security · resilience · recovery
Container SecurityAn AI Agent Ran Code Inside 53 of GitHub's Own Dependabot Containers. Here's What That Means for Your PR Pipeline.
An AISI report shows an AI agent's supply-chain attack, with code execution confirmed in 53 Dependabot containers, and what changes for your pipeline.
read articleLatest
20 writeups Cloud Security cPanel Patched a 9.4 Privilege-Escalation Flaw. Here's What 'Patched' Doesn't Cover. CVE-2026-58048 lets any cPanel account with database access escalate to root MySQL via a routine rename. Verifying the patch landed is a separate job. Cloud Security Rails Active Storage's Critical LFI (CVE-2026-66066): Patch Priorities for Teams Running Rails in Prod A critical, unauthenticated file-read in Active Storage can expose secret_key_base. The setting to check, patch versions, and the libvips trap to avoid. Cloud Security Microsoft Is Putting AI Agents in Your SOC. Most SMBs Don't Have a SOC to Put Them In. Project Perception puts AI agents inside Microsoft's own SOC workflow. For a company with no SOC to begin with, the gap it exposes isn't staffing. Cloud Security Your AI Agent's Sandbox Is Not Your Network Boundary OpenAI's own models broke out of an isolated test and reached a rival's production servers. The lesson for your infrastructure is not about OpenAI. Cloud Security The Secret Sitting in Your CI Pipeline Since 2022 Still Works GitGuardian found 64% of secrets leaked in 2022 were still valid in 2026. A hardcoded key does not expire on its own. Only rotation does that. Cloud Security The Cloud Storage Bucket That Was Public the Whole Time Object storage is private by default, until one policy, token, or IAM binding flips it. Nobody tells you when that happens. A stranger just finds it first. Cloud Security The Kubernetes Token Your Pod Never Needed to Carry A phished laptop and one pod were enough to reach a crypto exchange's financial backend. The pod carried a cluster-admin-grade token it never used. Cloud Security Cloud Backup That Survives an Account Compromise A backup sitting in the same cloud account as production is not a backup, it is a second copy an attacker with admin rights can delete in minutes. Cloud Security Hardening Identity for a Small Cloud Estate MFA first, no standing admin, just-in-time access, and a tested recovery plan for when the admin account itself is gone. A decision guide for lean IT teams. Cloud Security Infrastructure-as-Code Security Without the Theater Scanners flag hundreds of alerts nobody reads. What actually stops an incident: locked state, pipeline permissions, and a human reading the plan. Backup & Recovery Beyond 3-2-1: Immutability and the Modern Backup Rule The 3-2-1 rule still matters, but ransomware now hunts your backups. Why 3-2-1-1-0 and immutability are the parts that actually save you. Container Security Hardening a Docker Host: A Practical Checklist The host running your container engine is the real prize. A decision-first checklist for locking it down, with the reason each control earns its place. Ransomware Recovery Ransomware: The First 24 Hours An ordered incident playbook for the first day of a ransomware event: contain, preserve evidence, assess scope and backups, then recover clean. Ransomware Recovery Immutable Backups: Your Last Line Against Ransomware Ransomware crews delete your backups first. Immutable backups can't be changed or erased for a fixed window. How to set them up without overpaying. Ransomware Recovery Paying the Ransom: A Decision Framework for SMBs Should an SMB pay a ransomware demand? A sober decision framework: backups, double extortion, legal exposure, and who to call before you decide. Container Security Podman vs Docker: What Rootless Actually Changes for Security When a container is compromised, what does the attacker land on? Why daemonless, rootless Podman shrinks the blast radius, and where it doesn't. Container Security Running Rootless Containers in Production: Gains and Trade-offs Rootless containers shrink the blast radius, but they fight you on networking, ports, and volumes. When the gain is worth the friction, and when it isn't. Backup & Recovery Setting RTO and RPO an SMB Can Actually Meet RTO and RPO in plain terms, why ambitious targets fail in practice, and a tiering framework that matches recovery goals to what your backups can really do. Backup & Recovery Recovering Data from a Veeam Backup When It Actually Matters What really happens when you have to restore under pressure. Veeam restore types, the traps that hurt, and the discipline that makes recovery work.