Sign in

Matteo Bisi

@msbiro.net
19 followers 33 following 90 posts

Italian DevSecOps Team Leader @cloudnativedaysitaly.org 2026 🇮🇹Organizer Based in Galway, Ireland My blog: www.msbiro.net

PostsRepliesMedia
Matteo Bisi @msbiro.net · 29/09/2026
third-party[.]com looked like a placeholder in 1700+ repos. It was never reserved like example.com. Someone registered it. No code changed. Trust did. How I audit external refs and trust assumptions: www.msbiro.net/posts/when-e...
000
Matteo Bisi @msbiro.net · 21/09/2026
AI agents can install tools, retry failed approaches, and explore an environment for hours. I wrote about microVMs, Firecracker, Kata Containers, and what the ECB’s AI cybersecurity letter means for banks: www.msbiro.net/posts/microv...
msbiro.net
MicroVMs vs Containers for AI Agents: ECB Cybersecurity Guide
What the ECB's AI cybersecurity letter means for banks: microVMs, containers, Firecracker, and Kata Containers for isolating AI agents.
000
Matteo Bisi @msbiro.net · 15/09/2026
Opening a repo is not always read-only. A trusted VS Code workspace can run  tasks.json  on folder open. That makes the IDE part of your supply chain. A guide to malicious tasks, Workspace Trust, and untrusted repos: www.msbiro.net/posts/shift-... #DevSecOps #VSCode
msbiro.net
Shift Left Starts in the IDE: VS Code Security in 2026
Learn how to harden VS Code against malicious tasks and extensions, use Workspace Trust safely, and inspect untrusted repositories before opening them.
001
Matteo Bisi @msbiro.net · 10/09/2026
Security can write the NIS2 policy. Security cannot merge the Helm chart. If the engineering manager cannot name the artefact and the sprint, you do not have a security gap. www.msbiro.net/posts/who-ow...
msbiro.net
Who Owns NIS2 and DORA in a Platform Team
NIS2 and DORA fail when only security owns them. A Kubernetes platform RACI, plus the artefacts engineering managers must put on the board.
000
Matteo Bisi @msbiro.net · 04/09/2026
Kubernetes 1.37 brings three security capabilities worth planning for now: stable Pod certificates, Cluster Trust Bundles, and improved SELinux volume handling. www.msbiro.net/posts/kubern... #Kubernetes #CloudSecurity
msbiro.net
Kubernetes 1.37 Security: 3 Stable Advances, 3 Future Signals
Kubernetes 1.37 security: three stable advances in workload identity and SELinux, plus three alpha features shaping the future of cloud native security.
000
Matteo Bisi @msbiro.net · 02/09/2026
AI coding agents can write code. Can they close work with proof? Grok Bot pairs execution with ownership, feedback, CI checks, and human review based on risk. Senior engineers remain the control plane. www.msbiro.net/posts/grok-b... #AIAgents
msbiro.net
Grok Bot: An AI Superpower for Senior Engineers
Grok Bot is an AI engineering system that manages coding agents. This article explains why senior engineers and engineering leaders still provide the judgment, verification, and risk control AI agents...
010
Matteo Bisi @msbiro.net · 26/08/2026
Your SOC receives a runtime alert. Can the analyst quickly establish who changed the workload, what traffic reached it, and what happened before the detection? Kubernetes audit logs and HAProxy ingress logs provide that evidence. www.msbiro.net/posts/kubern...
msbiro.net
Kubernetes Audit Logs and HAProxy Logs for SOC Evidence
Learn how Kubernetes audit logs and HAProxy logs complement CNAPP posture and runtime security to give SOC analysts actionable evidence.
000
Matteo Bisi @msbiro.net · 22/08/2026
A DevSecOps seat is live on my team. Kubernetes, Policy-as-Code, shift-left, runtime security, and open source, not ticket closing. Hybrid: Vimercate, Rome, Catania, or Cascina. Italian + English (C1) required. JD + apply → www.linkedin.com/jobs/view/44...
linkedin.com
Devsecops Engineer at ReeVo Cloud & Cyber Security — Vimercate, Lombardy, Italy | LinkedIn Jobs
Apply for Devsecops Engineer at ReeVo Cloud & Cyber Security in Vimercate, Lombardy, Italy. Full-time Mid-Senior level role. See responsibilities, qualifications, and similar jobs on LinkedIn.
000
Matteo Bisi @msbiro.net · 17/08/2026
Apple Container can run a local SIGHUP Distribution profile on Apple silicon. This walkthrough covers the current bootstrap recovery, registry-free local images, storage, Fluent Bit inotify tuning, and upcoming improvements for native creation and host access. www.msbiro.net/posts/apple-...
msbiro.net
Apple Container Kubernetes on macOS: A SIGHUP Distribution Lab
A verified Apple Container Kubernetes walkthrough on macOS: recover a kubeadm cluster, load local images without a registry, and evaluate SIGHUP Distribution.
000
Matteo Bisi @msbiro.net · 09/08/2026
A kernel CVE hiding for 18 years. CVSS 8.5. Container escape. And it probably is not aimed at you. Severity and exposure are two different questions. www.msbiro.net/posts/sctpha...
msbiro.net
SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic
CVE-2026-64564 (SCTPhantom) is a critical Linux kernel use-after-free in SCTP ASCONF with a high CVSS score and a demonstrated container escape. A DevSecOps threat-modeling walkthrough of when to care...
000
Matteo Bisi @msbiro.net · 05/08/2026
OWASP GenAI LLM Top 10 2026 adds incident data to practitioner judgment, drawing on 7,714 real AI security incidents. www.msbiro.net/posts/owasp-...
msbiro.net
OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams
OWASP released the GenAI LLM Top 10 2026, the first edition grounded in 7,714 real AI security incidents. Prompt Injection stays at number one. Excessive Agency climbs. Misinformation is the widest ga...
000
Matteo Bisi @msbiro.net · 27/07/2026
"Just temporarily" is how an AI agent ends up with cluster-admin. K8s doesn't distinguish a destructive action by an attacker from the same action by an over-privileged agent. Shadow AI threat model, laptop to pod: www.msbiro.net/posts/shadow...
msbiro.net
Shadow AI in CI/CD: Threat-Modelling Laptop to Kubernetes
Shadow AI turns ungoverned coding assistants and agents into a live threat across CI/CD. A stage-by-stage threat model from developer laptop to Kubernetes pod, with the executive controls and tooling ...
110
Matteo Bisi @msbiro.net · 17/07/2026
It's 2026 and I still get asked why encrypting secrets with git-crypt isn't enough. Short answer: encryption solves confidentiality, not revocation, audit logging, or dynamic secrets. DORA and NIS2 remove any remaining excuse. www.msbiro.net/posts/secret...
msbiro.net
In 2026 I Am Still Asked Why You Need a Centralized Secrets Manager
Why a centralized secrets manager is non-negotiable in 2026: the operational limits of git-crypt and sealed-secrets style tools, the DORA and NIS2 mandate, and why OpenBao is now the open source secre...
000
Matteo Bisi @msbiro.net · 10/07/2026
The ECB told bank CEOs AI is shortening the gap between vulnerability discovery and exploitation. Action plan due 31 October 2026, DORA as the foundation. Also extending the IT Risk Questionnaire deadline to Feb 2027. My breakdown with CNAPP, hardened images and SBOMs www.msbiro.net/posts/ecb-ai...
msbiro.net
ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026
ECB letter on AI-enabled cybersecurity threats: action plan due October 2026, ITRQ deadline extension, CNAPP, hardened images, SBOMs and DORA resilience.
000
Matteo Bisi @msbiro.net · 06/07/2026
Built a fully local meeting-minutes pipeline: on-device speech-to-text + diarization on Apple Silicon, then a 14B model via Docker Model Runner and Docker Agent. No audio, transcript, or prompt ever leaves the machine. www.msbiro.net/posts/local-...
msbiro.net
Local AI Meeting Minutes with Docker Model Runner and Docker Agent: No Cloud, No Leaks
Local AI meeting minutes on Apple Silicon: on-device transcription with speaker diarization, then minutes from a 14B model through Docker Model Runner and Docker Agent. No cloud, no data flow to third...
110
Matteo Bisi @msbiro.net · 29/06/2026
Episode 3 of my "Back to Basics" series: TLS and PKI from the ground up. What an X.509 certificate actually contains, how the chain of trust works, the TLS 1.3 handshake step by step, and the Kubernetes PKI most engineers never look at. www.msbiro.net/posts/back-t...
msbiro.net
Back to Basics: TLS and PKI from the Ground Up
TLS and PKI explained from the ground up: what an X.509 certificate actually contains, how the chain of trust works, what happens during a TLS handshake step by step, and how Kubernetes builds a full ...
000
Matteo Bisi @msbiro.net · 24/06/2026
In 2026 I still get asked why enterprises need a hardened container image catalog. DORA and NIS2 mandate it. Container base images are infrastructure and deserve the same governance we always applied to operating systems. www.msbiro.net/posts/harden... #devsecops #nis2
msbiro.net
In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog
Why hardened container image catalogs are non-negotiable in 2026: the technological case, the DORA mandate, and the NIS2 obligations explained.
000
Matteo Bisi @msbiro.net · 21/06/2026
Your engineering culture is not shaped by the all-hands. It is shaped by your EMs in every 1:1 this week. New post connecting McKinsey 2026 data to what I live daily as a team leader: why middle management is a CTO's highest-ROI investment. www.msbiro.net/posts/engine...
msbiro.net
Engineering Managers Are Your Real Culture: Why CTOs Must Invest in Middle Management
Engineering managers are the real culture carriers in your organization. McKinsey 2026 data explains why CTOs must prioritize investment in their middle management layer.
000
Matteo Bisi @msbiro.net · 16/06/2026
AI finds zero-days faster than disclosure was designed to handle. Athena is a new coalition: 24+ members, coordinated remediation before public disclosure, 20k findings, 2k patches already. My take on what it means for DevSecOps teams: www.msbiro.net/posts/athena...
msbiro.net
Athena Coalition: Coordinated Open Source Defense in the AI Vulnerability Era
Athena is a new industry coalition for coordinated open source vulnerability defense. Here is what it means for DevSecOps teams and security leaders.
000
Matteo Bisi @msbiro.net · 12/06/2026
Apple just introduced “container machine” with Container 1.0. Worth adding to your workflow? It depends, but it’s definitely interesting. www.msbiro.net/posts/apple-...
msbiro.net
Apple container 1.0 and container machine: hands-on security test
Hands-on Apple container 1.0 test of container machine on macOS, covering home-mount security, networking, systemd, and Docker or Podman alternatives.
010
Matteo Bisi @msbiro.net · 10/06/2026
AI agents run with the privileges we give them, and attackers now operate at machine speed. Anthropic's Zero Trust for AI Agents eBook is the practical framework the field has been missing. My review: www.msbiro.net/posts/zero-t... #zeroTrust #agents #antrhopic
msbiro.net
Zero Trust for AI Agents: Why Anthropic's New eBook Should Be on Your Reading List
A review of Anthropic's Zero Trust for AI Agents eBook: a practical security framework for deploying autonomous AI agents, covering threat modeling for security leaders and an implementation guide for...
000
Matteo Bisi @msbiro.net · 22/05/2026
@cloudnativedaysitaly.org Italy 2026 is behind us, and Bologna was worth every bit of the work. As one of the organizers, I wrote a short recap of 2 full days, 40 sessions, 4 workshops, and the community conversations that made this edition special. www.msbiro.net/posts/cloud-...
msbiro.net
Cloud Native Days Italy 2026: A Wrap-Up from Bologna
Cloud Native Days Italy 2026 wrapped up in Bologna. A personal recap from one of the organizers: speakers, MCs, sponsors, and a community worth celebrating.
011
Matteo Bisi @msbiro.net · 11/05/2026
@sentinelone.com purple-mcp: open-source MCP server for Singularity, 22 read-only tools. I tested the integration with Claude Code. One prompt → alert list, asset context, triage brief. ~6 seconds. No tab-switching. Tested against a live tenant. www.msbiro.net/posts/sentin...
msbiro.net
SentinelOne Purple MCP: A Hands-On Guide to Singularity AI Integration
Hands-on review of SentinelOne's purple-mcp: how to connect Singularity alerts, vulnerabilities, and threat hunting to Claude Code for faster SOC triage.
110
Matteo Bisi @msbiro.net · 06/05/2026
Lazarus Group hides malware in git hooks, targeting developers through fake job interviews. Clone a repo. Run git merge. Your credentials are gone. Attack breakdown + five practical defences: www.msbiro.net/posts/lazaru...
msbiro.net
Lazarus Group Hides Malware in Git Hooks to Target Developers
North Korea's Lazarus Group embeds malware in git hooks to compromise developers through fake job interviews. Attack breakdown and five practical defences.
000
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 01/05/2026
🎉 PLATINUM SPONSOR ANNOUNCEMENT: Spectro Cloud Spectro Cloud helps enterprises orchestrate infrastructure from cloud to edge, and metal to model. They're also the sponsor behind the CNCF Kairos project: an immutable Linux meta-distribution designed for edge Kubernetes.
011
Matteo Bisi @msbiro.net · 01/05/2026
CVE-2026-31431 "Copy Fail": nine years in the kernel, root in 732 bytes of Python. No race conditions, no kernel offsets. Container namespaces don't protect you the page cache is shared across the host. Only runtime detection catches this. www.msbiro.net/posts/cve-20...
msbiro.net
CVE-2026-31431 Copy Fail: A Nine-Year-Old Kernel Bug, a 732-Byte Script, and a Root Shell
CVE-2026-31431 Copy Fail is a local privilege escalation in the Linux kernel exploitable with a 732-byte Python script. This post covers what it is, how to fix it, what to do when patching isn't immed...
000
Matteo Bisi @msbiro.net · 30/04/2026
Ubuntu 26.04 LTS is out. I focused on the server side instead of the desktop headlines: security changes, cgroup v2-only, confidential VMs, sudo-rs, post-quantum SSH, and what it means for Ubuntu-based container workloads. www.msbiro.net/posts/ubuntu...
msbiro.net
Ubuntu 26.04 LTS: What Changes for Security and Container Workloads
Ubuntu 26.04 LTS 'Resolute Raccoon' just shipped. For teams running RHEL or Ubuntu on servers, this post breaks down what actually changed in security and container/Kubernetes workloads compared to 24...
100
Matteo Bisi @msbiro.net · 27/04/2026
3 supply chain attacks in 3 weeks. Bitwarden CLI, Trivy, Axios , all used postinstall scripts to steal credentials from developer environments and CI/CD pipelines. EDR doesn't see it coming. I wrote up the pattern and 8 controls worth actually putting in place. 🔗 www.msbiro.net/posts/supply...
msbiro.net
Supply Chain Attacks Won't Stop: 8 Controls to Reduce Your Exposure
Bitwarden CLI, Trivy, and Axios compromised in three weeks. Your EDR won't catch postinstall scripts. 8 practical controls to reduce the blast radius.
000
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 23/04/2026
🎉 SMART SPONSOR ANNOUNCEMENT: @cncf.io Cloud Native Days Italy has always been deeply connected to the CNCF community with CNCF Ambassadors, maintainers, and contributors at the heart of our event. Together we've built a vibrant cloud-native community in Italy.
021
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 21/04/2026
📚 BOOK SIGNING & GIVEAWAY For the first time ever, Pietro Libro and @artemlajko.bsky.social will sign copies of their book "Implementing GitOps with Kubernetes" together and it's happening at Cloud Native Days Italy 2026!
111
Matteo Bisi @msbiro.net · 21/04/2026
Tomorrow K8s 1.36 ships. Ingress NGINX retires, but on security side SELinux labeling GA (faster Pod startup on enforcing systems) + external ServiceAccount signing GA (KMS integration). I've written a breakdown focused on why these matter for your infrastructure → www.msbiro.net/posts/kubern...
msbiro.net
Kubernetes 1.36: The Release That Said Goodbye to Ingress NGINX
Kubernetes 1.36 releases tomorrow with a significant security focus: the end of Ingress NGINX, SELinux volume labeling reaching GA, and a set of long-overdue removals that tighten the security posture...
100
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 18/04/2026
🚨 THE COUNTDOWN IS ON! 🚨Only 1 month to go! Cloud Native Days Italy 2026 is just around the corner: May 18-19 in Bologna … and we couldn't be more excited! 🚀
111
Matteo Bisi @msbiro.net · 17/04/2026
🐧 Wrote a piece on Linux Kernel 7.0 from a platform security lens — what's changed, what it means for your infrastructure, and what leaders should be paying attention to. If you're in DevSecOps or cloud native, worth a read 👇 www.msbiro.net/posts/linux-... #Linux #DevSecOps #CloudNative
msbiro.net
000
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 15/04/2026
Coming solo or with your team? Let us know! 👇
011
Matteo Bisi @msbiro.net · 14/04/2026
☁️ @cloudnativedaysitaly.org 2026 is coming to Bologna on May 18-19 🇮🇹 Two full days with 2 tracks, workshops, great talks, and a dedicated maintainer space on day 2. I’m proud to help organize it! join us! Agenda cloudnativedaysitaly.org/agenda
010
Matteo Bisi @msbiro.net · 13/04/2026
Weekend experiment: As a spec-kit user, I wanted to test GSD (Get Shit Done), a different SDD framework built around preventing AI context rot. Starting point: zero production code. Comparison of both frameworks + full session walkthrough 👇 msbiro.net/posts/gsd-sbom-drift-spec-driven-development/
msbiro.net
000
Matteo Bisi @msbiro.net · 07/04/2026
As an AI enthusiast and Security Team Leader, when I saw Docker Sandboxes I couldn't resist going deep. I installed it, broke it, fixed it, and ran GitHub Copilot CLI inside a sandbox. Here's what I found Big kudos to @docker.com for shipping this 🐳 🔗 msbiro.net/posts/docker-sandboxes-ai-agents/
msbiro.net
000
Matteo Bisi @msbiro.net · 02/04/2026
KubeCon EU 2026 swag: 6 months of Copilot Pro+ First thing I did back home: raise the security baseline of my side project. OpenSSF Scorecard as required merge check · Dependabot for Go + GitHub Actions · SHA-pinned workflows · branch protection via gh api Write-up 👇 www.msbiro.net/posts/actui-...
msbiro.net
Hardening ACTUI: Dependabot and OpenSSF Scorecard for a Side Project
Back from KubeCon EU 2026 with a free Copilot Pro+ subscription, I turned my attention to the security posture of apple-container-tui. Here's how I added Dependabot and OpenSSF Scorecard using GitHub ...
000
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 01/04/2026
⚡ KEYNOTE SPEAKER: GIACOMO TENAGLIA Chair, @cern.bsky.social Open Source Program Office 25 years building and running services on open-source software 🎤 Keynote talk: "Open Source at CERN" This is the kind of keynote that reminds us why open source matters.
011
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 31/03/2026
🎉 COMMUNITY PARTNER ANNOUNCEMENT: theRedCode TheRedCode.it a tech blog that shares practical tech guides on DevOps, security and AI for dev and not, in small bits. A huge thank you to Serena Sensini for supporting Cloud Native Days Italy and contributing to the broader cloud-native community! 🙌
011
Matteo Bisi @msbiro.net · 30/03/2026
Just dropped my #KubeConEU 2026 recap. Fourth in a row, and this time also wearing the Cloud Native Days Italy organizer hat, that changed a lot. Short read, no fluff. 👇 msbiro.net/posts/kubecon-eu-2026-amsterdam-recap/
msbiro.net
000
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 29/03/2026
It's a wrap for KubeCon + CloudNativeCon week! 🇳🇱 Our CND Italy organizers and Reevo partners soaked it all in, and now we're bringing that energy back home to Bologna Today is your last chance to grab the KubeCon week discount! 🎟️ ti.to/apropos/clou...
011
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 27/03/2026
Kubecon may be over, but the CND Italy Kubecon discount is still active! Last few days to grab tickets at €110 👀 📅 May 18-19, Bologna 🎟️ Use code CND-ITALY-26-KUBECON-EU-22326 at checkout. Valid until Sunday March 29th: ti.to/apropos/clou... #CNDItaly #CloudNativeDaysItaly2026
011
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 26/03/2026
🎉 INTRODUCING: OUR FIRST CONFIRMED SPEAKERS! We're starting to reveal the incredible lineup for Cloud Native Days Italy 2026 and we couldn't be more excited. More announcements are coming soon as we finalize confirmations with additional speakers. 🎟️ cloudnativedaysitaly.org
122
Matteo Bisi @msbiro.net · 24/03/2026
Who said a conference doesn’t count as a workout? #Kubecon #Amsterdam
030
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 23/03/2026
Couldn't make it to KubeCon + CloudNativeCon Amsterdam? ✅ CND Italy = same energy but with Italian vibes ✅ Local, accessible, community-focused ✅ Pizza > stroopwafels (we said what we said 🍕) Use code CND-ITALY-26-KUBECON-EU-22326Valid all week 🎟️ ti.to/apropos/clou...
011
Matteo Bisi @msbiro.net · 23/03/2026
Amsterdam mode: on. Badge collected and ready for the week! Starting tomorrow, come meet the ReeVo team at booth 893 to talk cloud, security, and Kubernetes. #KubeConEU #ReeVo #DevSecOps
My conference badge with a little sister egg
000
Matteo Bisi @msbiro.net · 21/03/2026
🚨 Trivy was compromised. Your CI/CD pipeline may have exfiltrated your secrets without you knowing. Full attack breakdown + mitigation checklist: www.msbiro.net/posts/trivy-... #DevSecOps #SupplyChain
msbiro.net
The Trivy Supply Chain Attack: A Breakdown of Credential Theft and the CanisterWorm Escalation
A comprehensive analysis of the March 2026 Trivy supply chain incident: from malicious GitHub Actions to the self-propagating CanisterWorm.
010
Matteo Bisi @msbiro.net · 20/03/2026
💰 $12.5 million invested to fortify open-source security. This is a big moment for the cloud-native community. What does it mean in practice? I shared my take on the blog 👇 msbiro.net/posts/invest...
msbiro.net
010
Reposted by Matteo Bisi
Cloud Native Days Italy @cloudnativedaysitaly.org · 19/03/2026
🎉 GOLD SPONSOR ANNOUNCEMENT: @sentinelone.com SentinelOne is redefining cybersecurity with autonomous AI that prevents, detects, and responds to threats, without requiring constant human intervention. Huge thanks to Andrea Viano for the collaboration and support 🙌 🎟️ cloudnativedaysitaly.org
011