cloud-security
+3
Aug 4, 2026
•
6 min read
One annotation redirects the client, and the webhook's own token goes with it
+4
Jul 28, 2026
2 min read
One number gets rewritten, and your socket list comes back short
CI/CD
Jul 21, 2026
4 min read
AsyncAPI's own release pipeline published five npm versions with malware in them, each with valid provenance.
+2
Jul 14, 2026
An unauthenticated bug in Argo CD's repo-server walks straight to full cluster takeover. No CVE, no patch, and the fix is a Helm setting the chart shipped switched off until 10.0.0.
Weekly Recon
Jul 7, 2026
Sysdig caught a ransomware attack a model ran end to end, and it fixed its own broken exploit in 31 seconds.
Jun 30, 2026
Clone a repo and your coding agent runs the payload. Plus a dormant OAuth backdoor and a malicious skill marketplace.
Detection Engineering
You defend what you can see. Three ways the cloud hides what's happening from you.
Jun 16, 2026
5 min read
The agent era moves trust to both ends of the wire: the skills you install run as untrusted code, the scanners that vet them are theater, and the agents attackers run find your bugs faster than you do.
Jun 9, 2026
Attackers ride the primitives you already trust: a poisoned official Claude Code Action, your own AWS domains as C2, your coding agent's tool calls