Blog

Notes from the AI DevOps team.

How a managed AI DevOps team replaces platform-engineering labor: capability tiers, approval gates, audit trails, and the economics of autonomous infrastructure.

A single git push owned every repo on GitHub Enterprise
Security

A single git push owned every repo on GitHub Enterprise

CVE-2026-3854 let any authenticated user inject internal headers via push options. One git push, RCE on the backend, access to every public and private repo on the same instance. Patch is GHES 3.19.3.

Jun 3, 2026 13 min read
Microsoft Defender CVE pair on the KEV clock: June 3 deadline
Security

Microsoft Defender CVE pair on the KEV clock: June 3 deadline

Microsoft disclosed CVE-2026-41091 (LPE to SYSTEM via Defender's Malware Protection Engine) and CVE-2026-45498 (Defender DoS) on May 19. Both actively exploited. CISA added both to KEV with a June 3 deadline.

May 26, 2026 13 min read
When Microsoft patches their cloud side: the May 2026 Azure cluster
Security

When Microsoft patches their cloud side: the May 2026 Azure cluster

May 2026 Patch Tuesday shipped a cluster of cloud-side-remediated Azure CVEs: DevOps (CVSS 10), Cassandra (CVSS 9.9 and 9.0), Cloud Shell (CVSS 9.6). Microsoft patched all of them without customer action. What's left on the customer-obligation list?

May 26, 2026 13 min read
Continuous threat modeling for platform teams in 2026
Security

Continuous threat modeling for platform teams in 2026

Threat modeling stopped being a quarterly Visio session in 2026. Post-IriusRisk acquisition, the combined platform pushes continuous AI-assisted modeling into the SDLC. Here's what that looks like for daily shippers.

May 14, 2026 11 min read
How to run a repository security audit
Security

How to run a repository security audit

Most teams don't know what's in their repos — leaked secrets, outdated dependencies, misconfigured CI. Here's how to run a thorough audit and fix what you find.

Apr 24, 2026 9 min read
Automated SBOM generation for polyglot monorepos
Security

Automated SBOM generation for polyglot monorepos

A monorepo with Go, Python, Node, and Rust doesn't produce one SBOM. It produces four, and they don't agree. Here's the 2026 playbook for getting them aligned.

Apr 22, 2026 11 min read

Talk to the team about your cloud

30 minutes with the team. We'll look at your cloud together, show you what we'd take off your plate, and scope a first month if it's a fit.