When Evaluating the Security of Your Project, Start With the Placeholder

We spend an enormous amount of time trying to secure software. We run SAST. We scan dependencies. We scan container images. We run IaC scanners. We check Kubernetes configurations. We monitor runtime behaviour. We build SBOMs. We integrate everything into CI/CD and create dashboards full of vulnerabilities, CVEs and security findings. And yet sometimes the most interesting security problem is not a vulnerability in our software at all. Sometimes it is a placeholder. ...

September 29, 2026 · 8 min · 1557 words · Matteo Bisi

MicroVMs vs Containers for AI Agents: ECB Cybersecurity Guide

AI agents have turned sandboxing from an engineering detail into a leadership decision. A capable agent can install tools, read source code, build experiments, retry failed approaches, and search for a path out of its environment for hours. The old question, “Do we have a sandbox?”, is no longer enough. Trail of Bits showed why in its VM escape experiment with a cyber-capable AI agent. The agent repeatedly escaped a QEMU/KVM environment by combining known but unpatched host weaknesses, fixes not yet included in the distribution, and eventually new vulnerabilities. The lesson is not that virtual machines are useless. It is that no technical boundary provides complete containment on its own. ...

September 21, 2026 · 9 min · 1728 words · Matteo Bisi

Grok Bot: An AI Superpower for Senior Engineers

Four years ago, I started moving from an engineering role into management and leadership. I have written before about my journey from Senior System Engineer to Team Leader and the importance of moving from delegation to ownership. Another transition is happening in parallel. AI coding agents are changing how experienced engineers build software. A recent X post from Lingxi Li, a SpaceXAI engineer working on Grok Bot, gave me one of the clearest examples I have seen so far. ...

September 2, 2026 · 6 min · 1153 words · Matteo Bisi

Shadow AI in CI/CD: Threat-Modelling Laptop to Kubernetes

Artificial intelligence is becoming part of daily software delivery, often before it becomes part of the organisation’s security architecture. This creates Shadow AI: AI tools, models, agents, extensions, or integrations used without formal approval, ownership, risk assessment, or monitoring. For executives, Shadow AI is not primarily a “developers using ChatGPT” issue. It is an enterprise-risk issue: ungoverned AI can gain access to source code, intellectual property, credentials, customer data, cloud environments, and deployment workflows. When AI systems are allowed to call tools or take actions, they must be treated as new non-human identities with access rights, not simply as productivity software. ...

July 27, 2026 · 13 min · 2597 words · Matteo Bisi

Local AI Meeting Minutes with Docker Model Runner and Docker Agent: No Cloud, No Leaks

Like most people in this industry, I spend a good part of my week in meetings: vendor evaluations, customer calls, technical deep dives on cloud-native projects. And like most people, I want minutes out of them without spending an hour writing them myself. The obvious answer in 2026 is “send the recording to an AI service”. For me, that answer is wrong by definition. Those recordings contain customer names, security architectures, commercial terms, gap analyses. As a security team leader, I cannot be the person who enforces data-handling policies on everyone else and then ships a customer’s security posture to a third-party API for convenience. ...

July 6, 2026 · 17 min · 3585 words · Matteo Bisi

Zero Trust for AI Agents: Why Anthropic's New eBook Should Be on Your Reading List

Attackers Now Run at Machine Speed If you have been following this blog, you know that 2026 has not been a quiet year for the security community. The Trivy supply chain attack in March was the wake up call: a trusted security scanner turned into a credential harvesting machine, followed by the CanisterWorm escalation that propagated itself through the npm ecosystem at a speed no human operator could match. In the weeks after, we saw several other serious and successful exploitations following the same pattern: automation turned against the defenders, with exploits appearing within hours of a patch instead of months. ...

June 10, 2026 · 7 min · 1384 words · Matteo Bisi

Docker Sandboxes: Running AI Agents in YOLO Mode, Safely

A few days ago, Docker published an article on LinkedIn about a new tool called Docker Sandboxes (sbx). The pitch is simple: run AI coding agents in fully autonomous mode, without worrying about them touching your host machine. I read it and decided to install it on my MacBook Pro M4 (32 GB RAM) and test it for real. Not to read the documentation and summarize it, but to actually break things, observe what happens, and verify the security claims hands-on. ...

April 7, 2026 · 17 min · 3567 words · Matteo Bisi