Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec
Security Architecture, Programming.
Posts
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Inside the complacency and decisions that eroded trust in #Azure — from a former Azure Core engineer.
https://isolveproblems.substack.com/p/how-microsoft-vaporized-a-trillion
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Capability based budgeting: "The point is that the capability—not the org chart or a system boundary—is the unit of planning and delivery."
https://www.niskanencenter.org/federal-it-budgeting-capability/
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Love to see the innovation in the GraphQL space: #Shopify reworked #graphql execution from depth first to breadth for performance gains.
"Almost every GraphQL implementation uses this depth-first pattern, including the canonical graphql-ruby gem that we have used since 2015, and the official graphql-js spec implementation that it follows. In our experience running this execution model with Ruby, we’ve found that it scales poorly."
https://shopify.engineering/faster-breadth-first-graphql-execution
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Rise 8 Livestream with Jennifer Pahlka & Bryon Kroger
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Exploring #wasm lately and finding #wasmcloud kinda fascinating.
They're orchestrating wasm modules on #Kubernetes with #nats as the control plane. A really interesting project that just hit 2.0.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
VM-Class Secure, Millisecond-Fast Cloud-Native Apps With #Hyperlight + #Nanvix
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
#Digital #Sovereignty A Framework to improve digital readiness of the Government of Canada
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
"The invisible #Unicode characters were devised decades ago and then largely forgotten. That is, until 2024, when hackers began using the characters to conceal malicious prompts fed to AI engines. While the text was invisible to humans and text scanners, #LLMs had little trouble reading them and following the malicious instructions they conveyed."
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
"2025’s exploited vendors followed the same pattern we observed last year, with big tech experiencing the most zero-day exploitation and security vendors following directly behind.
...
#Cisco and #Fortinet remain commonly targeted networking and security vendors, while #Ivanti and #VMware continue to see exploitation that reflects the high value threat actors place on VPNs and virtualization platforms."
https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Austrailia's early 2000s experiment with a #SharedServices organization is super interesting.
Super impressed that they actually checked that their #centralization effort was delivering on it's claims.... and it wasn't.
The original business case was "fundamentally flawed" and has "resulted in a total cost to the State of $473 million" instead of the expected savings of $68 million/year.
* 91 per cent of sampled agencies comment that service delivery has deteriorated upon transitioning to shared
services.
* Over 80 per cent of the sampled agencies reported that processing timeframes have worsened
* rolling-in to the DTFSSC has had a detrimental impact on the operations of the majority of rolled-in agencies
"The Authority concludes that the current structure of the DTFSSC is problematic. It is a monopoly provider, with a mandated client base and a lack of meaningful service level agreements. This means that there are minimal incentives for DTFSSC to improve service delivery and few ways in which client agencies can hold DTFSSC accountable"
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
" #eBPF was built to strengthen #Linux visibility and control. It succeeded, but that same capability has created new terrain for attackers. What began as an #observability framework has evolved into a critical security surface, one that defenders can no longer afford to ignore."
https://linuxsecurity.com/features/ebpf-abuse-linux-kernel-visibility-gap
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
#Exploitation in the era of #formalverification A peek at a new frontier with adacore/Spark
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
"The $126M-funded object storage company systematically dismantled its community edition over 18 months, and the fallout is still spreading"
"If your risk model assumes that #CNCF membership means long-term stability, #MinIO is your counterexample."
https://news.reading.sh/2026/02/14/how-minio-went-from-open-source-darling-to-cautionary-tale/
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
The original #lakehouse paper:
Lakehouse: A New Generation of Open Platforms that Unify
#Data Warehousing and Advanced Analytics
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
@joriki@infosec.exchange Big 👍 to Mazzucato's work. That book is new for me. I'll dig in!
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
In #TBS policy there are a number of places where they mention cloud service models as a progression from IaaS > PaaS > SaaS.
It's like commodity SaaS software is end state all initiatives should be aiming for... as though there is nothing unique about running a country that might require software.
#FaaS is furthest up the stack for custom development.
#SaaS is for commodity software.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
My latest attempt at explaining that mandate specific stuff will require custom development, not just procurement.
The weirdly consistent refusal I see (at all levels) in the Canadian government to engage in software development (or even employ programmers) means there are certain things can't/won't get done.
Does this make a clear case for custom dev? How would you argue that point?
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
Digital Transformation = Agile + APIs + AppSec Security Architecture, Programming.
"The PBO said that in the four departments it studied, IT services provided by outside contractors cost taxpayers between 22 and 25.7 per cent more than they would have if the services had been provided in-house."