When Evaluating the Security of Your Project, Start With the Placeholder

We spend an enormous amount of time trying to secure software. We run SAST. We scan dependencies. We scan container images. We run IaC scanners. We check Kubernetes configurations. We monitor runtime behaviour. We build SBOMs. We integrate everything into CI/CD and create dashboards full of vulnerabilities, CVEs and security findings. And yet sometimes the most interesting security problem is not a vulnerability in our software at all. Sometimes it is a placeholder. ...

September 29, 2026 · 8 min · 1557 words · Matteo Bisi

The EU Cyber Resilience Act: A Practical Roadmap

If you make, distribute, integrate, or buy software and connected products in the European Union, you should assess whether the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies. The CRA entered into force on 10 December 2024 and, as a regulation, does not need national transposition. Its main product obligations apply from 11 December 2027, while manufacturer reporting duties start on 11 September 2026. The OpenSSF 2026 CRA Awareness and Readiness Report, published by The Linux Foundation, surveyed 843 organizations and analyzed more than 12,000 open source projects. It points to a material readiness gap. It is useful evidence of what surveyed organizations are experiencing, not a measure of the whole industry. ...

August 20, 2026 · 12 min · 2483 words · Matteo Bisi

SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic

It is a Sunday morning in August, the kind of weekend where the plan is coffee, a quiet walk, and maybe some reading that has nothing to do with work. Instead, I am three articles deep into a Linux kernel vulnerability write-up, taking notes, and mentally drafting a threat model. The notification came in on a weekend, and when something with this much claimed impact lands, it is worth investigating even if your calendar says otherwise. ...

August 9, 2026 · 10 min · 2031 words · Matteo Bisi

OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams

The OWASP GenAI LLM Top 10 2026 was published on August 3, 2026. I am still learning my way around AI security, and I read OWASP Top 10 lists because they are the closest thing the industry has to a consensus map. They are not academic papers. They become the basis for threat models, security review checklists, and procurement questions. The GenAI edition specifically maps the risks that matter when you build applications around large language models. ...

August 5, 2026 · 6 min · 1111 words · Matteo Bisi

ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026

I have written several times about hardened images, SBOMs and CNAPP on this blog. I am coming back to them once more because this time the push does not come from a vendor or a conference talk, it comes from the ECB. When a supervisor tells bank CEOs to accelerate patching and prove control over their software supply chain, the technologies I keep recommending stop being nice to have and become the evidence you bring to your Joint Supervisory Team. This article connects the letter to that practical toolbox. ...

July 10, 2026 · 6 min · 1254 words · Matteo Bisi

2025 CWE Top 25: Mitre's Critical Software Weakness Rankings and Trends

MITRE released the 2025 CWE Top 25 on December 11, 2025, identifying the most dangerous software weaknesses based on 39,080 CVE Records published between June 2024 and June 2025. The list ranks weaknesses by their frequency as root causes in CVE data and their CVSS severity scores, highlighting persistent threats like XSS and SQL Injection alongside emerging issues such as authorization flaws and memory bugs—key priorities for DevSecOps teams securing modern cloud‑native applications. Explore how the 2025 rankings differ from 2024, the top ten shifts, and what CWE root causes reveal beyond CVE trends. ...

December 17, 2025 · 6 min · 1104 words · Matteo Bisi

Understanding the Power of SBOMs: Insights from OpenSSF's White Paper

OpenSSF, the Open Source Security Foundation, is an influential collaborative initiative under the Linux Foundation dedicated to improving open source software security. Bringing together industry leaders, security experts, and developers, OpenSSF drives broad community efforts to address vulnerabilities, foster best practices, and enhance transparency across software supply chains. Among its standout contributions is the advocacy and tooling development around Software Bill of Materials (SBOMs), which have rapidly become indispensable for managing security risks in modern software ecosystems. ...

October 3, 2025 · 5 min · 928 words · Matteo Bisi

Urgent: Zero-Day CVEs Found in Two Major Secrets Managers — Have You Updated Yet?

Today, my manager forwarded me this article about several zero-day CVEs discovered in CyberArk and HashiCorp products. After some time spent researching online, I confirmed that both brands have fixed these CVEs by releasing updated versions!! I’m not surprised that these two big corporations acted quickly and fixed the vulnerabilities; both are well-known and reliable! This event gave me an excuse to write this article and respond to one of the most common questions I get from my customers whenever I share news about a new release of a secrets manager: ...

August 11, 2025 · 2 min · 302 words · Matteo Bisi

The Critical Trio: Secrets Manager, Zero-CVE Images, and CNAPP are Needed (Not Only) for DORA Compliance!

With the Digital Operational Resilience Act (DORA) now in effect across the European Union as of January 17, 2025, financial institutions face unprecedented cybersecurity and operational resilience requirements. Successfully achieving DORA compliance demands a comprehensive security strategy that also includes the following three fundamental components: Robust secrets management Hardened container images with minimal vulnerabilities Unified cloud-native application protection platforms (CNAPPs) These technologies work synergistically to meet DORA’s stringent ICT risk management, asset identification, and third-party oversight mandates. ...

August 7, 2025 · 7 min · 1335 words · Matteo Bisi

SIGHUP Secure Containers: how do you choose the oci base image for your workload?

I believe it’s important to start with a premise: In this article, I’ll talk about a product/service built and offered by my current employer, SIGHUP. No one from my company has asked me to publish this blog post here; these are my honest opinions about Secure Containers. Secure Containers is a paid service built by SIGHUP that provides secure, hardened, and updated container base images. Developers working with containers and images now enjoy several advantages compared to the past, such as standardization, automation, and faster release times. ...

April 13, 2023 · 2 min · 271 words · Matteo Bisi