
Why Gecko Isn’t an IaC Scanner, and What It Actually Does
Learn why Gecko Security isn’t an IaC scanning tool and what it actually does. Compare IaC scanners with application security testing.
Artemiy Malyshau
Vulnerability research, CVE write-ups and practical guides from the team building Gecko. Written for the engineers who have to fix the thing, not just triage it.

Learn why Gecko Security isn’t an IaC scanning tool and what it actually does. Compare IaC scanners with application security testing.
Artemiy Malyshau

When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs during npm test and silently give an attacker full access to the developer’s machine.
Jeevan “JJ” Jutla

Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the gap.
Jeevan “JJ” Jutla
Showing 25 - 27 of 47 articles
Occasional updates and insights. No spam; unsubscribe anytime.