Logo
Search
Home
Archive
Login
Sign Up
Logo
Weekly Recon

One attack. One fix. Tuesdays.

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

Articles

cloud-security

+3

Your secrets webhook hands out its own token

Aug 4, 2026

•

6 min read

Your secrets webhook hands out its own token

One annotation redirects the client, and the webhook's own token goes with it

R.K. Chidambaram
R.K. Chidambaram

cloud-security

+4

How a rootkit hides a connection

Jul 28, 2026

•

2 min read

How a rootkit hides a connection

One number gets rewritten, and your socket list comes back short

CI/CD

+4

Your release pipeline will vouch for malware

Jul 21, 2026

•

4 min read

Your release pipeline will vouch for malware

AsyncAPI's own release pipeline published five npm versions with malware in them, each with valid provenance.

cloud-security

+2

Your GitOps controller can hand over the whole cluster

Jul 14, 2026

•

6 min read

Your GitOps controller can hand over the whole cluster

An unauthenticated bug in Argo CD's repo-server walks straight to full cluster takeover. No CVE, no patch, and the fix is a Helm setting the chart shipped switched off until 10.0.0.

Weekly Recon

An AI ran the whole ransomware attack by itself

Jul 7, 2026

•

6 min read

An AI ran the whole ransomware attack by itself

Sysdig caught a ransomware attack a model ran end to end, and it fixed its own broken exploit in 31 seconds.

Your Agent Runs What You Cloned

Jun 30, 2026

•

6 min read

Your Agent Runs What You Cloned

Clone a repo and your coding agent runs the payload. Plus a dormant OAuth backdoor and a malicious skill marketplace.

Load more

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv