Security Insights
Practical cybersecurity guidance, threat intelligence, and industry perspectives from the Helm team.
458 packages. 5 ship to production. The rest are attack surface.
A serverless pipeline that watches RSS feeds, summarizes new posts with an LLM, and emails subscribers, built entirely with Azure Logic Apps, Terraform, and no long-lived secrets.
Vulnerability management hinges on good architecture practices. AI-powered vulnerability discovery doesn't solve for this in any meaningful way.
The Vercel incident is a good reminder: do you actually control what OAuth apps can access your Google Workspace?
Textbook PyPI supply chain attack, now targeting AI infrastructure. Treat your LLM stack like any other production dependency.
Read all articles and subscribe for weekly insights.
Subscribe on Substack →Topics We Cover
Breach analysis, response lessons, and IR best practices
Emerging attack techniques and threat actor TTPs
Securing AI tools, prompt injection, and AI governance
HIPAA, NIST, and practical compliance guidance