Shift Left Starts in the IDE: VS Code Security in 2026

I have been preparing talks for DevSecOps Day in Bologna this October, and I keep landing on the same sentence: if your shift left story starts at the pipeline, you are already late. In most orgs, shift left still means moving SAST and SCA earlier in CI. Signed images and policy as code are useful. None of them help if the first credential theft happened in the editor, on a laptop, while someone was trying to be a good engineer. ...

September 15, 2026 · 9 min · 1838 words · Matteo Bisi

Lazarus Group Hides Malware in Git Hooks to Target Developers

A few months back I saw a post circulating on LinkedIn about a developer who had been targeted by a fake recruiter. The person had been invited to a “technical assessment,” cloned a repository, and ran the code provided as part of the interview. What followed was a silent drain of every credential stored on their machine. I remember reading it and feeling a specific kind of disgust, not just at the technical sophistication of the attack, but at the deliberate choice to weaponize something as emotionally charged as a job search. ...

May 6, 2026 · 6 min · 1236 words · Matteo Bisi