PinnedA Cyber Evaluation Escaped Through Its Package CacheOpenAI's internal test reached Hugging Face production. The useful lesson is how an allowed dependency path became an attack path.Jul 22, 2026·5 min read
The Jira Ticket That Read the ServerOriginally published in Securing the Agentic Stack, my weekly newsletter on the trust boundaries that appear when software can turn what it reads into action. A Jira ticket is supposed to describe worAug 23, 2026·5 min read
The Approve Button Is Not EvidenceHe wrote his court filing in white ink. Humans saw a normal document. Software saw instructions to rule in his favor. On August 6, a Connecticut judge sanctioned him — even though nothing was fooled. Aug 22, 2026·7 min read
The Log Line That Waited for an EngineerKong's own patch test shows the real danger in CVE-2026-13341. The request does nothing when it arrives. The authority jump happens later, during investigation.Jul 16, 2026·4 min read
Nobody Wants to Give the AI Write Access to ProdAn SRE lead I follow spent KubeCon Europe walking the AI-vendor aisle. Multi-agent investigation. Production knowledge graphs. Autonomous remediation. Nine-figure funding rounds. Then he wrote down [wApr 20, 2026·6 min read
The AI Foundation Every Engineer Needs (and What to Skip)I surveyed 50+ resources so you don't have to. Here are the 18 that matter. Why This Matters Right Now Who is this for: All software professionals — backend, frontend, infra, data, QA, security, leaMar 23, 2026·18 min read
Stop Learning AI — Start Upgrading YOUR Role: A Guide for Every Software DisciplineIf "learn AI" advice has felt overwhelming and vague, you're not alone. The AI territory has already fragmented by role, and nobody is talking about that. AI is moving fast. But the real problem isn'tMar 15, 2026·7 min read