ATALAIA
  1. Home
  2. Resources
  3. Blog
Blog

Notes from the line.

Short, practical writing on application security, one station at a time.

All posts

DetectionOpinionThreat intel for engineers: check your stack, ignore the rest

Most threat intel is not for you. The useful part is a fast answer to one question: is this advisory in what we actually run?

4 min read
PipelineDeep diveWhat is actually running?

Trace a container in production back to its commit, build and pull request using image digests, OCI labels and attestations.

3 min read
PipelineChecklistWho can unlock prod? A deploy approvals checklist

Required reviewers on a production environment only work if the person who wrote the change cannot also approve it. Run this checklist to find out.

3 min read
TestingChecklistAre you ready for a bug bounty?

A checklist to run in one meeting before you invite outside researchers: disclosure basics, scope, triage SLAs, reward structure and the loop that turns reports into fixes.

4 min read
AI & toolingChecklistHardening a developer laptop in a day

Five controls, one working day: encrypted disk, secrets out of dotfiles, protected SSH keys, signed commits and tokens that can only do their job.

3 min read
TestingGuideAuthorisation tests your QA team can own

Broken access control is the bug QA is best placed to catch. A role by endpoint matrix and a few lines of pytest make it routine.

3 min read
DetectionGuideFrom pentest findings to SOC detections

Every pentest finding tells you how someone attacked you. Use it twice: fix the bug, then write the detection that would have caught the attempt.

4 min read
Supply chainGuideOne gate for every install

Route every package through one proxy, make new versions wait a few days, switch off install scripts and let the lockfile decide.

3 min read
ProgramOpinionPolicies engineers actually read

Short policies mapped to real controls, with evidence pulled from your pipelines, beat long documents nobody opens until the audit.

3 min read
TestingGuideWhich diffs deserve a human security review

You cannot security-review every pull request. Route the few that matter to people who know what to look for, using paths and CODEOWNERS.

3 min read
AI & toolingDeep diveThe IDE extension problem

Editor extensions run as your code, with your files and your tokens. How they work, how to inventory them, and how to build an allowlist people will accept.

4 min read
Supply chainGuideSBOM, provenance and signatures in plain words

Three artefacts, three questions: what is inside, who built it and has it changed. Here is how to produce and check each one.

4 min read
ProgramGuideFrom a team of one to a working program: a 90-day plan

A station-by-station plan for the lone security engineer, plus four measures that tell you whether the program is actually working.

4 min read
DesignOpinionKeep your threat model in layers

A single threat model document is out of date the week after the workshop. Split it into layers and update each one when that layer changes.

4 min read
AI & toolingDeep diveWhat an MCP server can reach

An MCP server runs with your tokens, your filesystem and your network. Here is what that means, and how to inventory and scope it.

4 min read
PipelineGuidePin your actions: a one-afternoon fix

Tags move, SHAs do not. Pin every action, let a bot keep them current and cut the token down to what each job needs.

3 min read
TestingGuideReading a pentest report like an engineer

A pentest report is a list of bugs with evidence. Triage it, reproduce it, fix the root cause, and make sure each finding can never quietly return.

4 min read
DesignDeep diveTrust boundaries you can draw on one page

If your architecture diagram cannot show where trust changes, it cannot tell you where the attacks go. Here is how to draw one that does.

4 min read
PipelineOpinionScans that developers do not mute

Running every scanner on every commit is easy. Getting developers to read the output is the real work, and it starts with showing less.

3 min read
Supply chainDeep diveAnatomy of a malicious package

Four ways a bad package reaches your build, what each one looks like in a manifest or a log, and how to check yourself.

3 min read
ProgramOpinionYour first security hire

When to hire, which profile to look for first, what the first 90 days should produce, and when a fractional lead is the smarter opening move.

4 min read
DesignGuideAbuse cases belong next to user stories

Write the misuse story in the same ticket as the feature, and security requirements stop being a document nobody opens.

4 min read
DesignGuideThreat modeling, together

Why the best threat models happen with business, developers and cyber in one room, and how to run one in an hour.

3 min read