AI security/securing the use of AI is going to kill me. I use Claude Code almost daily. It's a problem.... Here's what I have to change AGAIN this week. Security researcher Ari Marzuk disclosed 30+ vulnerabilities across AI coding tools. Cursor. GitHub Copilot. Windsurf. Claude Code. All of them. He called it IDEsaster. The attack chain includes prompt injection, hijacking LLM context, and auto-approved tool calls executing without permission. Then, legitimate IDE features are weaponized for data exfiltration and RCE. Your .env files. Your API keys. Your source code. Accessible through features you thought were safe. Most studies I read claim that around 85% of developers now use AI coding tools daily. Most have no idea their IDE treats its own features as inherently trusted. 𝗦𝗼... 𝗮𝗳𝘁𝗲𝗿 𝗿𝗲𝘃𝗶𝗲𝘄𝗶𝗻𝗴 𝗔𝗿𝗶'𝘀 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵, 𝗵𝗲𝗿𝗲'𝘀 𝗜 𝘄𝗶𝗹𝗹 𝗯𝗲 𝗱𝗼𝗶𝗻𝗴... Be warned: All this is SO much easier said than done! Audit every MCP server connection. Checked for tool poisoning vectors where legitimate tools might parse attacker-controlled input from GitHub PRs or web content. Removed servers I couldn't verify. Disabled auto-approve for file writes. The attack chains weaponize configuration files and project instructions like .claude/settings.json and CLAUDE.md. One malicious write to these files can alter agent behavior or achieve code execution without additional user interaction. Move all credentials to a secrets manager. No .gitignored .env files in agent-accessible directories. API keys live in 1Password CLI. Environment variables inject at runtime through a wrapper script the LLM never sees. Start running Claude Code in isolated containers. Mounted volumes limited to specific project directories. No access to ~/.ssh, ~/.aws, or ~/.config. If the agent gets compromised, blast radius stays contained. Enable all security warnings. Claude Code added explicit warnings for JSON schema exfiltration and settings file modifications. These exist because Anthropic knows the attack surface. Add pre-commit hooks for hidden characters. Prompt injections hide in pasted URLs, READMEs, and file names using invisible Unicode. Flag non-ASCII characters in any file the agent might ingest. The fix isn't to stop using AI coding tools. The fix is to stop trusting them implicitly. What controls do you have for AI tools with write access to your codebase? 👉 Follow for more AI and cybersecurity insights with the occasional rant #AISecurity #DevSecOps
Networking
Explore top LinkedIn content from expert professionals.
-
-
McKinsey & Company 𝗮𝗻𝗮𝗹𝘆𝘇𝗲𝗱 𝟭𝟱𝟬+ 𝗲𝗻𝘁𝗲𝗿𝗽𝗿𝗶𝘀𝗲 𝗚𝗲𝗻𝗔𝗜 𝗱𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁𝘀 — 𝗮𝗻𝗱 𝗳𝗼𝘂𝗻𝗱 𝗼𝗻𝗲 𝗰𝗼𝗺𝗺𝗼𝗻 𝘁𝗵𝗿𝗲𝗮𝗱: ⬇️ One-off solutions don’t scale. The most successful projects take a different path: They use open, modular architectures that enable speed, reuse, and control. → Designed for reuse → Able to plug in best-in-class capabilities → Free from vendor lock-in This is the reference architecture McKinsey now recommends — optimized to scale what works while staying compliant. It consists of five core components: ⬇️ 𝟭. 𝗦𝗲𝗹𝗳-𝘀𝗲𝗿𝘃𝗶𝗰𝗲 𝗽𝗼𝗿𝘁𝗮𝗹: → A secure, compliant “pane of glass” where teams can launch, monitor, and manage GenAI apps. → Preapproved patterns, validated capabilities, shared libraries. → Observability and cost controls built-in. 𝟮. 𝗢𝗽𝗲𝗻 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 → Services are modular, reusable, and provider-agnostic. → Core functions like RAG, chunking, or prompt routing are shared across apps. → Infra and policy as code, built to evolve fast. 𝟯. 𝗔𝘂𝘁𝗼𝗺𝗮𝘁𝗲𝗱 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗴𝘂𝗮𝗿𝗱𝗿𝗮𝗶𝗹𝘀 → Every prompt and response is logged, audited, and cost-attributed. → Hallucination detection, PII filters, bias audits — enforced by default. → LLMs accessed only through a centralized AI gateway. 4. 𝗙𝘂𝗹𝗹-𝘀𝘁𝗮𝗰𝗸 𝗼𝗯𝘀𝗲𝗿𝘃𝗮𝗯𝗶𝗹𝗶𝘁𝘆 → Centralized logging, analytics, and monitoring across all solutions → Built-in lifecycle governance, FinOps, and Responsible AI enforcement → Secure onboarding of use cases and private data controls → Enables policy adherence across infrastructure, models, and apps 5. 𝗣𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻-𝗴𝗿𝗮𝗱𝗲 𝗨𝘀𝗲 𝗖𝗮𝘀𝗲𝘀 → Modular setup for user interface, business logic, and orchestration → Integrated agents, prompt engineering, and model APIs → Guardrails, feedback systems, and observability built into the solution → Delivered through the AI Gateway for consistent compliance and scale The message is clear: If your GenAI program is stuck, don’t look at the LLM. Look at your platform. 𝗜 𝗲𝘅𝗽𝗹𝗼𝗿𝗲 𝘁𝗵𝗲𝘀𝗲 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁𝘀 — 𝗮𝗻𝗱 𝘄𝗵𝗮𝘁 𝘁𝗵𝗲𝘆 𝗺𝗲𝗮𝗻 𝗳𝗼𝗿 𝗿𝗲𝗮𝗹-𝘄𝗼𝗿𝗹𝗱 𝘂𝘀𝗲 𝗰𝗮𝘀𝗲𝘀 — 𝗶𝗻 𝗺𝘆 𝘄𝗲𝗲𝗸𝗹𝘆 𝗻𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿. 𝗬𝗼𝘂 𝗰𝗮𝗻 𝘀𝘂𝗯𝘀𝗰𝗿𝗶𝗯𝗲 𝗵𝗲𝗿𝗲 𝗳𝗼𝗿 𝗳𝗿𝗲𝗲: https://lnkd.in/dbf74Y9E
-
Mediocre marketers are beating great operators. Not because they’re better. Because they’re louder. Let me be blunt: If you’re building in silence… If your network doesn’t know what you’re up to… If your customers can’t explain what makes you different… You’re handing attention to people with half your talent and twice your audacity. I’ve seen 7-figure founders lose deals, hires, and even acquirers to louder, less capable competitors. Visibility > Ability (until proven otherwise). You don’t need to be a “creator.” But if you’re not documenting, positioning, and amplifying your wins someone else will steal your spotlight. 🔁 So what do you do? Steal this 3-step visibility flywheel: Document – Share 1 win, 1 lesson, 1 challenge weekly. Differentiate – Build IP. Frameworks > opinions. Deplatform – Drive traffic to a newsletter or lead magnet so you own the audience. Quiet excellence is noble. But in business? It's often invisible. Start showing your work. Loudly and strategically.
-
7 Critical Networking Protocols Every Technology Professional Must Know As a technology professional, understanding core networking protocols is crucial for building reliable and efficient systems. Let’s break it down into what, how, and where these protocols are used: 1. 𝗧𝗖𝗣/𝗜𝗣 𝗪𝗵𝗮𝘁: The backbone of the internet, combining the Transmission Control Protocol (TCP) and Internet Protocol (IP). 𝗛𝗼𝘄: - TCP ensures reliable data delivery with error checking and flow control. - IP manages addressing and routing across networks. 𝗪𝗵𝗲𝗿𝗲: - Web services like HTTP (port 80) and HTTPS (port 443) rely on TCP/IP for communication. 2. 𝗗𝗡𝗦 𝗪𝗵𝗮𝘁: Domain Name System translates human-readable domain names into IP addresses. 𝗛𝗼𝘄: - Uses a hierarchical structure: root servers, TLD servers, and authoritative name servers. - Supports record types like A, AAAA, MX, and CNAME. 𝗪𝗵𝗲𝗿𝗲: - Vital for web infrastructure and email routing. 3. 𝗛𝗧𝗧𝗣/𝗛𝗧𝗧𝗣𝗦 𝗪𝗵𝗮𝘁: Protocols that power web communication and data transfer. 𝗛𝗼𝘄: - Implements RESTful methods like GET, POST, PUT, and DELETE. - Status codes (e.g., 200, 404) indicate request outcomes. - HTTPS adds encryption via SSL/TLS for secure data transfer. 𝗪𝗵𝗲𝗿𝗲: - Used by websites, APIs, and modern web applications. 4. 𝗦𝗠𝗧𝗣 𝗪𝗵𝗮𝘁: Simple Mail Transfer Protocol enables email transmission. 𝗛𝗼𝘄: - Works alongside POP3 and IMAP for email delivery and retrieval. - Implements security features like SPF, DKIM, and DMARC. 𝗪𝗵𝗲𝗿𝗲: - Operates on ports 25 (standard) and 587 (TLS) for secure email communication. 5. 𝗙𝗧𝗣 𝗪𝗵𝗮𝘁: File Transfer Protocol for transferring files over a network. 𝗛𝗼𝘄: - Supports active and passive modes for connections. - Secure alternatives include SFTP (SSH-based) and FTPS (SSL/TLS-based). 𝗪𝗵𝗲𝗿𝗲: - Ideal for large file transfers, especially between servers. 6. 𝗨𝗗𝗣 𝗪𝗵𝗮𝘁: User Datagram Protocol prioritizes speed over reliability. 𝗛𝗼𝘄: - Offers minimal overhead, making it faster but less reliable than TCP. - Commonly used for real-time applications like VoIP and streaming. 𝗪𝗵𝗲𝗿𝗲: - Frequently paired with DNS and DHCP for network services. 7. 𝗗𝗛𝗖𝗣 𝗪𝗵𝗮𝘁: Dynamic Host Configuration Protocol automates IP address management. 𝗛𝗼𝘄: - Uses the DORA process (Discover, Offer, Request, Acknowledge) for IP assignment. - Configures network parameters like subnet mask and default gateway. 𝗪𝗵𝗲𝗿𝗲: - Critical for scaling networks and managing devices dynamically. Why These Protocols Matter These networking protocols form the foundation of modern systems. Mastering them enables better system design, faster troubleshooting, and improved performance. What tools do you use for network diagnostics? Personally, I rely on 𝗖𝗵𝗿𝗼𝗺𝗲 𝗗𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿 𝗧𝗼𝗼𝗹𝘀 for web debugging. What’s your go-to tool?
-
Modern IIoT systems demand a balance of safety, security, reliability, resilience, and privacy. This isn't just a tech challenge; it's a cultural one, bridging IT's obsession with privacy and OT's focus on safety. The 𝐈𝐧𝐝𝐮𝐬𝐭𝐫𝐲 𝐈𝐨𝐓 𝐂𝐨𝐧𝐬𝐨𝐫𝐭𝐢𝐮𝐦’𝐬 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐅𝐫𝐚𝐦𝐞𝐰𝐨𝐫𝐤 (𝐈𝐈𝐒𝐅), first released in 𝟐𝟎𝟏𝟔, is now on 𝐕𝐞𝐫𝐬𝐢𝐨𝐧 𝟐.𝟎, with its latest update in 𝟐𝟎𝟐𝟑. Over the years, it has evolved into a robust guide for securing IIoT systems, addressing the unique challenges of integrating IT and OT. The IISF is designed to help manufacturers build trustworthiness across systems by aligning safety, security, reliability, resilience, and privacy in a single framework. The 𝐈𝐨𝐓 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐌𝐚𝐭𝐮𝐫𝐢𝐭𝐲 𝐌𝐨𝐝𝐞𝐥 (𝐒𝐌𝐌), first released in 𝟐𝟎𝟏𝟖, is a structured framework that builds on the IISF’s principles by helping organizations assess and improve their security practices. 𝐖𝐡𝐚𝐭 𝐩𝐫𝐨𝐛𝐥𝐞𝐦𝐬 𝐝𝐨 𝐭𝐡𝐞𝐲 𝐬𝐨𝐥𝐯𝐞? • Securing legacy (brownfield) environments alongside modern, cloud-integrated systems. • Bridging the gap between IT (focused on data security) and OT (focused on operational safety). • Equipping manufacturers with tools to assess risks, address gaps, and build actionable security roadmaps. 𝐇𝐨𝐰 𝐓𝐡𝐞𝐲 𝐖𝐨𝐫𝐤 𝐓𝐨𝐠𝐞𝐭𝐡𝐞𝐫 • 𝐈𝐈𝐒𝐅 𝐏𝐫𝐨𝐯𝐢𝐝𝐞𝐬 𝐭𝐡𝐞 "𝐖𝐡𝐚𝐭" 𝐚𝐧𝐝 "𝐖𝐡𝐲": It explains what security goals organizations should aim for and why they matter in an IIoT context. • 𝐒𝐌𝐌 𝐏𝐫𝐨𝐯𝐢𝐝𝐞𝐬 𝐭𝐡𝐞 "𝐇𝐨𝐰": It helps organizations evaluate their current security maturity, define targets based on IISF principles, and create actionable roadmaps to achieve those targets. 𝐖𝐡𝐲 𝐔𝐬𝐞 𝐁𝐨𝐭𝐡? Together, the IISF and SMM offer a top-down and bottom-up approach: • Start with the IISF to understand the overarching security needs for your IIoT systems. • Use the SMM to assess where you stand and implement practical improvements to achieve those needs. 𝐃𝐨𝐰𝐧𝐥𝐨𝐚𝐝 𝐈𝐈𝐒𝐅: https://lnkd.in/eypinq3G 𝐃𝐨𝐰𝐧𝐥𝐨𝐚𝐝 𝐒𝐒𝐌: https://lnkd.in/e398Y9TU ******************************************* • Visit www.jeffwinterinsights.com for access to all my content and to stay current on Industry 4.0 and other cool tech trends • Ring the 🔔 for notifications!
-
Consulting firms are increasingly seeking to bring in Operating Partners or members of Portfolio Support Groups from Private Equity funds to join their ranks as Partners. As competition intensifies to serve the PE community, these Operating Partners have become a key differentiator for firms. Clients are placing higher value on consulting teams with professionals who possess genuine operational experience. The hands-on experience that Operating Partners bring is now seen as essential for driving value in PE-backed companies. Moreover, these professionals are playing a dual role. Not only are they delivering operational expertise, but they're also serving in an account management capacity. Their deep relationships within PE funds are being leveraged to cross-sell a range of services—allowing consulting firms to act as strategic partners, integrating solutions across strategy, transformation, and operational improvement. In a market where value-add is paramount, Consulting firms that integrate true operators into their leadership teams are poised to stand out. This trend highlights the growing alignment between Consulting and Private Equity, as firms work to bring not just advice, but real, operational know-how to the table.
-
🌟 𝐒𝐭𝐨𝐩 𝐓𝐡𝐢𝐧𝐤𝐢𝐧𝐠 𝐁𝐢𝐠 - 𝐒𝐭𝐚𝐫𝐭 𝐓𝐡𝐢𝐧𝐤𝐢𝐧𝐠 𝐖𝐢𝐝𝐞! The biggest breakthroughs don’t happen by digging deeper into one area - they happen when ideas, industries, and technologies collide. Think about it: AI combined with IoT has transformed healthcare. Sustainability powered by cloud solutions is opening new markets. The magic lies at the 𝐢𝐧𝐭𝐞𝐫𝐬𝐞𝐜𝐭𝐢𝐨𝐧𝐬 - where fresh opportunities emerge. 🚀 𝐖𝐡𝐲 𝐓𝐡𝐢𝐬 𝐌𝐚𝐭𝐭𝐞𝐫𝐬 1️⃣ 𝐅𝐚𝐬𝐭𝐞𝐫 𝐈𝐧𝐧𝐨𝐯𝐚𝐭𝐢𝐨𝐧: Combining technologies like AI and cloud accelerates growth. 2️⃣ 𝐍𝐞𝐰 𝐌𝐚𝐫𝐤𝐞𝐭 𝐑𝐞𝐚𝐜𝐡: Partnerships across industries unlock untapped customers. 3️⃣ 𝐒𝐡𝐚𝐫𝐞𝐝 𝐕𝐚𝐥𝐮𝐞: Cross-industry collaboration lowers costs and drives new value. At Deloitte, I’ve seen the power of collaboration. By partnering with organizations like #Celonis, #Schaeffler, #HumboldtInnovation, and #GermanEntrepreneurship, we’ve established the European non-profit AI ecosystem, #KIPark. This initiative brings together players from different industries to unlock innovation. For example, we’ve developed an ESG platform, marking a significant step toward sustainable solutions that are robust and business-relevant. 🛠️ 𝐓𝐡𝐫𝐞𝐞 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐭𝐚𝐲 𝐀𝐡𝐞𝐚𝐝 1️⃣ 𝐋𝐨𝐨𝐤 𝐎𝐮𝐭𝐬𝐢𝐝𝐞 𝐘𝐨𝐮𝐫 𝐈𝐧𝐝𝐮𝐬𝐭𝐫𝐲: Who could you partner with to create something new? 2️⃣ 𝐁𝐮𝐢𝐥𝐝 𝐌𝐢𝐱𝐞𝐝 𝐓𝐞𝐚𝐦𝐬: Pair data scientists with operations or customer-facing teams. 3️⃣ 𝐄𝐱𝐩𝐞𝐫𝐢𝐦𝐞𝐧𝐭 𝐁𝐨𝐥𝐝𝐥𝐲: Start small pilots that combine tech and business ideas. 🌍 𝐓𝐡𝐞 𝐁𝐨𝐭𝐭𝐨𝐦 𝐋𝐢𝐧𝐞 The future belongs to businesses that connect the dots others don’t see. Breadth - not just depth - is the key to growth and resilience. 💬 𝐘𝐨𝐮𝐫 𝐓𝐮𝐫𝐧 What’s one unexpected partnership or idea you’ve seen recently that sparked innovation? Let’s exchange ideas. Who knows what new intersections we might uncover together? #Deloitte #AI #Innovation #Leadership #BusinessStrategy #Partnerships 𝐴𝑟𝑡𝐵𝑎𝑠𝑒𝑙. 𝐶ℎ𝑎𝑛𝑔𝑒𝑂𝑓𝑃𝑒𝑟𝑠𝑝𝑒𝑐𝑡𝑖𝑣𝑒. 𝐹𝑜𝑢𝑛𝑑 𝑎𝑡 @𝑔𝑎𝑏𝑟𝑖𝑒𝑙𝑙𝑒𝑒𝑒𝑟𝑢𝑡ℎ
-
The Zscaler ThreatLabz research team analyzed a critical remote‑code execution flaw (CVE‑2026‑20131) in the web‑based management interface of Cisco’s Secure Firewall Management Center. The management console didn’t validate incoming data allowing an unauthenticated attacker to send malicious data that the system ran as if it were trusted. This handed adversaries full control to change firewall settings and aggressively move deeper into the network. This incident is another reminder that exposed management interfaces and legacy assets like VPNs and Firewalls are high‑value targets. Organizations should not only patch but also reduce their attack surface. Moving to a Zero Trust architecture removes public reachability, enforces least‑privilege access and blocks unauthenticated probes. Zscaler’s Zero Trust platform eliminates this risk by creating a one-to-one connection between users directly to applications rather than access to corporate networks, eliminating internet‑exposed endpoints and preventing lateral movement. Deepen Desai, CSO and EVP of Engineering, and the ThreatLabz team provide a full technical analysis of CVE‑2026‑20131 along with mitigation steps and best practices in their latest blog. https://lnkd.in/gVccQvHi #ZeroTrustEverywhere #ZeroTrust #ThreatIntelligence #ThreatLabz #CyberThreats
-
Behind every opportunity is a relationship, and behind every relationship is a conversation. Networking is about building real connections that last and have the potential to help you find your next opportunity. Data shared by the University of Maryland’s Department of Economics indicates you won’t find 70% of available jobs on any site that posts open positions. Those positions are usually found on a company’s internal network, often by referral. In other words, relationships can make the difference between finding a job or not. That’s no surprise to me. Throughout my journey, from engineer to investor, relationships have been a constant driver of growth. Mentors, colleagues and peers have not only opened doors, but also challenged my thinking, sharpened my skills and inspired my vision. Here’s what I have learned: - Be curious: Ask questions that show you care about people’s stories. - Be intentional: Connect with purpose, not just for your own gain. - Be consistent: Follow up, follow through and add value where you can. Networking isn’t a one-time event. It requires maintaining ongoing relationships rooted in trust and genuine interest in other people’s lives. Whether you’re just starting out on your professional journey or deep into your field, relationships are what power careers.
-
I see this writing mistake over and over again: You include too much in ONE LinkedIn post. Look, I get it. When you're an expert and a true connoisseur of your craft, it is your natural tendency to "overshare" information. To teach til the bell rings! You think: More angles = More value. But no. It should be: 1 post → 1 topic → 1 angle → 1 takeaway Today's post, as an example: Writing mistake → Happens a lot → Focus your posts Remember: If you have 5 ideas, write 5 LinkedIn posts. Never throw it all together into one post. Because there's too many focus points. I have to admit, when I first started writing, I'd always... No! Stop right here. That's another lesson. An entirely different post! (See how this works? 😊) "Focus" your posts, friend. More focus = More value. Always! P.S. Are you a natural "oversharer"? Do tell, don't be shy.