It’s 2026. It’s faster to fix CVEs than argue about them

There is a lot of buzz regarding reachability and exploitability. Also, following latest Black Hat, there are ~1000 new CVEs reported against Linux kernel (a lot of them relate to privilege escalation). Additionally, a lot of our assumptions, such as those about network isolation, may not hold true in reality. With that, today frequently it… Continue reading It’s 2026. It’s faster to fix CVEs than argue about them

The IDE is Now Just a Large Attack Surface

For years, a lot of thought and investment went into Integrated Development Environments (IDEs). Agentic development seemed to be their triumph, with tools like VSCode + Copilot, Windsurf, and Cursor bringing development experiences to the next level. But the same agentic development led to the decline of IDEs. The issue is that agents, and not… Continue reading The IDE is Now Just a Large Attack Surface

CI/CD Security Principles in 2026

This is a follow up on my older post “7 Best Practices of Modern CI/CD“. Points outlined there still hold true, but they are missing several important security considerations. Today, in 2026, CI/CD pipelines have become one of the key supply chain attack vectors (refer, for example, to the recent Trivy compromise). That warrants an… Continue reading CI/CD Security Principles in 2026

When the Paradigm Shifts: A Zero-Trust Model for AI Agents

“When a paradigm shifts, everyone goes back to zero” (Joel A. Barker in his book “Future Edge”). These days I find two types of people when talking about AI. The first type consists of those who doubt AI can do things properly. In my space, specifically, that would be coding. The argument goes something like… Continue reading When the Paradigm Shifts: A Zero-Trust Model for AI Agents

Time to Start Treating Dev Machines as Untrusted

Shai-Hulud, Shai-Hulud 2.0, Trivy, LiteLLM, and now Axios, and many smaller compromises bring us to the realization that existing supply chains are highly vulnerable. A common thread across of these attacks is that once you download and install a compromised package, the usual behavior of the malicious code inside is to steal tokens and other… Continue reading Time to Start Treating Dev Machines as Untrusted

Published
Categorized as Security

Want to Survive Current Tech Era – Learn to Be a Good QA

The amount of messages I see these days on our Discord and other platforms from humans and bots desperately looking for jobs is at spam-like levels. Couple of years ago, these were mostly coming to me in the form of LinkedIn inmails selling development contracts. Looks like now there maybe no budgets left for inmails… Continue reading Want to Survive Current Tech Era – Learn to Be a Good QA

Published
Categorized as Culture Tagged ,