Field notes

The seam, in writing.

Data and dispatches on CI/CD supply-chain attacks — how big the problem is, who's driving it, and why the gap between identity and the pipeline keeps winning.

Research · Published

How big is the CI/CD supply-chain problem — and who's behind it?

+75% malicious packages in a year, 267-day median detection, ~29M secrets leaked — and the nation-states (North Korea, China, Russia, Iran) behind the worst of it. Sourced.

~9 min read →
Thesis · Published

Your identity tools and your pipeline tools never talk

The security market is organized by telemetry domain, not by how attacks move. Why no incumbent owns the seam between identity and the pipeline — and why that gap is structural, not an oversight.

~5 min read →
Opinion · Published

Prevention is mostly free. Detection is the hard part.

The $0 hygiene that stops most CI/CD supply-chain attacks — and the residual risk (a valid credential turning hostile) that's actually worth paying to detect.

~5 min read →
Teardown · Published

Malicious-but-clean: the workflow attacks scanners can't see

A syntactically valid GitHub Actions workflow can still be an attack. Why pattern-matching misses intent — and what reasoning over the diff plus the committer looks like.

~6 min read →
Deep dive · Published

The fake employee: inside DPRK's IT-worker supply chain

320+ companies in a year. When the "insider threat" holds a real badge and a real commit history, prevention can't help and identity checks pass — so what's left to detect?

~6 min read →
Coming soon