The IDE is Now Just a Large Attack Surface

For years, a lot of thought and investment went into Integrated Development Environments (IDEs). Agentic development seemed to be their triumph, with tools like VSCode + Copilot, Windsurf, and Cursor bringing development experiences to the next level. But the same agentic development led to the decline of IDEs. The issue is that agents, and not… Continue reading The IDE is Now Just a Large Attack Surface

CI/CD Security Principles in 2026

This is a follow up on my older post “7 Best Practices of Modern CI/CD“. Points outlined there still hold true, but they are missing several important security considerations. Today, in 2026, CI/CD pipelines have become one of the key supply chain attack vectors (refer, for example, to the recent Trivy compromise). That warrants an… Continue reading CI/CD Security Principles in 2026

Time to Start Treating Dev Machines as Untrusted

Shai-Hulud, Shai-Hulud 2.0, Trivy, LiteLLM, and now Axios, and many smaller compromises bring us to the realization that existing supply chains are highly vulnerable. A common thread across of these attacks is that once you download and install a compromised package, the usual behavior of the malicious code inside is to steal tokens and other… Continue reading Time to Start Treating Dev Machines as Untrusted

Published
Categorized as Security

Towards Perfect Vulnerability Management System

Here I would like to summarize my thoughts on what constitutes a perfect vulnerability management system, what frequently gets missed, and what elements we already have in the latest ReARM release. I Not Only Vulnerabilities First of all, a management system should cover all security findings, not only vulnerabilities. That includes things like SAST /… Continue reading Towards Perfect Vulnerability Management System

SBOM Developments for December 2025

Happy New Year 2026! Following my previous post about SBOM developments for July 2025, this is another one about things that happened in the community since. Again, this is mostly for myself as a reference storage but I’m happy if other people find this useful too. 1. ENISA SBOM Landscape Analysis December 2025 – important… Continue reading SBOM Developments for December 2025

Published
Categorized as BOMs Tagged