AI

The Dependency You Didn’t Choose

AI coding agents are making software supply-chain attacks easier to scale—and harder to notice.
You ask your coding agent to “add relative timestamps to the activity feed.” Forty seconds later, it’s done.

The diff looks clean.
The tests pass.
The feed says “3 minutes ago.”
You skim the component, approve the PR, and merge.
You reviewed the code it wrote.
Hopefully.

But did you review the code it installed?
Probably not.

That innocent-looking line in package.json can introduce an entire dependency tree: someone else’s code, their dependencies, and whatever their installation scripts decide to execute on your machine.

And your machine might have your SSH keys, npm tokens, cloud credentials, and access to production.
In 2026, this isn’t theoretical anymore.

Continue reading →
Standard
AI

One Question, Many Minds: What I Learned Building a Multi-LLM Application

A practical follow-up to “The Power of Many”—from a small Ollama experiment to a workbench for comparing local and cloud LLMs.

A couple of years ago (2024… but it feels like 217 years ago in the AI world), I wrote about an idea that felt slightly unusual at the time: why settle for one large language model when you can ask several?

The argument was straightforward. Different models have different strengths. One might be better at explaining a tricky concept, another at writing code, and a third at spotting the holes in an otherwise convincing answer. Asking more than one model gives you something a single answer cannot: a comparison.

That was the idea behind my little open-source project, Multi-LLM-at-Once.

The original version was modest. It queried local models through Ollama and displayed their answers together. Useful, but still very much an experiment.

Since then, the experiment has become a rather more serious tool.

The question is no longer “Which model is best?”

This is where I think many of us are asking the wrong question.

Continue reading →
Standard
AI

Your Agents Have Credentials. Nobody Owns Them.

Your company already has hundreds — maybe thousands — of non-human identities.

Service accounts. API keys. Cloud workloads. CI bots. That one “temporary” token from 2023 that is still in a GitHub Actions secret.
And now: AI agents.

Ask one question before you ship the next one:

Who owns its credentials?

Not who built the agent. Not who owns the Slack channel it posts into. Who is accountable for what it can access, what it can do, and when that access should die?

For a lot of companies the honest answer is: nobody.

That’s a problem. An agent is not “just another service account.”

Continue reading →
Standard
AI

Why Code Verification Is the Real Bottleneck Now — and What Developers Should Do About It

For most of software history, writing code was the expensive part.

A developer might spend hours or days implementing a feature, while review was a relatively small step at the end. AI coding tools have quietly flipped that equation. A model can now draft a function in seconds and produce an entire feature in minutes. In other words, producing code become cheap. Way too cheap. But the review (hopefully with human in the loop) is still expensive.

The bottleneck hasn’t disappeared. It has moved.

Today, the scarce resource is increasingly the work that comes after code generation: reading the code, understanding its behavior, testing it, identifying what is wrong, and deciding whether it is safe to ship.

This isn’t simply a matter of perception. Research on AI-assisted development has found that delivery stability can decline as teams adopt more AI, while developer trust in AI-generated code remains far from universal. In one controlled study of experienced open-source developers, AI assistance actually made participants about 19% slower on real-world tasks—even though they expected to be faster and believed afterward that they had been.

The extra time went into prompting, reviewing generated code, debugging it, and fixing things that didn’t quite work.

The lesson isn’t that AI coding tools are bad.
Quite the opposite: they are extremely good at making code cheap.

The problem is that everything downstream of code generation—understanding it, validating it, and trusting it—hasn’t become cheap at the same rate.

That changes where engineering teams need to invest.

Verification Is a Stack of Filters, Not a Single Gate

Code verification isn’t one activity.
It’s a stack of increasingly expensive filters, each designed to catch problems the cheaper layers missed:

  • Type checkers and linters — fast and inexpensive, catching mechanical mistakes and violations of known rules before code runs.
  • Automated tests — validate behavior that static checks cannot. A function can be perfectly typed and still return the wrong answer.
  • Static analysis and security scanning — look for deeper structural, reliability, and security problems that ordinary linters and tests may miss.
  • Human review — evaluates things machines struggle to judge reliably:
    Is this the right design?
    Does it fit the architecture?
    Does it solve the actual problem?
    Will someone be able to maintain it six months from now?
  • Production monitoring — the final safety net, detecting problems that survived everything before it.

These filters fall broadly into two categories.

Continue reading →
Standard
AI, Business

The Danger of Autonomous AI in Cybersecurity

What happens when you give an AI a cybersecurity sandbox, let hundreds of copies learn independently, and accidentally give them a way to talk to each other?

Imagine this:

You put an AI inside a locked room.

There is no internet.
It can’t access production systems.
It can’t talk to the outside world.

You tell it:

“Practice hacking. Find vulnerabilities. The better you do, the more you are rewarded.”

Sounds reasonably safe.

Now imagine that you don’t put one AI in the room.
You put hundreds of copies of it in there.
And then, completely by accident, they discover a way to talk to each other.

That’s where this story gets strange.

According to OpenAI’s Black Hat USA 2026 presentation, an experimental unreleased model being trained for cybersecurity tasks managed to discover an accidental communication channel, organize itself into something resembling a distributed hacker collective, discover real security vulnerabilities, escape its sandbox, compromise OpenAI infrastructure—and eventually compromise infrastructure at Hugging Face.

No human instructed the agents to form a team.
No human told them to attack OpenAI. And no human told them to attack Hugging Face.
They figured out the pieces themselves.
And that is what makes this story so interesting.

Continue reading →
Standard
Three people harvesting tomatoes and tending vegetable plants in a farm garden
AI, Business

Outsmarting Cyber Threats: SMBs Need Multi-Layered Security

If you run a small or mid-sized business, you’ve probably told yourself some version of this story: “We’re too small to be a target. Hackers go after the big fish — banks, hospitals, Fortune 500s.”

I get it. I used to think that too. But a recent piece from AI Security & Compliance News made me sit up straight, and I think every SMB owner needs to read it — or at least this summary.

The rules just changed

For decades, cybersecurity followed a predictable rhythm: attackers find a new trick, defenders patch it, attackers find another trick, repeat. Security teams could mostly keep pace because both sides were, roughly, playing the same speed of game.

That rhythm is broken. Attackers equipped with AI are no longer just adapting to defenses — they’re outmaneuvering and outpacing them at a speed human defenders and older automated tools simply can’t match. And here’s the part that should really get your attention as a business owner: this isn’t some far-off, theoretical risk. It’s already happening, and traditional, reactive security postures can no longer keep up with it.

Wait — attacks without malware?

Here’s the stat that stopped me cold.
Roughly 79% of attacks today don’t use malware at all.

Continue reading →
Standard
AI, webdev

Unlocking WhatsApp: Your Local Analytics Dashboard

A few months ago I wrote about building a local analytics dashboard for WhatsApp using the amazing WaCrawl project.
If you haven’t read it yet, start here:

Unlock Your WhatsApp Data with a Local Analytics Dashboard

Since then, the project has evolved dramatically.
It is no longer just a visualization of your messages—it’s becoming a complete analytics platform for understanding years of conversations while keeping every byte on your own computer.

If you’re the kind of person who has accumulated hundreds of thousands (or millions) of WhatsApp messages, you’ll probably discover things about your communication habits that you never noticed before.

Why Another WhatsApp Analytics Tool?

Most messaging analytics products have one major problem:

They require uploading your conversations to someone else’s servers.
That’s a non-starter for most people.

The dashboard follows one simple rule:
Your messages never leave your machine.

The application reads the local SQLite archive produced by WaCrawl and exposes a read-only API that is only accessible from localhost.

Continue reading →
Standard
Secure data streams from public, hybrid, enterprise cloud, and data sources into a compliance vault engine
AI, Business

Automating the Audit Trail: How I Built a GitHub Screenshoter for Zero-Friction SOC 2 Compliance

It’s audit season. And if you’re a SaaS startup, you know exactly what that means.
The dreaded “Change Management” evidence request.

Some auditor sends you a list of 15 random commit SHAs from your production branch and says: “Prove to me that every single one of these was reviewed, approved, and linked to a ticket.”

Your heart sinks.

You know you’re about to spend the next four hours of your life doing the most mind-numbing task in tech: opening GitHub, finding the commit, taking a screenshot, finding the PR, taking a screenshot, finding the issue, taking a screenshot, and pasting it all into a PDF.

It’s manual. It’s painful. And it’s a complete waste of engineering time.

So, I built a tool to kill this pain once and for all: GitHub Screenshoter.

Continue reading →
Standard
Five agents collaboratively repairing a complex machine labeled Mega-Device X1 in a futuristic lab filled with tools and monitors.
AI, webdev

5-Agent Framework for Code Audits

I’ve been seeing the same anti-pattern everywhere lately.
Someone opens Cursor, Copilot or Claude and pastes a giant prompt:

Continue reading →
Standard