When Evaluating the Security of Your Project, Start With the Placeholder

We spend an enormous amount of time trying to secure software. We run SAST. We scan dependencies. We scan container images. We run IaC scanners. We check Kubernetes configurations. We monitor runtime behaviour. We build SBOMs. We integrate everything into CI/CD and create dashboards full of vulnerabilities, CVEs and security findings. And yet sometimes the most interesting security problem is not a vulnerability in our software at all. Sometimes it is a placeholder. ...

September 29, 2026 · 8 min · 1557 words · Matteo Bisi

MicroVMs vs Containers for AI Agents: ECB Cybersecurity Guide

AI agents have turned sandboxing from an engineering detail into a leadership decision. A capable agent can install tools, read source code, build experiments, retry failed approaches, and search for a path out of its environment for hours. The old question, “Do we have a sandbox?”, is no longer enough. Trail of Bits showed why in its VM escape experiment with a cyber-capable AI agent. The agent repeatedly escaped a QEMU/KVM environment by combining known but unpatched host weaknesses, fixes not yet included in the distribution, and eventually new vulnerabilities. The lesson is not that virtual machines are useless. It is that no technical boundary provides complete containment on its own. ...

September 21, 2026 · 9 min · 1728 words · Matteo Bisi

Shift Left Starts in the IDE: VS Code Security in 2026

I have been preparing talks for DevSecOps Day in Bologna this October, and I keep landing on the same sentence: if your shift left story starts at the pipeline, you are already late. In most orgs, shift left still means moving SAST and SCA earlier in CI. Signed images and policy as code are useful. None of them help if the first credential theft happened in the editor, on a laptop, while someone was trying to be a good engineer. ...

September 15, 2026 · 9 min · 1838 words · Matteo Bisi

Who Owns NIS2 and DORA in a Platform Team

I keep seeing the same meeting. Someone from legal or risk drops a NIS2 control, a DORA article, or a “can we evidence this” request into the room. The Kubernetes platform team looks at security. Security looks at the platform team. A ticket lands on the security board, because that feels like the responsible place. Three sprints later the cluster has not changed, the evidence still does not exist, and everyone is slightly angry at the security lead. ...

September 10, 2026 · 11 min · 2151 words · Matteo Bisi

The EU Cyber Resilience Act: A Practical Roadmap

If you make, distribute, integrate, or buy software and connected products in the European Union, you should assess whether the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies. The CRA entered into force on 10 December 2024 and, as a regulation, does not need national transposition. Its main product obligations apply from 11 December 2027, while manufacturer reporting duties start on 11 September 2026. The OpenSSF 2026 CRA Awareness and Readiness Report, published by The Linux Foundation, surveyed 843 organizations and analyzed more than 12,000 open source projects. It points to a material readiness gap. It is useful evidence of what surveyed organizations are experiencing, not a measure of the whole industry. ...

August 20, 2026 · 12 min · 2483 words · Matteo Bisi

SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic

It is a Sunday morning in August, the kind of weekend where the plan is coffee, a quiet walk, and maybe some reading that has nothing to do with work. Instead, I am three articles deep into a Linux kernel vulnerability write-up, taking notes, and mentally drafting a threat model. The notification came in on a weekend, and when something with this much claimed impact lands, it is worth investigating even if your calendar says otherwise. ...

August 9, 2026 · 10 min · 2031 words · Matteo Bisi

OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams

The OWASP GenAI LLM Top 10 2026 was published on August 3, 2026. I am still learning my way around AI security, and I read OWASP Top 10 lists because they are the closest thing the industry has to a consensus map. They are not academic papers. They become the basis for threat models, security review checklists, and procurement questions. The GenAI edition specifically maps the risks that matter when you build applications around large language models. ...

August 5, 2026 · 6 min · 1111 words · Matteo Bisi

In 2026 I Am Still Asked Why You Need a Centralized Secrets Manager

It’s 2026 and I still get the same question from customers and colleagues: we already encrypt our secrets with git-crypt (or SOPS, or sealed-secrets), why do we need a full secrets manager on top of that? I hear it from platform teams that are otherwise mature, from developers who are genuinely trying to do the right thing, and from managers who see a centralized secrets manager as one more piece of infrastructure to buy, run, and justify. ...

July 17, 2026 · 9 min · 1824 words · Matteo Bisi

ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026

I have written several times about hardened images, SBOMs and CNAPP on this blog. I am coming back to them once more because this time the push does not come from a vendor or a conference talk, it comes from the ECB. When a supervisor tells bank CEOs to accelerate patching and prove control over their software supply chain, the technologies I keep recommending stop being nice to have and become the evidence you bring to your Joint Supervisory Team. This article connects the letter to that practical toolbox. ...

July 10, 2026 · 6 min · 1254 words · Matteo Bisi

Back to Basics: TLS and PKI from the Ground Up

This is the third article in my “Back to Basics” series. The goal is simple: take something modern engineers interact with daily through abstractions, and explain what is actually happening underneath. In the first article, I hardened an SSH daemon and explained why the defaults are insecure. In the second, I showed that containers are ordinary Linux processes wrapped in namespaces and cgroups. This article applies the same approach to TLS: strip away the abstractions, read the raw structures, and understand what the tooling is doing on your behalf. ...

June 29, 2026 · 16 min · 3263 words · Matteo Bisi