Blog

Build security in, in practice

Notes from working with engineering teams: what holds up in code, pipelines and decisions, and what only looks good on a dashboard. Most pieces start as the Build Security In newsletter on LinkedIn.

Output is not evidence

Three pieces of AI security research landed in a single month, on three different problems. They all point at the same soft spot.

The vulnerability nobody wrote

A free GitHub account was enough to puppeteer the pipelines of Microsoft, Google, Apache and Cloudflare. Here is why your scanner never saw it coming, and what AI coding is about to do to the problem.

AI writes the code. Who reviews the risk?

AI ships code faster and repeats old vulnerability patterns with confidence, while NIS2 raises the bar on how software is built. Why security belongs in design and review.

RSS feed

Newsletter

Build Security In

The engineering side of security: secure coding, DevSecOps, AI code and NIS2, for teams who ship. One email per new issue.