Field Notes
Security Insights
Practical notes on AI security, application security, and DevSecOps — written by practitioners, not marketers.
Figma Reviews Every Pull Request With AI for 50 Cents
Figma and Google Cloud both published how they use AI agents to secure their own code this year. The machinery is cheap and the method is documented. What neither company can sell you is the written threat model that makes it work.
Hackers Are Using AI to Target Businesses. Five Steps That Will Keep Your Business Secure.
AI is now being used to attack organisations. Below are five basic security steps anyone can take to run their business securely.
Supply Chain Attacks Keep Hitting npm. Here Is What AWS Says Actually Helps
AWS wrote a long post on supply chain security after Shai-Hulud and the other npm attacks this year. We read it so you don't have to. Here is what's actually worth doing.
10 Security Mistakes Hiding in Every Vibe-Coded App (Check Yours in 10 Minutes)
AI writes working code fast. It also makes the same security mistakes again and again. Here are the 10 most common ones, why they happen, and a quick way to check each one in your own app.
npm v12 Will Stop Running Install Scripts by Default: What It Means and How to Prepare
npm v12 comes in July 2026 and it changes how npm install works. Install scripts, git dependencies and remote tarballs will be blocked by default. Here is what changes, why, and what you should do now.
Your AI Has a Favourite Programming Language. Here Is What It Costs You
When you vibe-code, the AI picks the language, not you. The data shows it picks TypeScript for the frontend and Python for the backend. Each comes with its own security bill. Here is what ships in the box, and why Go deserves a look now.
Harden Your GitHub: 14 Free Things to Do Right Now
GitHub default settings are made for convenience, not for security. Here are 14 changes you can do today for free. They cover access, Actions, secrets, supply chain and dependencies.
323 npm Packages Poisoned in 22 Minutes: Inside the AntV Supply Chain Attack
On May 19, 2026, a compromised npm account pushed malicious versions of 323 packages across Alibaba's AntV ecosystem. The payload reads GitHub Actions runner memory to extract masked secrets in plaintext. Here is what happened, how it works, and what to do.
Copy Fail: A New Linux Vulnerability That Hands Attackers Root Access
CVE-2026-31431, disclosed yesterday, lets any user on a Linux machine become root administrator in seconds. No patch is available yet. Here is what it means and what to do right now.
Post-Quantum Cryptography: What Your Business Needs to Know Now
Quantum computers will eventually break most of today's encryption. The standards are ready, the big vendors are moving, and waiting too long will cost you. Here is what it means for your business.