RSSAmplifier

Blog

jimdevsec

Software security, from inside the pipelines. I'm Jim — Dimitrios, more formally — a DevSecOps and application security engineer. I spend most of my time ...

jimdevsec.bearblog.devRSS feed ↗3 posts

Latest posts

My morning cyber briefing now builds itself

Staying current is part of the job in security, but the intake has always been messy: Hacker News in one tab, a few newsletters, vendor advisories, the odd conference recording. Most of it gets skimmed in stolen minutes, and the commute is dead time on top of that. In May, Spotify launched Studio by Spotify Labs , a standalone desktop app in research preview that generates personal audio from a…

My Server Has No SSH Port

A small decision about a one-box setup — and the access-control idea underneath it, which scales much further than the box does. I was standing up a small personal server on AWS — nothing exotic, just a single instance to host a few projects. The launch wizard reached the firewall step and offered the usual default: allow SSH, source 0.0.0.0/0 . Anywhere. By default, the launch wizard offered me…

Vulnerability Discovery Is No Longer the Bottleneck

Where AI vulnerability scanners actually belong in the SSDLC, and why finding the bug was never the hard part In its first month, Project Glasswing pointed an unreleased model, Claude Mythos Preview, at more than a thousand of the open-source projects that hold up the modern internet. The scan flagged 23,019 potential vulnerabilities, of which Anthropic estimated 6,202 as high or…