Field Notes
Security Insights
Practical notes on AI security, application security, and DevSecOps — written by practitioners, not marketers.
Vibe Coding Is Shipping Vulnerabilities: What the Research Shows
AI coding tools are helping teams ship faster. They are also introducing a predictable set of security failures. Here is what the evidence shows and what you can do about it.
10 Rules of GitHub Branch Protection: Why Every Org Should Use Them
Any organisation — from a two-person startup to a global charity — benefits from branch protection rules in GitHub. They’re included for free on public …
Securing AI in Applications: Practical Best Practices for 2025
AI security is still a wild west. Many controls are experimental, most vendors claim coverage they do not fully deliver, and new solutions are untested at …
Application Security Patterns: Building Blocks for Safer Software
Why AppSec patterns matter, examples of common ones, and how to structure a reusable pattern.