Blog
- AI security
, 4 min read
AI-generated code is a security problem hiding in plain sight
Independent studies keep finding vulnerabilities in a large share of AI-generated code, and developers using assistants feel more confident about it. The fix isn't banning the tools. It's gates that don't care who wrote the code.
Read the post - War story
, 1 min read
The Elasticsearch deadlock that parked every index: ILM warm phases on a single node
A single-node Elasticsearch cluster hit 999 of its 1,000-shard ceiling, then deadlocked a month later. Both came from the same missing setting in the ILM policy.
Read the post - CVE explainer
, 4 min read
The XZ Utils Backdoor (CVE-2024-3094)
A contributor spent more than two years earning maintainer rights on a compression library, then shipped a backdoor that reached sshd. It was caught because a login took half a second too long.
Read the post
Start with a $500 audit.
See exactly where you stand. Actionable findings in a week.
The full report and debrief call. Delivery in 5–7 business days.