
Why Gecko Isn’t an IaC Scanner, and What It Actually Does
Learn why Gecko Security isn’t an IaC scanning tool and what it actually does. Compare IaC scanners with application security testing.
Artemiy Malyshau
Vulnerability research, CVE write-ups and practical guides from the team building Gecko. Written for the engineers who have to fix the thing, not just triage it.

Learn why Gecko Security isn’t an IaC scanning tool and what it actually does. Compare IaC scanners with application security testing.
Artemiy Malyshau

When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs during npm test and silently give an attacker full access to the developer’s machine.
Jeevan “JJ” Jutla

Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the gap.
Jeevan “JJ” Jutla
Authentication bypass in n8n’s StripeTrigger node allows unauthenticated attackers to forge arbitrary Stripe webhooks without knowing the signing secret.
Artemiy Malyshau
Path traversal vulnerability in n8n’s Webhook node allows attackers to write files to arbitrary locations on remote servers connected via SSH.
Artemiy Malyshau

The gap between tracking where data flows and reasoning about whether the logic is correct.
Jeevan “JJ” Jutla
Showing 25 - 30 of 47 articles
Occasional updates and insights. No spam; unsubscribe anytime.