Tag: security

  • don’t keep PII

    high-value credential – a passport – was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk.” It’s always best to delete whatever you no longer need. 🔗 One Million Passports Leaked Online

    Read more

  • Top-down diagram of an attic bedroom. Two blue vertical lines mark the windows on opposite walls; a black circle representing an exhaust fan sits in front of the right window. A green rounded rectangle labeled

    AI Coding Costs Overtake Salaries, Broadcom’s Intelligence Processor, and sovereign cloud – Related to your interests, Thursday

    Defeat AI-Powered Threats with VMware Tanzu Spring Here’s the panel I hosted on how the Spring project is adapting to AI-powered threats. We covered the volume spike in Spring security reports, the kinds of vulnerabilities the models are good at finding, chained “narrative” attacks, the three-bucket fix/fork/ditch triage for open source deps, the clean-room rebuild…

    Read more

  • How AI change your software development organization

    How AI change your software development organization

    A catch-up with Purnima Padmanabhan, GM of the Tanzu Division at Broadcom, on what her team has actually learned shipping enterprise software with AI for the last year and a half: code generation is the small part, beautiful code is the new uncanny valley, and you cannot solve the agent boundary problem from inside the…

    Read more

  • Enterprise Harness Smack-Talk, Forms Don’t Love You Back, and Doing Nothing on Purpose – Related to your interests, Friday

    Enterprise Harness Smack-Talk, Forms Don’t Love You Back, and Doing Nothing on Purpose – Related to your interests, Friday

    Also: Anthropic’s 80% code claim, and Claude’s quiet enterprise share. From: Broadcom’s Investment in Spring to Combat AI-Fueled Security Challenges in the Enterprise As the chart shows, there’s been a huge jump in CVEs for Spring – this is what’s happening everywhere, you know. My work, Tanzu, has been focusing on this and has changed…

    Read more

  • Flood of security patches: Spring Framework ed.

    Flood of security patches: Spring Framework ed.

    Community security reports for Spring, by month. In April, utilizing new scanning capabilities, we received an unprecedented 482 new security reports across 65 scanned projects. Of those 482 new reports, 370 came from our internal scanning capabilities and 112 came from the community. This means that even without the new scanning, we would still have…

    Read more

  • Stochastic Smart Talk, the DIY Platform Trap, and Strategic AI Not Spending – Related to your interests, Friday

    Also: hardened images everywhere, quarterly Java patch tours, Wells Fargo’s complicated employment math, and a Highgate gravestone. Related to your interests Silo busters – a unified platform needs a unified team – “This matters because it removes the structural excuse for fragmentation. When a single platform surfaces all the controls a unified team needs, there…

    Read more

  • security over features

    From what I can tell, every core part of the software stack is stopping what they’re doing and taking care of the flood of new, AI-driven security issues. 🔗 Java Maintenance Engineering Shifts Focus on Quarterly Critical Patch Stabilization

    Read more

  • Why aren’t all images super-secure, or hardned?

    Here’s what I learned: container base images grew up as a developer convenience tool, not a security artifact. Installing extra packages from the command line is one of the first things any Docker tutorial teaches–Docker’s own Dockerfile guide includes apt-get install–and many of the most popular official images ship a full toolchain by default, with…

    Read more

  • Three reasons why a “batteries included” platform is urgently needed right now

    Removing product as a bottleneck: The conversation around PaaS is urgent again, and AI is why. Code generation can speed up your development cycles, building and pushing features faster, but production delays will persist if you’re still deploying at the same speed as before. To avoid eroding the benefits of code generation, you need to deploy…

    Read more

  • Now you can react faster than ever to security problems

    This is an excerpt from our Tanzu Catsup last week. In that episode we talked all about how this AI stuff is changing – for the better – how you can handle security problems at the app layer. It’s Monday morning. Your boss walks up, says “scrap the backlog, we’ve got a list of CVEs…

    Read more

  • Tanzu’s 15-Year Head Start, Max Headroom in Every Terminal, and Doctors Catch the AI Bug – Related to your interests, Monday

    Tanzu’s 15-Year Head Start, Max Headroom in Every Terminal, and Doctors Catch the AI Bug – Related to your interests, Monday

    Also: Mirantis acquisition logic, and tech jobs at a 3-year high, so why the layoffs? Here’s the latest Tanzu Catsup: AI lets us find more vulnerabilities, faster than ever. That’s good news. You want to know what’s broken, and you want to patch it. The hard part is the volume. How do you handle it…

    Read more

  • Platform engineering is what makes AI enterprise-ready

    As we’ve found, writing AI-powered software is the easy part. Testing it, securing it, operating it at enterprise scale – that’s where things get interesting. “Guardrails,” all that. Purnima lays this out: a shift from deterministic systems (input goes in, predictable output comes out) to probabilistic ones where agents wander around exploring multiple paths to…

    Read more

  • MCP Security Guide

    My pal Adib Saikali wrote up an MCP security guide covering how to think about securing MCP servers in the enterprise (no lead-generation required, just a straight-up PDF download). It gets into access tiers (open, group, and user-level servers), authentication with OAuth 2.1, identity propagation models (when to use service accounts vs. forwarding user identity),…

    Read more

  • Using AI for security log analysis and how to fix it suggestions: Building on that foundation, leading the list of announcements is a strategy described as an “agentic security operations center” powered by its latest Gemini AI models. Google is introducing adaptive AI agents that can investigate alerts, synthesize intelligence and assist in remediation workflows…

    Read more

  • Developers crave AI tools for various tasks beyond coding, but that’s only about 20% of their work. But, ops people freak out about security and control challenges, like cost, regulatory compliance, and usage tracking.

    Read more

  • In its latest set of predictions, First said that this year, the upper bounds of its 90% confidence interval in fact approaches 118,000 CVEs, and according to the data, realistic scenarios suggest 70,000 to 100,000 disclosed vulnerabilities are “entirely possible”. The median figure for 2026, it said, would most likely be around 59,000.” 🔗 CVE…

    Read more

  • Lots of yes-but’ing here, inc. this gem for y’all security folk: Wall Street doesn’t understand the reluctance of enterprise CIOs to trust startups with mission-critical data or value the expertise needed to run SaaS reliably at scale as much as the shiny new thing. 🔗 A day of reckoning for the AI boom

    Read more

  • Discounts for VMware and Tanzu software: Under this new agreement, [US] agencies can purchase select Broadcom software solutions at a 64% discount off the list price. These offers are valid until May 2027 across the portfollo” 🔗 New U.S. GSA and Broadcom OneGov Agreement to Help Accelerate Federal Agency AI and Security Initiatives

    Read more

  • Relative to your interests, Sunday

    Is Your AI Assistant Creating a Recursive Security Loop? – AI-assisted coding is starting to eat its own tail: the same LLMs that write code are increasingly asked to review it, explain security decisions, and even override their own warnings. That creates recursive trust loops where “explain your reasoning” becomes an attack surface, and models…

    Read more

  • Use yours secrets to get generative AI ROI

    From an article by my colleagues and me: For generative AI (GenAI) apps to deliver real business value, they need access to your company’s proprietary data. Without it, models default to the public data they were trained on–meaning you get the same generic ideas as your competitors. If everyone is starting with the same new…

    Read more