Logo
Search
Home
Archive
Login
Sign Up
Logo

Archive

Every issue, open. One attack, one rule, one move worth shipping.

cloud-security

+3

Your secrets webhook hands out its own token

Aug 4, 2026

•

6 min read

Your secrets webhook hands out its own token

One annotation redirects the client, and the webhook's own token goes with it

R.K. Chidambaram
R.K. Chidambaram

cloud-security

+4

How a rootkit hides a connection

Jul 28, 2026

•

2 min read

How a rootkit hides a connection

One number gets rewritten, and your socket list comes back short

CI/CD

+4

Your release pipeline will vouch for malware

Jul 21, 2026

•

4 min read

Your release pipeline will vouch for malware

AsyncAPI's own release pipeline published five npm versions with malware in them, each with valid provenance.

cloud-security

+2

Your GitOps controller can hand over the whole cluster

Jul 14, 2026

•

6 min read

Your GitOps controller can hand over the whole cluster

An unauthenticated bug in Argo CD's repo-server walks straight to full cluster takeover. No CVE, no patch, and the fix is a Helm setting the chart shipped switched off until 10.0.0.

Weekly Recon

An AI ran the whole ransomware attack by itself

Jul 7, 2026

•

6 min read

An AI ran the whole ransomware attack by itself

Sysdig caught a ransomware attack a model ran end to end, and it fixed its own broken exploit in 31 seconds.

Your Agent Runs What You Cloned

Jun 30, 2026

•

6 min read

Your Agent Runs What You Cloned

Clone a repo and your coding agent runs the payload. Plus a dormant OAuth backdoor and a malicious skill marketplace.

Detection Engineering

+2

Weekly Recon #10: Blind Spots

Jun 30, 2026

•

6 min read

Weekly Recon #10: Blind Spots

You defend what you can see. Three ways the cloud hides what's happening from you.

R.K. Chidambaram
R.K. Chidambaram
Weekly Recon #9: Untrusted by Invitation

Jun 16, 2026

•

5 min read

Weekly Recon #9: Untrusted by Invitation

The agent era moves trust to both ends of the wire: the skills you install run as untrusted code, the scanners that vet them are theater, and the agents attackers run find your bugs faster than you do.

R.K. Chidambaram
R.K. Chidambaram
Weekly Recon #8: Borrowed Trust

Jun 9, 2026

•

5 min read

Weekly Recon #8: Borrowed Trust

Attackers ride the primitives you already trust: a poisoned official Claude Code Action, your own AWS domains as C2, your coding agent's tool calls

R.K. Chidambaram
R.K. Chidambaram
Load more

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv