Skip to main content

Insights

Engineering, security, and infrastructure, from the perspective of those who live it.

Explore by topic

26% of AI spend is wasted (and nobody knows who pays)

Harness State of AI in FinOps: 1 in 5 companies spends $1M+/month on AI and 52% have no cost owner. The 26-point gap between writing and enforcing rules.

Gabriel FerraresiOct 6, 20263 min read
finopsaiwaste+2

AI regulation one vote away: R$ 50 million fines ahead

Brazil’s AI bill (PL 2338) is in its final House vote with fines up to R$ 50 million and the ANPD in charge. What changes for anyone running AI in production.

Gabriel FerraresiOct 6, 20263 min read
airegulationbrazil+3

R$ 2 trillion in tech by 2029: data centers at the center

Brasscom: R$ 2 trillion in tech from 2026 to 2029, R$ 252.4 billion in data centers. 38 GW in the grid queue, 88% renewable matrix, and the tax bottleneck.

Gabriel FerraresiOct 6, 20263 min read
brazildata-centerscloud+3

ReData approved: R$ 5.2 billion to unlock data centers

The Senate approved the Datacenter Tax Regime: 5 years of equipment tax suspension with counter-commitments. What changes in practice for the market.

Gabriel FerraresiOct 6, 20263 min read
redatadata-centerstaxes+2

Social engineering: the most expensive firewall is human

90% of breaches start with phishing, not exploits. Turning the weakest link into a defense line: simulations, training, and a report button.

Gabriel FerraresiOct 6, 20263 min read
social-engineeringphishingawareness+3

VPS vs shared hosting: when to upgrade, with real numbers

LVE caps at peak, add-on invoices, denied resources: the 4 signs it is VPS time, with real migration prices and specs. Downtime-free method included.

Gabriel FerraresiOct 6, 20263 min read
vpshostingmigration+2

Corporate portals: is your website’s code actually yours?

Most agencies lease your portal: you pay, they keep the code. Code ownership, lock-in, and the three levels of digital maturity (DXP).

Gabriel FerraresiOct 3, 20263 min read
dxpportalsip-ownership+3

SparroWocky: espionage in LATAM, Brazil off the list

ESET exposes a China-linked year-plus campaign against 8 Latin American governments, screenshots every 500ms. Brazil absent: no reading is comfort.

Gabriel FerraresiOct 3, 20263 min read
aptespionageeset+3

Does your AI agent have a budget? FinOps next frontier

73% of companies have an AI cost policy, only 47% enforce it. Budget per agent, step ceilings and kill switch: the governance between pilot and production.

Gabriel FerraresiOct 2, 20263 min read
aiagentsfinops+2

Jack Henry: When the Vendor Falls, the Bank Falls Too

Core banking for thousands of institutions hit by vishing lost terabytes. Fourth-party risk: did your vendor’s vendor pass your due diligence?

Gabriel FerraresiOct 2, 20263 min read
fourth-partycore-bankingvishing+3

LGPD checklist: incident response in 3 business days

ANPD Resolution 15/2024 set a 3-business-day deadline to notify relevant-risk incidents. The practical checklist for the first 72 hours of response.

Gabriel FerraresiOct 2, 20263 min read
lgpdanpdincident+3

Web hosting: when it holds your site, and when it does not

LVE caps at peak, backups that do not restore, ticket-queue support: how to assess whether your hosting holds the traffic your business needs.

Gabriel FerraresiOct 2, 20263 min read
hostingwebautoscaling+3

ANPD fines TikTok R$ 153.7 million: LGPD shows teeth

Ruling 27/2026 hits ByteDance with a R$ 153.7M fine over teen registrations. What the largest LGPD fine teaches any product handling minors’ data.

Gabriel FerraresiOct 1, 20264 min read
lgpdanpdprivacy+3

Cloud waste: 29% of cloud spend is wasted, says Flexera

Flexera 2026: IaaS and PaaS waste is rising again, now USD 122 billion a year. Idle GPUs cost 20x their price. Where the fix actually starts.

Gabriel FerraresiOct 1, 20263 min read
finopscloudwaste+3

Hypervisor Ransomware: Brazil Ranks Among the Top 5 Targets

Akira, Qilin and DragonForce hit VMware ESXi, Hyper-V and Nutanix with no MFA and network-reachable backups. 2026 reports place Brazil in the top 5.

Gabriel FerraresiSep 30, 20264 min read
ransomwarehypervisoresxi+3

VPS in Brazil: 4ms latency and the cost of hosting far away

Your São Paulo user waits 120ms for a response that could arrive in 4. Latency, LGPD and pricing in local currency: geography is a line item.

Gabriel FerraresiSep 30, 20264 min read
vpsbrazillatency+3

1.4 Trillion Tokens in a Day: When AI Inference Surpassed Training and Became a Digital Public Utility

On April 18, 2026, OpenRouter registered 1.4 trillion tokens processed by Qwen 3.6 Plus in a single day. Inference surpassed training, cost plummeted, and regulation arrived. The architecture behind 370 trillion tokens per day.

Gabriel FerraresiAug 5, 20264 min read
aiinferencetokens+7

471 Million Data Breach Notifications in 6 Months: The ITRC Report Showing That Breach Transparency Is Disappearing

The ITRC H1 2026 Data Breach Report recorded 471.2 million victim notifications in 6 months. Only 24% included attack vector details. Transparency is disappearing.

Gabriel FerraresiAug 4, 20264 min read
securitydata-breachitrc+7

Coca-Cola Refused the Ransom: The Anubis Attack on Fairlife and Why Paying Ransomware with a Wiper Is a Losing Bet

The Anubis attack on Fairlife stopped four US plants for eleven days. The group offers a /WIPEMODE parameter that permanently zeros file contents, even if you pay. Why Coca-Cola refused the ransom and what it teaches about the cold chain.

Gabriel FerraresiAug 4, 20264 min read
securityransomwareanubis+7

313 CVEs in the MCP Ecosystem: The Protocol Connecting AI Agents to Tools Has an Architectural Problem

The Model Context Protocol has 313 indexed CVEs in 18 months. The root cause is architectural: there is no separation between data and control. Tool descriptions are processed as instructions by the LLM, with the same authority as system prompts.

Gabriel FerraresiAug 4, 20264 min read
securitymcpmodel-context-protocol+7

279 Million CPFs at $10,000: The Leak That Exposes the Absence of Consequences Under Brazil's LGPD

In July 2026, 279 million CPFs were offered for $10,000 on the criminal forum breached.su. The third mega-leak of the year exposes data that became a commodity and an LGPD with no effective consequence.

Gabriel FerraresiAug 2, 20264 min read
securitylgpdanpd+7

Minnesota: 30+ Water Systems, Compromised PLCs and the 5-Year Pattern That Became a Crisis

On July 26, 2026, operators of more than 30 water systems across 7 states lost access to their own PLCs. CyberAv3ngers, Rockwell Allen-Bradley and the patch that doesn't exist.

Gabriel FerraresiAug 2, 20264 min read
securityotplc+7

22 Minutes, 631 Malicious Versions: The npm Attack That Exfiltrated 3,800 Repos and Infected AI Agents

Between 01:44 and 02:06 UTC on May 19, 2026, someone published 631 malicious versions across 314 npm packages via account takeover of the atool account. The attack collected 20 categories of credentials, planted hooks in AI agents, and exfiltrated 3,800 private repositories.

Gabriel FerraresiAug 2, 20264 min read
securitynpmsupply-chain+7

World-Class 5G, Worst Cloud Latency of 22 Countries: Brazil's Broken Bridge

Brazilian 5G beats Germany on the radio, but has the worst cloud latency among 22 countries measured by Ookla. The gap that makes real-time AI inference unviable.

Gabriel FerraresiJul 31, 20264 min read
infrastructure5glatency+7

The Inference Flip: When Inference Became 80-90% of AI Cost and Training Became Residual CapEx

Inference went from one-third to two-thirds of all AI compute in three years and now accounts for 80-90% of total production AI spend. Why training became residual CapEx and inference became perpetual OpEx.

Gabriel FerraresiJul 29, 20264 min read
finopsaiinference+7

Cloud Repatriation: 93% of Companies Bringing AI Workloads Back On-Prem

93% of companies have already repatriated or are evaluating repatriation of AI workloads from public cloud. Cloudian and Broadcom data show why cost surpassed security as the top cloud concern in 2026.

Gabriel FerraresiJul 28, 20264 min read
finopscloudrepatriation+7

Zero Trust: 82% Know, 17% Act, 65 Points of Gap Where Attackers Live

82% of organizations consider Universal ZTNA essential. Only 17% have fully implemented it. The 65-point gap is where attackers live, and where the malicious insider costs $4.92 million per breach.

Gabriel FerraresiJul 27, 20264 min read
securityzero-trustztna+7

MFA No Longer Protects: AI Phishing Jumped 14x and AiTM Bypasses Everything

AI-generated phishing jumped from 4% to 56% in one month (Hoxhunt). 59% of compromised accounts had MFA enabled (Proofpoint). AiTM intercepts session cookies. The answer is phishing-resistant MFA.

Gabriel FerraresiJul 21, 20264 min read
securityphishingai+7

BACEN Resolution 5.274: 14 Mandatory Controls, Deadline Passed, Auditor in the Field

Resolução CMN nº 5.274/2025 expired on March 1, 2026. 14 mandatory controls, MFA on Pix and STR, annual pentest, cyber intelligence. The BACEN auditor is already in the field.

Gabriel FerraresiJul 20, 20264 min read
securitybacencmn-5274+7

ANPD Infringement Notice: 500 Thousand Records, Ransomware, and the ISAC Case That Redefined Healthcare Data Enforcement

Administrative Sanctioning Proceeding against ISAC for a ransomware attack affecting 500 thousand records. The case that redefined healthcare data enforcement under Brazil's LGPD.

Gabriel FerraresiJul 19, 20265 min read
securitylgpdanpd+7

One Attack, an Entire Cold Chain on the Ground: the Nichirei Case and the Single Point of Failure

On July 13, 2026, a single attack on Nichirei brought down Japan's cold chain and paralyzed KFC, Kura Sushi, Aeon and Nissui. Lessons on C-SCRM, NIST CSF 2.0 and single point of failure.

Gabriel FerraresiJul 19, 20264 min read
securitysupply-chainransomware+7

Brazil in 3rd Place Globally in Ransomware: The Gentlemen, FortiGate and 241 Days of Dwell Time

In June 2026, Brazil debuted in 3rd place globally in ransomware. The Gentlemen group exploits 14,700 pre-compromised FortiGate devices via CVE-2024-55591. What Tech86 implements.

Gabriel FerraresiJul 18, 20263 min read
securityransomwarethe-gentlemen+7

KIMI 3: 2.8 Trillion Parameters in MoE That Shakes the LLM Podium

Moonshot AI released KIMI 3 with 2.8T parameters in MoE, 16 active experts out of 896, and a 1M token context window. GPQA Diamond at 93.5%, Arena Code WebDev leadership, and open weights on July 27, 2026.

Gabriel FerraresiJul 18, 20264 min read
aillmkimi3+7

Kubernetes at 8%: The Utilization Crisis That Costs 27K Reais per Month in Idle GPU

The Cast AI 2026 report analyzed 23,000 Kubernetes clusters and found average CPU utilization of 8% and GPU of 5%. In Brazil, an idle H100 cluster costs R$27,742 per month. What Tech86 implements to cut the waste.

Gabriel FerraresiJul 18, 20264 min read
finopskubernetesgpu+5

Shadow AI: the new breach category that costs $670K more per incident

IBM created the Shadow AI category in its Cost of a Data Breach Report 2025: $670K additional per incident, a 247-day lifecycle, and 89% of enterprise AI use invisible to security.

Gabriel FerraresiJul 18, 20264 min read
securityshadow-aiai-governance+5

PhantomEnigma: When Trusted Infrastructure Becomes the Weapon

PhantomEnigma hijacked 20 .gov.br portals to deliver banking malware. According to ANY.RUN, the campaign abuses SPF, DKIM and DMARC and delivers a Node.js backdoor inside a modified Electron app.

Gabriel FerraresiJul 16, 20264 min read
securityphantomenigmagov-br+5

CISO: The Broken Mirror Between Facade Proactivity and Structure

82% of Latin American CISOs say they are proactive, but 34% operate without firewall. The passive CISO is a product of structure, and the role is migrating from the factory floor to the boardroom.

Gabriel FerraresiJul 15, 20264 min read
securitycisogovernance+5

Phishing: 1 in 3 Clicks and the Repetition That Closes the Door

33.1% of employees click on phishing before training. After 12 months of continuous simulation, the rate drops to 4.1%. Frequency is the variable that matters most, and the highest ROI control in your security stack.

Gabriel FerraresiJul 15, 20265 min read
securityphishingawareness+5

PIX: The Anatomy of 40 Seconds and the Millisecond Budget

PIX has 40 seconds from the user's tap to settlement in SPI. Every millisecond is budgeted. The architecture sustaining 79.8 billion transactions with isolation, low latency, and BCB compliance.

Gabriel FerraresiJul 14, 20264 min read
architecturepixlow-latency+5

Armored Likho: New APT Maps the Brazilian Power Grid With Generative AI

According to Kaspersky, the Armored Likho APT uses BusySnake Stealer and LLM-generated code against the Brazilian power grid. Silent espionage, no blackout, but clear intent.

Gabriel FerraresiJul 13, 20264 min read
securityaptpower-grid+5

Multi-cloud: the structural irony that multiplied lock-in

Multi-cloud was born to kill vendor lock-in, but multiplied the lock-in instead. 89% of enterprises adopted it; 29% of cloud spend is wasted. The way out is to abstract, not add.

Gabriel FerraresiJul 13, 20264 min read
finopsmulticloudlock-in+6

SOC: 47,000 Alerts a Day and the Structural Fatigue That Benefits the Attacker

47,000 alerts, one SOC, one day. The math that makes coverage impossible, the burnout that feeds dwell time, and why security investment produces insecurity.

Gabriel FerraresiJul 13, 20264 min read
securitysocalert-fatigue+5

CitrixBleed 2: Same Binary, Same Bug, Same Leaked Memory

CitrixBleed 2 (CVE-2025-5777, CVSS 9.3) repeats the buffer over-read in NetScaler nsppe and leaks NSC_AAAC tokens. Patching does not fix it, stolen tokens survive the upgrade. Layered remediation.

Gabriel FerraresiJul 12, 20264 min read
securitycitrixbleednetscaler+5

Silicon Curtain: The Mirrored Wall of AI Between the US and China

The US requires a license to export Anthropic's models; China discusses restricting overseas access to Qwen, Doubao and GLM-5.2. The same wall, from opposite sides, and sovereign inference as the answer.

Gabriel FerraresiJul 12, 20264 min read
aigeopoliticssilicon-curtain+5

Apple vs OpenAI: Trade Secrets, the Auth Bug, and the Lawsuit That May Redefine IP in AI

Apple sued OpenAI for trade secrets after an engineer downloaded a thousand pages via an authentication bug. Case 5:26-cv-07078 and what it teaches about IAM, Zero Trust, and DLP when engineers leave for competitors.

Gabriel FerraresiJul 11, 20264 min read
securityappleopenai+5

JADEPUFFER: Agentic Ransomware Run by an LLM With No Human Operator

JADEPUFFER, disclosed by Sysdig on July 1, 2026, is ransomware operated by an LLM with no human operator. The agent entered via Langflow CVE-2025-3248 and encrypted 1,342 Nacos items with unrecoverable AES_ENCRYPT.

Gabriel FerraresiJul 11, 20264 min read
securityransomwareai+5

AWS GPU +20% and DeepSeek Surge Pricing: The End of Predictable AI Cost

In the same week of June 2026, AWS raised EC2 Capacity Blocks by 20% and DeepSeek introduced surge pricing. AI cost is no longer a straight line.

Gabriel FerraresiJul 10, 20264 min read
finopsawsdeepseek+5

PocketOS: The Agent That Deleted Production, the IAM That Failed, and the Confession That Shouldn't Matter

A Claude Opus 4.6 agent in Cursor deleted PocketOS's production volume and backups, causing a ~30 hour outage. The root cause was not the model, it was IAM. Why system prompts are advisory and RBAC is enforcement.

Gabriel FerraresiJul 9, 20264 min read
aiai-agentsiam+6

ANPD Becomes an Agency: Claro Sanction, 21 Silent Companies, and the End of the Advisory Model

Law 15.352/2026 turned Brazil's ANPD into an autarchy with police power. First sanction against a large private company (Claro), 21 companies forwarded for sanction for not responding to inspection.

Gabriel FerraresiJul 8, 20264 min read
securitylgpdanpd+5

BYOVD: EDR Killers, The Gentlemen, and the Green Dashboard That Lies

Your EDR stopped reporting and the dashboard is green, but the encryptor is already running. BYOVD, The Gentlemen, and the EDR killers that silence your security agent.

Gabriel FerraresiJul 8, 20264 min read
securitybyovdedr+5

GLM-5.2 Self-Hosting: Real Infra, Real Break-Even, and the End of Subsidized Pricing

The real infrastructure we run to serve GLM-5.2 in production: 2 clusters, 8x H200 per rack, measured throughput, and the break-even math against a subsidized API.

Gabriel FerraresiJul 5, 20264 min read
aiglm-52self-hosting+6

Operation Escaneo: CloudSEK Exposes APT-Level Threat Against LATAM

CloudSEK discovered Operation Escaneo in June 2026: Kimera framework, 15 CVEs, Cisco router persistence and SAP/Oracle exploitation. LATAM has graduated to APT-level threats.

Gabriel FerraresiJul 4, 20264 min read
securityaptlatam+4

Autoguardrails: Karpathy's Autoresearch Transposed to AI Safety

Santander AI Lab turned Karpathy's autoresearch into autoguardrails: an agent that searches over policy.md to minimize Attack Success Rate without destroying benign pass. Same turnstile, different metric.

Gabriel FerraresiJul 3, 20264 min read
aiai-safetykarpathy+4

Backdoor.Turn: The Ransomware That Hid Inside Microsoft Teams for 2 Months

DragonForce used the Turn backdoor to abuse Microsoft Teams TURN relay infrastructure as C2. The first malware in the wild to turn collaboration traffic into a command and control channel.

Gabriel FerraresiJul 3, 20264 min read
securityransomwaredragonforce+4

The Honest Mistake: Lateral Movement via WMI That Bypassed 47 Micro-Segmentation Policies

We almost missed a lateral movement attack via WMI during an incident response. The lesson that changed our IR methodology at Tech86.

Gabriel FerraresiJul 2, 20264 min read
securitylateral-movementwmi+2

Dual Attacker: When a Cryptominer is a Smoke Screen for PIX Exfiltration

Real incident response case at a Brazilian payment processor where an XMRig cryptominer hid a second actor exfiltrating digital certificates and PIX transaction data.

Gabriel FerraresiJul 1, 20264 min read
securityincident-responsecryptominer+2

Mythos 5, Fable 5 and the Kill-Switch: One Letter Turned Off AI in 100+ Countries

A Friday letter shut down Mythos 5 and Fable 5 in 100+ countries. The first export control on a commercial AI model via API, and what it means for your infrastructure sovereignty.

Gabriel FerraresiJul 1, 20264 min read
aisovereigntyanthropic+4

Brazil-EU: AI Sovereignty and the R$ 2 Billion Supercomputer

Brazil joins the EU Digital Partnership and announces R$ 2 billion for a sovereign supercomputer. We analyze the two moves and the three bottlenecks that remain.

Gabriel FerraresiJun 30, 20265 min read
aisovereigntybrazil+4

GLM-5.2 Z.AI: The First Open-Weight Frontier at Parity with Claude and GPT

Z.AI's GLM-5.2 is the first open-weights model that sustains production at parity with Claude and GPT, charging a tenth per token. MoE architecture, benchmarks, and deployment.

Gabriel FerraresiJun 29, 20264 min read
aiglmzai+4

WhatsApp Usernames: The Privacy Win That Opens New Attack Surfaces

WhatsApp launched usernames on June 29, 2026, hiding phone numbers but creating squatting, visual similarity phishing, and cross-platform linking. Technical analysis from Tech86.

Gabriel FerraresiJun 29, 20264 min read
securitywhatsappprivacy+2

Dígitro: The Leak That Exposed the Blueprint of State Surveillance

3.39 TB of source code and data from Dígitro leaked on DDoSecrets. Guardião, the lawful interception platform used by 150+ institutions, had its blueprint exposed. Analysis of the technical and legal impact.

Gabriel FerraresiJun 28, 20264 min read
securitydata-leaklawful-interception+2

FortiBleed: The Attack That Turned 430K Firewalls Into Network Sniffers

FortiBleed compromised 86K+ FortiGate firewalls and turned 19K+ into active traffic sniffers. The industrialized operation that abuses legitimate FortiOS commands to capture credentials in real time.

Gabriel FerraresiJun 28, 20265 min read
securityfirewallfortigate+2

Private Cyber Armies: When AI Becomes a Weapon of War

The US government spends $1B on cyberattacks while cutting $1.2B from defense. Two cybersecurity startups reveal the privatization of cyber warfare, and the governance vacuum that comes with it.

Gabriel FerraresiJun 27, 20264 min read
securityaigeopolitics+2

Mechanical Governance for LLMs: The mech-gov-framework and the EU AI Act

27% of LLM deferrals carry zero decision-relevant information. Santander's mech-gov-framework solves this with 4 mechanical primitives, with direct implications for the EU AI Act.

Gabriel FerraresiJun 27, 20264 min read
aigovernanceeu-ai-act+2

Miasma and IronWorm: When the Supply Chain Learns to Infect Your AI Agent

Two supply chain worms in June 2026 rewrote AI agent instructions and installed eBPF rootkits. Technical analysis of Miasma and IronWorm, and how to protect your agents.

Gabriel FerraresiJun 27, 20265 min read
securitysupply-chainai+2

Agentjacking: Hijacking AI Coding Agents via Sentry MCP

Attack discovered by Tenet Security hijacks AI agents via Sentry MCP with 85% success rate. 2,388 orgs with exposed DSNs. Open-source mitigation available.

Gabriel FerraresiJun 26, 20265 min read
securityaimcp+2

Metered Token Billing: Why Flat-Rate Pricing for AI Coding Is Dead

Between March and June 2026, every AI coding tool migrated to metered token billing. The real numbers, Jevons Paradox, and what it means for engineering organizations.

Gabriel FerraresiJun 26, 20263 min read
finopsaibilling+2

NVIDIA SkillSpector: The Scanner That Proved AI Skills Security Needs More Than Static Analysis

26% of AI skills contain vulnerabilities and 5% are likely malicious, according to Liu et al. NVIDIA launched SkillSpector, but Trail of Bits proved static scanners can be bypassed in under 1 hour.

Gabriel FerraresiJun 26, 20264 min read
securityainvidia+2

Xiaomi MiMo Code: The Open-Source Coding Agent That Challenges Claude Code

Xiaomi released MiMo Code, an open-source coding agent under MIT license that outperforms Claude Code on self-reported benchmarks. But the caveats matter as much as the numbers.

Gabriel FerraresiJun 26, 20264 min read
aiopen-sourcexiaomi+2

Brazil Civil Defense Hack: Cell Broadcast Compromised, 200 Million Without Alerts

Brazil's IDAP platform was hacked on June 19, 2026. Attacker sent false Extreme-level alerts to millions of phones. System remains offline, and Cell Broadcast by design lacks cryptographic authentication.

Gabriel FerraresiJun 21, 20263 min read
securitycell-broadcastbrazil+2

SantanderAI: The Bank That Open-Sourced Its AI Stack

Santander published 14 repositories on GitHub, including a mechanical governance framework, synthetic fraud graph generator, and vendor-agnostic LLM bridge. Zero real customer data. The European playbook for banking AI.

Gabriel FerraresiJun 21, 20264 min read
aiopen-sourcebanking+2

AI Writes 8× More Code, and Review Time Jumps 441%

Data from Anthropic, Faros AI, and GitClear shows AI accelerates code output but creates a review bottleneck. Code churn +861%, defects +54%. How to redesign the pipeline.

Gabriel FerraresiJun 17, 20263 min read
aicode-reviewengineering+2

Claude Code: 6 Disclosures, 1 Real Attack, and the Architectural Disease

A structural vulnerability in the Claude Code GitHub Action produced 6 separate disclosures, 1 source code leak, and 1 real supply chain attack. The patch covers a symptom, the disease is architectural.

Gabriel FerraresiJun 17, 20265 min read
claude-codesecuritysupply-chain+2

SearchLeak: P2P Injection + Bing SSRF Exfiltrates M365 Copilot Data

CVE-2026-42824 discovered by Varonis enables data exfiltration from M365 Copilot Enterprise via prompt injection in the search parameter and SSRF through Bing. One click is enough.

Gabriel FerraresiJun 17, 20265 min read
copilotprompt-injectionssrf+2

Gentlemen Ransomware: FortiGate Worm, 478 Victims in 10 Months

The Gentlemen RaaS exploits CVE-2024-55591 in FortiGate for worm propagation with 21 lateral movement techniques. 478+ victims, 66 countries, and an encryptor that makes decryption functionally impossible.

Gabriel FerraresiJun 17, 20264 min read
ransomwarefortigateperimeter-security+2

Google GTIG: The First AI-Developed Zero-Day in the Wild

Google GTIG identified the first AI-developed zero-day used by criminals. A 2FA bypass via semantic logic flaw, the vulnerability class LLMs find and fuzzers cannot.

Gabriel FerraresiJun 17, 20264 min read
zero-daysecurityai+2

GREYVIBE: First Forensic Case of Commercial AI Across the Entire Kill Chain

WithSecure documented the first forensic case of a threat group using commercial AI across every phase of the kill chain against Ukraine. What it means for cyber defense.

Gabriel FerraresiJun 17, 20263 min read
securityaicyber-threats+2

n8n-mcp: CVSS 9.9 IDOR Exposes All Tenants' Credentials

CVE-2026-54052 (assigned by Manifold Security; pending NVD publication) in n8n-mcp lets any authenticated tenant read every other tenant's credentials. Fifth multi-tenant security issue in 2026, the persistence layer was never isolated.

Gabriel FerraresiJun 17, 20264 min read
n8nidormcp+2

Tech86 Partner Program: Sell Complex Projects Without Hiring a Team

The Tech86 partner program enables consultancies, agencies, and integrators to sell complex engineering projects without a senior technical team. Recurring revenue share, engineering as a service, and account protection.

Gabriel FerraresiJun 17, 20265 min read
partnersrevenue shareengineering as a service+5

SHEETCREEP: APT Uses Google Sheets as Network-Invisible C2

SHEETCREEP, a RAT linked to APT36, uses Google Sheets as command-and-control infrastructure. Traffic indistinguishable from legitimate Google Workspace requires endpoint-level detection.

Gabriel FerraresiJun 16, 20264 min read
apt36c2google-sheets+2

Foxconn vs Nitrogen: Encryptor Bug Makes Ransom Payment Futile

Coveware reverse-engineered the Nitrogen ESXi encryptor and found a bug that corrupts the public key. Decryption is mathematically impossible. Foxconn was hit in May, approximately 3 months after disclosure. Paying does not help.

Gabriel FerraresiJun 15, 20264 min read
ransomwarenitrogenfoxconn+2

Tchap: Infrastructure Sovereignty Doesn't Protect Against Compromised Credentials

France's sovereign messenger exposed data of 73,467 public agents after a single account was compromised via social engineering. Why infrastructure sovereignty is not a substitute for credential security.

Gabriel FerraresiJun 15, 20264 min read
tchapsecuritysovereignty+2

LangGraph: From SQL Injection to RCE Through AI Agent Memory

Check Point Research documented an exploitation chain from SQL injection to remote code execution through the LangGraph checkpointer, the persistence layer that gives the agent memory is the same one that gives the attacker persistence.

Gabriel FerraresiJun 15, 20264 min read
langgraphsql injectionrce+3

Sophos CTU: AI-Powered Ransomware Lab Tests EDR Evasion at Scale

Sophos discovered a ransomware development lab using AI to accelerate development and test EDR evasion. Nearly 80 modules, 70+ techniques. What changes for your defense.

Gabriel FerraresiJun 15, 20264 min read
sophos cturansomwareartificial intelligence+3

CISA BOD 26-04 and EO 14409: AI in Federal Cyberdefense

CISA replaced CVSS with 4 binary patching factors. EO 14409 mandated AI-powered defense acceleration. What changes for security operations in practice.

Gabriel FerraresiJun 13, 20264 min read
securitycisaai+2

Ivanti Sentry CVSS 10.0: Unauthenticated RCE as Root

CVE-2026-10520 in Ivanti Sentry enables unauthenticated command injection with root execution. CVSS 10.0, public PoC, CISA KEV. Real timeline and data.

Gabriel FerraresiJun 13, 20264 min read
ivantizero-dayrce+2

Nightmare Eclipse: 8 Zero-Days Against Microsoft in 10 Weeks

A solo researcher exploited 8 vulnerabilities in the Microsoft ecosystem, including SYSTEM LPE, BitLocker bypass, and Defender TOCTOU. What this means for your defense.

Gabriel FerraresiJun 13, 20264 min read
microsoft defenderzero-dayendpoint security+3

ShinyHunters Exploited PeopleSoft Zero-Day for 13 Days Before Advisory

CVE-2026-35273: unauthenticated RCE in Oracle PeopleSoft exploited for 13 days before Oracle published an advisory. 454K sensitive records leaked. What this reveals about the patch cycle.

Gabriel FerraresiJun 13, 20264 min read
securityzero-dayrce+2

N-day Became N-hour, The Myth of the Safe Patch Window

Anthropic demonstrated that Mythos Preview generates functional exploits in hours, not weeks. Cost per privilege escalation chain dropped to $2K. The monthly patch cycle has become structurally inadequate.

Gabriel FerraresiJun 12, 20263 min read
securityaiexploit+2

Miasma Worm: When Trust Infrastructure Becomes the Attack Itself

How the Miasma Worm exploited SLSA, Sigstore, and legitimate credentials to compromise npm, PyPI, and Microsoft repositories in 7 days, without a single CVE.

Gabriel FerraresiJun 12, 20264 min read
supply chainsecuritymiasma worm+3

BigQuery LIMIT 100: The Illusion Draining Your OPEX

SELECT * with LIMIT 100 in BigQuery scans the entire table and charges by bytes read. TABLESAMPLE SYSTEM cuts processing by 95%. Real FinOps data.

Gabriel FerraresiJun 11, 20263 min read
finopsbigquerytablesample+2

Google Cloud Next 2026: Infrastructure the Agentic Enterprise Needs

From TPU v8 to Agent Gateway, Virgo Network to Agentic Defense, what Google Cloud Next 2026 means for teams running agents at scale and why governance beats building.

Gabriel FerraresiJun 11, 20264 min read
google-cloudai-agentsagentic-infrastructure+2

AI Compressed the Vulnerability Window, Microsoft Says So

Microsoft declared that AI can autonomously discover, chain, and exploit vulnerabilities. The discovery-to-exploitation window collapsed. What this means for your security operations.

Gabriel FerraresiJun 11, 20264 min read
securityaivulnerability+2

AI Inference FinOps Playbook: 5 Levers in the Right Order

80-90% of AI cost goes to inference. Five measurable levers, in priority order, to cut 50-90% of waste without sacrificing quality.

Gabriel FerraresiJun 6, 20265 min read
finopsaiinference+2

Claude Code in Your Pipeline: The Structural Hole and Rule of Two

Claude Code GitHub Action exposes credentials via unsandboxed Read tool. Microsoft steals keys in two steps. RyotaK: 50 bypasses. The Rule of Two you need to adopt.

Gabriel FerraresiJun 6, 20264 min read
claude codeci/cdprompt injection+2

Malicious LLM API Routers: The Invisible Threat Inside Your AI Agents

428 routers tested, 9 injecting code, 1 draining Ethereum. How malicious LLM API routers compromise AI agents without detection.

Gabriel FerraresiJun 5, 20263 min read
llmapi routerssecurity+2

State of FinOps 2026: 73% Blew Their AI Budget

State of FinOps 2026 data: 73% of organizations exceeded AI budget, only 20% predicted spend within ±10%. FinOps is now technology value management.

Gabriel FerraresiJun 5, 20264 min read
finopsaicloud cost+2

iFood Data Breach: 1.2M vs 43M and the Risk They Denied

iFood leaked CPF of 1.2 million users, failed to notify Brazil's ANPD, and claimed no relevant risk. The 36x discrepancy and what it reveals about LGPD enforcement.

Gabriel FerraresiJun 4, 20264 min read
ifooddata breachlgpd+2

Chrome DBSC: session cookie theft is finally over

DBSC binds session cookies to hardware via TPM. Stolen cookies expire without the key. The most significant browser security improvement in years, but it's one layer.

Gabriel FerraresiJun 3, 20264 min read
chromedbscinfostealer+2

LLM Agent Worms: Zero-Click Propagation Across Frameworks

The first autonomous worm propagating between LLM agents without human interaction. Zero-click, cross-platform, 3 hops. Defense requires a formal theorem.

Gabriel FerraresiJun 3, 20265 min read
wormllmai agents+2

MemPoison + MCFA: The Memory Attack Surface in LLM Agents

Memory attacks on LLM agents reach 95% success. MemPoison poisons memory, MCFA hijacks control flow. Current defenses are insufficient.

Gabriel FerraresiJun 3, 20264 min read
memoryllmai agents+2

PoisonedSkills: Skill Docs That Make AI Agents Run Malware

PoisonedSkills uses skill documentation to execute payloads in AI coding agents via DDIPE. 33.5% bypass rate. 4 CVEs. Skill registries are the new supply chain.

Gabriel FerraresiJun 3, 20264 min read
poisoned skillsaisupply chain+2

CVE-2026-41089: One UDP Packet Takes Down Your DC

CVE-2026-41089 in Windows Netlogon allows unauthenticated DoS via UDP 389. CVSS 9.8, active exploitation confirmed. Learn how to protect your DCs.

Gabriel FerraresiJun 2, 20264 min read
netlogonwindowsactive directory+2

WP Maps Pro: Backdoor by Design and Full Admin Takeover

CVE-2026-8732 in WP Maps Pro enables unauthenticated admin takeover. CVSS 9.8, 15,800 sites exposed. A frontend nonce is not authentication.

Gabriel FerraresiJun 2, 20264 min read
wordpresspluginadmin takeover+2

CIFSwitch: 19-Year Kernel Bug Gives Root in 1 Syscall

19-year Linux kernel vulnerability lets any unprivileged user get root via request_key and cifs.upcall. Public PoC. Enterprise servers exposed.

Gabriel FerraresiJun 1, 20265 min read
linuxkernelcifswitch+2

Vercel Bill Shock: Why Headless Without FinOps Fails

38% of headless merchants lost revenue in 90 days. Vercel Pro jumps from $20 to $2,000. FinOps is what separates scale from loss.

Gabriel FerraresiJun 1, 20265 min read
finopsvercelheadless+2

GlobalProtect Auth Bypass: Your VPN Perimeter Just Broke

CVE-2026-0257 in PAN-OS GlobalProtect enables authentication bypass with CVSS 9.1. Active exploitation, CISA KEV. Real data from Rapid7 MDR.

Gabriel FerraresiMay 31, 20264 min read
vpnglobalprotectpalo alto+2

CVE-2026-46230: Windows Kernel RCE with SYSTEM via SMB/RDP

CVE-2026-46230 in the Windows kernel enables unauthenticated RCE with SYSTEM via SMB and RDP. CVSS 9.8, public PoC. Learn how to protect your infrastructure.

Gabriel FerraresiMay 31, 20264 min read
windowskernelrce+2

FortiClient EMS: When Your Antivirus Becomes the Attack

CVE-2026-35616 in FortiClient EMS enables pre-auth API bypass, CVSS 9.1. Attackers push EKZ Stealer via EMS and steal session cookies, bypassing MFA.

Gabriel FerraresiMay 30, 20264 min read
forticlientekz stealerendpoint+2

PoolSlip and Gogs: Two Zero-Days Exposing Your Infra

CVE-2026-9256 (CVSS 9.2) in NGINX and Gogs zero-day CVSS 9.4 with no patch for 2+ months. Two entry points no one can afford to ignore.

Gabriel FerraresiMay 30, 20264 min read
nginxpoolslipgogs+2

CVE-2026-48172: LiteSpeed CVSS 10.0 and Shared Hosting Risk

CVE-2026-48172 in LiteSpeed cPanel Plugin scores CVSS 10.0, any tenant becomes root. Why shared hosting breaks by design with this class of vulnerability.

Gabriel FerraresiMay 29, 20265 min read
litespeedcpanelcvss 10+2

TrapDoor, TanStack and npm: When AI and Registry Become the Attack

TrapDoor plants invisible instructions in .cursorrules. TanStack steals OIDC tokens. 33 npm packages impersonate corporate namespaces. Three vectors, same result.

Gabriel FerraresiMay 29, 20264 min read
supply chainnpmai+2

FinOps for AI: Cost-per-Token and the GPU You Don't Use

73% of AI projects blow their budget. GPU utilization sits at 15-30%. Learn to measure cost-per-token and recover up to half your inference budget.

Gabriel FerraresiMay 28, 20264 min read
finopsaigpu+2

LLM Self-Replication Worm: From 6% to 81% in One Year

Palisade Research documented the first LLM self-replication worm: 4 hops, 3 continents, zero human intervention. Success rates jumped from 6% to 81% in 12 months.

Gabriel FerraresiMay 28, 20265 min read
self-replicationaiworm+2

Prompt Injection Is the New SQL Injection, Now It Leads to RCE

73% of AI deployments have prompt injection. Chatbots leak data via markdown rendering. Semantic Kernel enables RCE via Startup folder. Data and defenses.

Gabriel FerraresiMay 28, 20265 min read
prompt injectionairce+2

WordPress Security Crisis: 11,334 Flaws and the Headless Exit

WordPress hit 11,334 new vulnerabilities in 2025 (+42% YoY). Headless architecture removes the attack surface structurally and cuts LCP by 75%.

Gabriel FerraresiMay 28, 20264 min read
wordpressheadlesssecurity+2

Dirty Frag: Deterministic LPE to Root via Container Escape

CVE-2026-43284 + CVE-2026-43500 chain two kernel bugs into a deterministic root shell. AI inference nodes with GPU access are the highest-value targets.

Gabriel FerraresiMay 27, 20265 min read
dirty fraglinuxcontainer escape+2

Prompt Injection Is State Poisoning, Your Agent Is Exposed

CoT Forgery and Trojan Hippo prove prompt injection poisons internal model state. The security boundary is in the wrong place. Here is what changes.

Gabriel FerraresiMay 27, 20264 min read
prompt injectionaisecurity+2

SGLang: 4 unpatched RCEs in the AI inference server

Four RCE vulnerabilities in SGLang, the AI inference server running on 400K GPUs, three unpatched and the maintainer ignores CERT/CC.

Gabriel FerraresiMay 27, 20265 min read
sglangrcesecurity+2

Defender Zero-Days: When the Protector Becomes the Attack Vector

SYSTEM-privilege CVEs and Microsoft-signed malware prove that blind trust in Defender is the real vulnerability your organization faces.

Gabriel FerraresiMay 25, 20264 min read
microsoft defenderzero-dayendpoint security+2

AI Writes Zero-Days Now, and the Window Collapsed

How AI moved from finding vulnerabilities to writing exploits and self-replicating through them, and why the discovery-to-exploitation window collapsed in 2026.

Gabriel FerraresiMay 24, 20266 min read
aisecurityzero-day+2

Supply Chain 2026: When Trust Became the Attack Vector

How SLSA provenance, code signing, and CI/CD became the attack vectors for supply chain attacks in 2026, and what your company must do now.

Gabriel FerraresiMay 23, 20266 min read
supply chainsecuritynpm+2

Infrastructure AI Needs: Co-Design Is the New Paradigm

NVIDIA invested $40B in infrastructure and Vera Rubin proves it: the AI bottleneck isn't silicon, it's energy, fiber, and orchestration. The data center is the unit of compute.

Gabriel FerraresiMay 22, 20265 min read
infrastructureainvidia+2

Drupal SQL Injection: When the Abstraction Fails

CVE-2026-9082 exposed SQL injection in Drupal's abstraction API. 15K attacks in 48h. The patch was one line. Lessons on blind trust in frameworks.

Gabriel FerraresiMay 20, 20264 min read
drupalsql injectionweb security+2

NGINX Rift: 18-Year Bug Found by AI in 6 Hours

CVE-2026-42945: heap overflow in NGINX since 2008. AI found it in hours; patching thousands of instances takes weeks. The asymmetry that changes everything.

Gabriel FerraresiMay 19, 20265 min read
nginxsecurityai+2

SEO for AI: Google's Official Guide That Changes Everything

Google published the definitive SEO guide for AI search. The message: there is no AEO or GEO. The same fundamentals that worked in 2020 work in AI Mode today.

Gabriel FerraresiMay 16, 20265 min read
seoaigoogle+2

PROMPTSPY: the Android malware that uses AI to operate your phone

The first Android malware powered by generative AI reads your screen, thinks, and acts autonomously. Technical analysis and defense strategies.

Gabriel FerraresiMay 15, 20264 min read
malwareaiandroid+2

NATS as C2: When Your Infrastructure Becomes the Weapon

Attackers use NATS pub/sub as an invisible C2 channel. Learn how to detect and block malicious traffic disguised as legitimate microservice communication.

Gabriel FerraresiMay 14, 20264 min read
natsc2security+2

Containers Don't Isolate Workloads: CopyFail & DirtyFrag

Page cache CVEs collapse container isolation in Kubernetes. Why patches aren't enough and which architecture actually solves it.

Gabriel FerraresiMay 13, 20265 min read
kubernetessecuritylinux kernel+2

AI FinOps: Model Selection Is Unit Economics

Paying 21x more for 0.6% better benchmarks is capital waste. Learn how to select AI models based on real cost and throughput per dollar.

Gabriel FerraresiMay 11, 20264 min read
finopsaimodel selection+2

The Harness Beats the Model, Claude Code Architecture

Claude Code has 1,900 TS files. Only 1.6% is AI logic. The other 98.4% is control infrastructure, and that's what separates reliable agents from demos.

Gabriel FerraresiMay 1, 20264 min read
claude codearchitectureai+2

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.