Author: drweb

What does it take to secure AI agents without slowing developers down? A recent panel explored the answer  I recently joined Zach Lloyd, founder and CEO of Warp; Gavriel Cohen, co-founder and CEO of NanoCo and creator of NanoClaw; and moderator Moriah Hara, founder of a community of more than 3,000 CISOs and a three-time Fortune 500 CISO, for a discussion on one of the biggest challenges facing enterprise security teams today: how to safely unlock the productivity of agentic AI. The rapid rise of agentic AI in the enterprise is putting CISOs in a tough spot. On one hand,…

Read More

TL;DR — Key Takeaways Manual triage is becoming the slowest part of incident response as engineers struggle to connect alerts, telemetry, ownership data and recent changes. Automated triage shortens the gap between detection and action by assembling context, ranking likely causes and recommending safe next steps. The strongest approach combines reliable observability with progressive automation, keeping humans responsible for judgment and higher-risk decisions. Manual triage is becoming the slowest and most expensive part of modern incident response. In distributed systems, the problem is no longer detecting that something is wrong; the real problem is turning noisy alerts, scattered telemetry and…

Read More

Most Linux guides still recommend the same FTP clients they listed years ago, even though some of those projects are no longer maintained. If you install one of them today, you may end up dealing with bugs, compatibility issues, or missing features instead of simply transferring files. FTP (File Transfer Protocol) is a standard network protocol used to transfer files between a client and a server over a network. FTP clients were originally command-line tools, long before graphical file managers became common. Even today, many developers continue to maintain command-line FTP clients because they’re fast, lightweight, and easy to use…

Read More

TL;DR — Key Takeaways Attackers are flooding GitHub with 7,600 fake repositories posing as AI skills and MCP servers, abusing AI coding assistances into tricking developers into downloading malware. Island researchers found Claude Code, Gemini, and ChatGPT could autonomously surface malicious repositories as legitimate options, a tactic dubbed AgentBaiting. The fake repos deliver the long-running SmartLoader/StealC malware chain, which steals passwords, cookies, sessions, screenshots, and other sensitive data. Rather than hacking GitHub, the attackers exploit AI-driven software discovery, highlighting the need to verify repositories and isolate new AI tools before installing them. Threat actors continue to find new ways to…

Read More
SQL

For anyone living through job loss, the end of a routine, or the quiet loss of a working identity.It is late, and you are still awake. Something ended, and the house has gone quiet in a way that has a shape to it. All day you told people you were fine. You are so tired of telling people you are fine.For twenty-five years I was the person companies called at their worst hour, when the systems were down and no one had slept. The machines always had an answer by morning. The people did not. I learned to watch what…

Read More

Predictions from some of the most prominent voices in the technology industry suggest that software engineering could become increasingly obsolete within a year, jolting the developer community in ways that are still unfolding. The ripple effect spreads further across social media and news outlets, with some leaders urging developers to start seriously considering alternative career paths before the window closes.But while AI can generate functional code in seconds, it still cannot handle complex decision-making, understand ambiguous real-world requirements, navigate legacy systems, or take accountability for the behavior of large interconnected systems. Those limitations matter enormously in production environments where the…

Read More