-04:00</updated>
  
    <id>https://some-natalie.dev/blog/starting-ai-cyber/</id>
    <content type="text/html" src="https://some-natalie.dev/blog/starting-ai-cyber/" />
    <author>
      <name>Natalie Somersall</name>
    </author>

  
    
  

  <summary>This talk was first presented at the Boulder Secure AI &amp;amp; DevOps group on 20 April 2026.    The end goal is enough knowledge to (1) take some first steps on your own and (2) to see the path is worth exploring because there are tons of problems to solve still!  You won’t leave an expert or have a deep dive into any particular problem.  These are the slides with expanded writeup.   This talk t...</summary>

  </entry>

  
  <entry>
    <title>Enterprise chargeback - finding business value</title>
    <link href="https://some-natalie.dev/blog/chargeback-value/" rel="alternate" type="text/html" title="Enterprise chargeback - finding business value" />
    <published>2026-04-06T00:00:00-04:00</published>
  
    <updated>2026-04-06T00:00:00-04:00</updated>
  
    <id>https://some-natalie.dev/blog/chargeback-value/</id>
    <content type="text/html" src="https://some-natalie.dev/blog/chargeback-value/" />
    <author>
      <name>Natalie Somersall</name>
    </author>

  
    
  

  <summary>There’s nothing quite like the feeling of a successful proof-of-concept becoming a production system, but we’re not there yet.  It turns out money makes for the hardest problems on the path to production.  Let’s solve the problem we set out to solve, getting an understanding of software costs to recover them.  We’ll find some unexpected value in the process too.  How many ways can a vendor char...</summary>

  </entry>

  
  <entry>
    <title>Enterprise chargeback - a better quality of life for operations</title>
    <link href="https://some-natalie.dev/blog/chargeback-buildout/" rel="alternate" type="text/html" title="Enterprise chargeback - a better quality of life for operations" />
    <published>2026-03-31T00:00:00-04:00</published>
  
    <updated>2026-03-31T00:00:00-04:00</updated>
  
    <id>https://some-natalie.dev/blog/chargeback-buildout/</id>
    <content type="text/html" src="https://some-natalie.dev/blog/chargeback-buildout/" />
    <author>
      <name>Natalie Somersall</name>
    </author>

  
    
  

  <summary>We left off with a laptop and a database serving as a bare-minimum proof of concept.  It works, but not enough to be usable.  Starting a project from scratch doesn’t have to be toil.  Moving this into “real infrastructure” gave me an opportunity to implement quality of life improvements.  Let’s do databases better this time  By this point, the project had expanded beyond one person’s exploratio...</summary>

  </entry>

  
  <entry>
    <title>There I FIPS’d it - misadventures in federal cryptography</title>
    <link href="https://some-natalie.dev/blog/fipsd-it/" rel="alternate" type="text/html" title="There I FIPS’d it - misadventures in federal cryptography" />
    <published>2026-01-25T00:00:00-05:00</published>
  
    <updated>2026-05-11T00:16:16-04:00</updated>
  
    <id>https://some-natalie.dev/blog/fipsd-it/</id>
    <content type="text/html" src="https://some-natalie.dev/blog/fipsd-it/" />
    <author>
      <name>Natalie Somersall</name>
    </author>

  
    
  

  <summary>Cryptography seems deceptively simple until you get into implementation.  Tempted by shortcuts to save money, organizations ship something “just good enough” to pass compliance checks.  I see this all the time working with the public sector and companies in highly-regulated industries making new products or trying to enter the market for the first time.  Just when you think you’ve done everythi...</summary>

  </entry>

</feed>


