Notes from the engine room.
Notes on design, engineering and the weird stuff in between.
StyleSmuggler Is a Template Engine Story, Not a Magento Story
CVE-2026-75650 gave unauthenticated RCE on every Magento 2.4.4-2.4.9 install through the email template engine. The lesson lives in every rendering pipeline, not just Adobe's.
Read more- 049Engineering6 min read
binding.gyp Is the npm Attack Vector You Forgot to Audit
The Miasma worm hit 32 @redhat-cloud-services packages by hiding code execution in binding.gyp, not package.json scripts. If your scanner only audits install hooks, you have a hole.
- 048Engineering7 min read
Tag Pinning Is Not Supply Chain Security
The TeamPCP compromise of trivy-action rewrote 76 of 77 tags overnight. If your CI pins to @v0.34.2, you already lost.
- 047Engineering8 min read
Your Replication Account Is the Blast Radius
CVE-2026-6471 turns any REPLICATION-attributed Postgres account into RCE. Here's how to audit the credentials nobody has looked at since 2019.
- 046Engineering6 min read
Your Image Optimization Pipeline Is a Remote Code Execution Surface
The Next.js AVIF CVE wasn't in Next.js. It lived four dependencies deep, in code nobody on your team has ever read, and it ran on every image request.
- 045Engineering8 min read
Three WordPress SSO CVEs in 90 Days All Have the Same Root Cause
SAML signature confusion keeps producing unauthenticated admin takeover. The problem isn't plugin hygiene, it's what you inherit when you delegate auth to a dependency.
- 044Engineering8 min read
Token Spend Is an Architecture Problem, Not a Budget Problem
Uber burned its 2026 AI budget by April. The fix isn't spending controls, it's fixing the lazy agent design that made the bill explode in the first place.
- 043Design7 min read
Your AI Helpdesk Bot Has an Account Takeover Vector You Designed In
Meta's 2026 chatbot password reset exploit wasn't an infra bug. It was an interaction design failure, and your SaaS assistant probably has the same one.
- 042AI7 min read
Context Rot Is Not a Context Window Problem
Bigger context windows don't fix agent drift. Your long-running agent loses the plot because of context rot, and no amount of tokens saves you.
- 041Engineering7 min read
Your Agent Eval Sandbox Is the Attack Surface
The AISI July incident wasn't about frontier model danger. It was about containment design nobody actually does. Here's a checklist to fix that.
- 040Engineering9 min read
The Review Queue Is Now Your Deployment Bottleneck
Agents open more PRs in a day than your team used to see in a month. Your 2023 review process can't keep up. Time to redesign it.
- 039Engineering7 min read
The debug and chalk Hijack Was a Maintainer Identity Failure, Not a North Korea Story
Amazon tied the September 2025 npm hijack of debug and chalk to the same North Korean crew behind the axios compromise. The scary part isn't the attacker. It's the model.
- 038Engineering8 min read
The CRA 24-Hour Clock Starts September 11 and Your Dependency Graph Is the Liability
Article 14 of the EU Cyber Resilience Act lands on your codebase, not your legal team. Here is what the 24-hour reporting rule actually demands from engineering.
- 037Engineering8 min read
Your LLM Gateway Is a Credential Vault, and the LiteLLM Breach Proved It
The March 2026 LiteLLM supply chain attack showed why your AI proxy is the highest-value target in your stack, and why most teams still treat it like a utility library.
- 036AI7 min read
Prompt Injection Is a Code Execution Primitive Now
Microsoft's CVE-2026-25592 showed a single injected prompt driving host-level RCE. Your threat model still treats it like a content problem. That's the bug.
- 035AI8 min read
Stop Constraining Agents With Prompts, Constrain Them With Infrastructure
Stripe's Minions ship 1,300 zero-human PRs a week against a trillion-dollar codebase. The trick isn't a smarter model, it's making the sandbox the permission system.
- 034Engineering6 min read
The Axios Postinstall Hook Was the Whole Attack
Sapphire Sleet published axios@1.14.1 with a RAT in a postinstall hook. OIDC Trusted Publishing didn't save anyone. Here's the misconfiguration that actually let it happen.
- 033Engineering7 min read
AI Is Rewriting Your IAM Layer and Nobody Reviews the Diff
A hands-on audit playbook for the overly broad permissions that LLM-generated backend code quietly bakes into your codebase on every PR.
- 032Engineering9 min read
Server Actions Are Public Endpoints, Treat Them Like It
Every exported Server Action is a callable HTTP endpoint with no auth, no rate limiting, no validation. Here's the hardening checklist we run on every Next.js project.
- 031Design6 min read
The Homogenization Trap: Why Every AI-Designed UI Looks Identical
72% of designers now use generative AI, and the result is a sea of interchangeable SaaS dashboards. Tactile brutalism is the engineering answer.
- 030Engineering8 min read
AI Code Passes CI and Breaks Production Anyway
Your CI was built for deterministic human code. AI output is probabilistic and context-sensitive, and your validation pipeline has no primitives for catching where it fails.
- 029Business6 min read
You Are Paying for AI to Write the Bugs It Will Charge You to Fix
Velocity numbers measuring code written instead of value delivered are how engineering leaders are quietly fooling their own boards in 2026.
- 028Engineering7 min read
Your Tests Passed and Production Still Broke: The AI Verification Gap Nobody Wants to Name
81% of tech leaders report more production failures from AI code even with 92% pre-deploy confidence. The gap isn't volume, it's the pipeline itself.
- 027Engineering9 min read
The Vercel Breach Is a Template for How OAuth Sprawl Kills You
A hands-on audit guide for finding the silent OAuth grants, stale tokens, and unencrypted env vars that turn one phished laptop into a full breach.
- 026Engineering7 min read
Your AI Dev Toolchain Is the Attack Surface
The June 2026 Microsoft GitHub compromise targeted developers running Claude Code and Gemini CLI. Your AppSec posture was never built for this.
- 025Business8 min read
Your AI Coding Budget Is Buying the Illusion of Speed
84% of developers use AI tools, but org-wide productivity is stuck at 10-30%. Here's where the ROI actually disappears and what to do about it.
- 024Engineering8 min read
SLSA Provenance Did Not Save TanStack
84 malicious package versions shipped with valid SLSA Build Level 3 attestations. The attacker hijacked the pipeline, not the credentials. Provenance signed the malware.
- 023AI6 min read
The METR Productivity Illusion in Real Engineering Work
METR found senior devs were 19% slower with AI but felt 20% faster. That 39-point gap should change how you measure AI tooling.
- 022AI9 min read
Structured Outputs Guarantee Syntax, Not Sanity
GPT-4o's JSON mode gives you valid JSON. It doesn't give you correct data. Here's why that distinction is destroying pipelines.
- 021AI10 min read
Postgres + pgvector 0.8 Is Probably Enough for Your Embeddings
Before you spin up Pinecone or Qdrant, read this. We benchmarked pgvector 0.8 HNSW against Qdrant 1.13 and the results will bore you in the best way.
- 020AI12 min read
Tool Calls Are Not Actions: Build an Approval Queue First
The gap between an LLM returning a tool-call and actually running it against live data is where AI features go wrong. Here's the concrete pattern.
- 019AI8 min read
Structured Outputs Guarantee Shape, Not Semantics
JSON mode doesn't mean your LLM output is safe to use. Here's why you need a schema contract layer on top of it.
- 018AI9 min read
Structured Outputs Don't Mean Your LLM Data Is Correct
Schema conformance is trivially easy. Semantic correctness is where LLM pipelines actually fall apart, and most teams never notice until production.
- 017Engineering9 min read
Stop mocking your database: Postgres 17 makes it unnecessary
Mocking your DB keeps tests green and production broken. Here's how transaction savepoints and schema isolation fix that.
- 016AI9 min read
Your AI Feature Ships Fast and Rots Faster
Shipping a GPT-4o integration takes a weekend. Maintaining it takes a policy. Here's the one-page lifecycle template we actually use.
- 015Engineering9 min read
Postgres Outbox Beats RabbitMQ for Webhook Ingestion Under 5k RPM
Before you bolt on SQS for webhook reliability, read this. A Postgres outbox table and a Go worker will serve most startups better.
- 014Engineering9 min read
Postgres RLS Is Your Real Tenant Isolation Layer, Not Django
Manual WHERE clauses in your ORM will eventually leak tenant data. Here's how to wire Postgres 17 RLS into Django 6.x properly.
- 013Engineering12 min read
Stop warming pools: adaptive CPU-bursting that actually saves money
Warm pools feel like a win until the AWS bill arrives. Here's a concrete pattern with Go worker pools, Redis token buckets, and KEDA that gets you sub-200ms p95 without paying for idle CPUs.
- 012Engineering12 min read
Edge for delivery, Go for domain
A strict partitioning recipe for Next.js 15 and Go 1.22, with auth, SSR streaming, flags, observability, and none of the hand-wavy edge hype.
- 011Engineering10 min read
One npm package nearly owned our Next.js 15 app
A postinstall hook, a remote loader, and a few ugly hours in CI. The fixes were simple once we stopped pretending JavaScript supply chain risk was theoretical.
- 010Engineering10 min read
Stop Paginating in the Client, Let Next.js 16 Do It
Client-side pagination burns memory, inflates TTFB, and makes UX flaky. Cursor APIs plus route-segment caching fix the mess without a rewrite.
- 009Engineering10 min read
A sane monorepo needs hard boundaries
Monorepos work fine in 2026, if you treat boundaries as code and automate enforcement. Our setup is boring on purpose, and that’s why it holds.
- 008AI10 min read
Swap Encoders Without Torching Retrieval
Embedding model upgrades break search in quiet, expensive ways. This is the rollout playbook we use to ship encoder changes without wrecking retrieval.
- 007Engineering11 min read
Edge observability is mostly a telemetry problem
Next.js 15 edge functions and Go 1.22 services need different observability than long-lived servers. Trace cold starts, collect sampled flamegraphs, and tail-sample hard.
- 006AI10 min read
Don’t ship agent chains to SMB customers
Agentic tool orchestration looks clever in demos and turns ugly in production. Use typed function calls, deterministic proxies, and explicit fallbacks instead.
- 005Engineering10 min read
Stop shipping business logic in Next.js edge
Use Edge for fast decisions, keep stateful work in Go. This split fixes correctness bugs, retries, and observability holes that keep showing up in SaaS systems.
- 004Engineering10 min read
Kill the GraphQL gateway at 12 services
Federation adds a governance tax most mid-stage startups can't afford. Typed OpenAPI and consumer-driven contracts bring back speed and make failures obvious.
- 003Engineering9 min read
Zero-Downtime Django Postgres Migrations Need Multi-Step Plans
Safe schema changes in a Django monolith come from staged rollouts, backfills, and boring operational discipline. Squashed migrations won't save you.
- 002Engineering14 min read
Multi-tenant Postgres 16: pick RLS unless proven otherwise
Most SaaS teams should default to Row Level Security in Postgres 16. The hard part isn't SQL, it's pooling, migrations, and operational discipline.
- 001Engineering10 min read
Stop Forcing Analytics Through Django ORM
Reporting code packed into chained QuerySets gets slow, fragile, and unreadable. Put heavy analytics back in SQL, where Postgres can actually help you.