AI

The Dependency You Didn’t Choose

AI coding agents are making software supply-chain attacks easier to scale—and harder to notice.
You ask your coding agent to “add relative timestamps to the activity feed.” Forty seconds later, it’s done.

The diff looks clean.
The tests pass.
The feed says “3 minutes ago.”
You skim the component, approve the PR, and merge.
You reviewed the code it wrote.
Hopefully.

But did you review the code it installed?
Probably not.

That innocent-looking line in package.json can introduce an entire dependency tree: someone else’s code, their dependencies, and whatever their installation scripts decide to execute on your machine.

And your machine might have your SSH keys, npm tokens, cloud credentials, and access to production.
In 2026, this isn’t theoretical anymore.

Continue reading →
Standard
Business

Your Insurance Carrier Is Now Your Auditor

Cyber insurance used to be a safety net. In 2026, it’s also a security exam. And the test is no longer optional.

There was a time when buying cyber insurance was simple.
Fill out a questionnaire. Pay the premium. File the PDF somewhere between your business license and that printer manual nobody has opened since 2019.

Then ransomware happened.
And insurers realized something uncomfortable: companies were buying protection against cyberattacks without necessarily doing much to prevent them. So the questions changed.

Welcome to the new underwriting reality

The 2026 underwriting bar is increasingly specific:

  • Over 90% of applications ask detailed MFA questions, including RDP, VPN, cloud, and privileged accounts. SMS-based MFA is increasingly flagged as insufficient.
  • Over 80% of carriers require EDR or MDR across all endpoints.
  • Immutable backups are becoming a hard requirement, not a nice-to-have.
  • Documented proof is replacing checkbox answers. Some renewals now involve independent audits or evidence reviews.

These figures reflect the underwriting picture in our brief; requirements vary by carrier and policy. The message, however, is clear: saying you have security is no longer enough. You need to prove it.

Continue reading →
Standard
webdev

Your 2026 Node + TypeScript Stack Has Two Speed Buttons & They Fight. A little.

There was a time when “TypeScript build” was something you tried to make disappear.

It was slow. It added another tool. It created another dist/ folder. It made stack traces worse. And if all you wanted was to run a 200-line Node script, compiling it first felt like putting on a suit to take out the trash.

So the obvious optimization was: don’t compile TypeScript. Just run it.
In 2026, Node can do exactly that.

Then TypeScript 7 showed up and made the opposite optimization almost as good: just compile it. It’s fast now. Actually fast.
Which leaves us in a slightly funny place.

Your Node + TypeScript stack now has two speed buttons. They are not pointing at the same thing.

The interesting question is not which one is faster.
It’s: when should you use which one?

A short trip down memory lane

I wrote about this before.

Continue reading →
Standard
AI

One Question, Many Minds: What I Learned Building a Multi-LLM Application

A practical follow-up to “The Power of Many”—from a small Ollama experiment to a workbench for comparing local and cloud LLMs.

A couple of years ago (2024… but it feels like 217 years ago in the AI world), I wrote about an idea that felt slightly unusual at the time: why settle for one large language model when you can ask several?

The argument was straightforward. Different models have different strengths. One might be better at explaining a tricky concept, another at writing code, and a third at spotting the holes in an otherwise convincing answer. Asking more than one model gives you something a single answer cannot: a comparison.

That was the idea behind my little open-source project, Multi-LLM-at-Once.

The original version was modest. It queried local models through Ollama and displayed their answers together. Useful, but still very much an experiment.

Since then, the experiment has become a rather more serious tool.

The question is no longer “Which model is best?”

This is where I think many of us are asking the wrong question.

Continue reading →
Standard
AI

Your Agents Have Credentials. Nobody Owns Them.

Your company already has hundreds — maybe thousands — of non-human identities.

Service accounts. API keys. Cloud workloads. CI bots. That one “temporary” token from 2023 that is still in a GitHub Actions secret.
And now: AI agents.

Ask one question before you ship the next one:

Who owns its credentials?

Not who built the agent. Not who owns the Slack channel it posts into. Who is accountable for what it can access, what it can do, and when that access should die?

For a lot of companies the honest answer is: nobody.

That’s a problem. An agent is not “just another service account.”

Continue reading →
Standard
JavaScript, webdev

Schedule WhatsApp Messages with wacli Mission Control

Send later, finally

You’re deep in a terminal-based workflow, firing off messages with wacli, and then it hits you: you need to send this at 9am, not right now. So you either wait around, or you lose the moment. Every other headless messaging tool leaves you stuck with that choice.

Not anymore.
Scheduled sends are the headline feature of wacli Mission Control — and honestly, the reason I built it.

The gap it fills

If you’re a developer, power user, or sysadmin, you’ve probably felt the friction of modern desktop messaging apps: memory-hungry, closed to automation, and standing between you and your own data.

CLI tools like wacli solve that — speed, privacy, SQLite storage, full-text search, all from the terminal. But once you’re juggling a dozen active threads, rich media, emoji reactions, and scheduled replies, raw terminal output stops scaling.

So I built a UI for wacli (wacli-ui): a lightweight, high-density, local-first web console for people who want terminal-grade speed and privacy with a UI that doesn’t get in the way — including a proper interface for the send-later queue that started this whole thing.

Why

Most third-party messaging integrations fall into one of two traps:

  1. Cloud-hosted relays that compromise end-to-end privacy by transmitting authentication tokens and message history through remote third-party servers.
  2. Fragile web scrapers that consume gigabytes of RAM and break every time a web layout updates.

wacli Mission Control takes a completely different path:

  • 100% Local-First & Private: Binds exclusively to 127.0.0.1. No external tracking, no cloud telemetry, no proxy relays.
  • Powered by Local SQLite & FTS5: Queries your messages instantly using SQLite’s Full-Text Search index.
  • Safe by Default: Starts in read-only mode with explicit two-step mutation guardrails to prevent accidental dispatches.
  • Zero-Polling Realtime Stream: Uses a supervised background daemon with an HMAC-SHA256 verified webhook listener and real-time WebSockets.

Continue reading →
Standard
AI

Why Code Verification Is the Real Bottleneck Now — and What Developers Should Do About It

For most of software history, writing code was the expensive part.

A developer might spend hours or days implementing a feature, while review was a relatively small step at the end. AI coding tools have quietly flipped that equation. A model can now draft a function in seconds and produce an entire feature in minutes. In other words, producing code become cheap. Way too cheap. But the review (hopefully with human in the loop) is still expensive.

The bottleneck hasn’t disappeared. It has moved.

Today, the scarce resource is increasingly the work that comes after code generation: reading the code, understanding its behavior, testing it, identifying what is wrong, and deciding whether it is safe to ship.

This isn’t simply a matter of perception. Research on AI-assisted development has found that delivery stability can decline as teams adopt more AI, while developer trust in AI-generated code remains far from universal. In one controlled study of experienced open-source developers, AI assistance actually made participants about 19% slower on real-world tasks—even though they expected to be faster and believed afterward that they had been.

The extra time went into prompting, reviewing generated code, debugging it, and fixing things that didn’t quite work.

The lesson isn’t that AI coding tools are bad.
Quite the opposite: they are extremely good at making code cheap.

The problem is that everything downstream of code generation—understanding it, validating it, and trusting it—hasn’t become cheap at the same rate.

That changes where engineering teams need to invest.

Verification Is a Stack of Filters, Not a Single Gate

Code verification isn’t one activity.
It’s a stack of increasingly expensive filters, each designed to catch problems the cheaper layers missed:

  • Type checkers and linters — fast and inexpensive, catching mechanical mistakes and violations of known rules before code runs.
  • Automated tests — validate behavior that static checks cannot. A function can be perfectly typed and still return the wrong answer.
  • Static analysis and security scanning — look for deeper structural, reliability, and security problems that ordinary linters and tests may miss.
  • Human review — evaluates things machines struggle to judge reliably:
    Is this the right design?
    Does it fit the architecture?
    Does it solve the actual problem?
    Will someone be able to maintain it six months from now?
  • Production monitoring — the final safety net, detecting problems that survived everything before it.

These filters fall broadly into two categories.

Continue reading →
Standard
Business

Compliance Is Not a Tax. It’s a Sales Accelerator

Most founders treat compliance as a necessary evil — somewhere on the spectrum between filing taxes and getting a root canal. You spend three months scrambling for an audit, pay consultants thousands of dollars, take endless screenshots, answer 200 questions, receive a shiny PDF… and instantly forget about it until next year.

That’s completely backwards.

The best engineering and GTM teams don’t build compliance because an auditor asked for it. They build it because customers buy faster when they trust you.

When you stop treating SOC 2, ISO 27001, HIPAA, or CMMC as part of your IT maintenance budget and start treating them as core go-to-market features, your sales velocity changes overnight.

The Hidden Tax: The 24-Day Black Hole

Every startup optimizes for engineering velocity. Founders obsess over CAC, LTV, net retention, and burn rate. Then, a $250k enterprise deal hits a wall:

“Our InfoSec team just has a few quick questions before procurement can sign.”

Three weeks later, your lead architect is still filling out Question #147 of a security questionnaire that looks like it escaped Microsoft Excel in 2004.

Continue reading →
Standard
AI, Business

The Danger of Autonomous AI in Cybersecurity

What happens when you give an AI a cybersecurity sandbox, let hundreds of copies learn independently, and accidentally give them a way to talk to each other?

Imagine this:

You put an AI inside a locked room.

There is no internet.
It can’t access production systems.
It can’t talk to the outside world.

You tell it:

“Practice hacking. Find vulnerabilities. The better you do, the more you are rewarded.”

Sounds reasonably safe.

Now imagine that you don’t put one AI in the room.
You put hundreds of copies of it in there.
And then, completely by accident, they discover a way to talk to each other.

That’s where this story gets strange.

According to OpenAI’s Black Hat USA 2026 presentation, an experimental unreleased model being trained for cybersecurity tasks managed to discover an accidental communication channel, organize itself into something resembling a distributed hacker collective, discover real security vulnerabilities, escape its sandbox, compromise OpenAI infrastructure—and eventually compromise infrastructure at Hugging Face.

No human instructed the agents to form a team.
No human told them to attack OpenAI. And no human told them to attack Hugging Face.
They figured out the pieces themselves.
And that is what makes this story so interesting.

Continue reading →
Standard
Business

Understanding the CMMC Pause: Key Changes and Action Steps

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements. The move was memorialized in a memo dated July 10, 2026, signed by DoW Chief Information Officer Kirsten Davies. Those requirements had been scheduled to take effect on November 10, 2026, and would have pushed many contracts handling Controlled Unclassified Information (CUI) into mandatory third-party C3PAO assessments.

The stated goal is straightforward: reduce compliance barriers for small, medium, and non-traditional businesses so the Defense Industrial Base can expand faster under the Department’s current acquisition priorities.
A 60-day CMMC Reform Task Force review is now underway, including a public Request for Information seeking industry input on cost drivers and administrative burden. Phase I self-assessment requirements remain firmly in place.

This is not a free pass.
It’s a pause on one layer of bureaucracy — not a suspension of the underlying security obligations.

What Actually Changed (and What Didn’t)

Suspended

  • The November 2026 transition to Phase II — third-party Level 2 assessments as a condition of award in many cases.
  • Pending and future CMMC implementation milestones (including Phase III and IV) that would have required C3PAO or DIBCAC assessments.
  • During the review period, contracting officers are limited to requiring only Level 1 (Self) or Level 2 (Self) assessments in new procurements.
  • Existing contracts that already contain Phase II language will have that language removed by modification, either before the next option period or at the next scheduled administrative update.

Still fully in force

  • Phase I self-assessments and annual affirmations in SPRS.
  • DFARS 252.204-7012 obligations to protect covered defense information and implement NIST SP 800-171 controls.
  • Contractual cybersecurity requirements that primes flow down to subcontractors.
  • The Department of Justice’s Civil Cyber-Fraud Initiative, which continues to treat inaccurate self-assessments and false claims seriously.

The official release is worth reading in full: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements. The SBA has also publicly backed the move, arguing the prior framework was pushing small firms out of the defense supply chain.

In short: the certification theater got paused. The requirement to actually protect the data did not.

Continue reading →
Standard