Browse Security Blogs (28)

John Edward explains why AI agents that look great in demos often break down in production, and what teams need to engineer around the model to make agents reliable at scale.
Rob Bos shares a curated set of GitHub governance references he regularly sends to teams, covering enterprise platform baselines, GitHub Actions supply-chain controls, GitHub Advanced Security rollout and triage practices, and GitHub Copilot governance topics like premium requests, extension governance, and MCP-related security notes.
John Edward explains how Azure’s “Agentic Agents” can support resilient cloud operations across migration planning, observability, and continuous optimization. The article focuses on turning telemetry into actionable guidance, reducing alert fatigue, improving root-cause analysis, and driving cost, performance, security, and sustainability improvements in Azure environments.
John Edward outlines an end-to-end approach for building a ServiceNow-focused AI assistant in Microsoft Copilot Studio, aimed at ticket auditing, SLA risk monitoring, and engineer performance reporting. The guide covers a layered architecture, ServiceNow REST API integration via Power Platform custom connectors, and practical security considerations for enterprise deployment.
Hidde de Smet explains how MCP’s Enterprise-Managed Authorization changes MCP authentication from per-server OAuth consent to policy-driven sign-in via an identity provider, with VS Code 1.123 preview support for Entra ID, Okta, and Auth0 and governance controls that pair with GitHub Copilot’s MCP registry policies.
Thomas Maurer explains what Azure Local Small Form Factor (SFF) is and why it matters for edge scenarios, then outlines an end-to-end deployment flow: provisioning a device as an Azure resource, installing the Azure Local OS, registering it with Azure Arc, and running container workloads with Docker and K3s.
DevClass reports on Vercel’s Ship event announcements, focusing on the new open source eve agent framework and enterprise controls like Passport for bringing AI-built apps and agents under centralized identity and policy, including OpenID Connect support for providers such as Okta and Microsoft Entra ID.
DevClass reports on upcoming npm 12 default changes that stop install-time scripts from running automatically, aiming to reduce a major supply-chain attack surface on developer machines and CI runners. The piece explains the new flags, breaking-change impact, and how teams can prepare using npm 11.x settings.
DevClass reports on Checkmarx survey findings that many developers believe AI-generated code contains more vulnerabilities, yet some still ship it to production. The piece connects AI-assisted development, open source supply-chain risk, and security process gaps to higher breach frequency.

Azure Local Simplified Machine Provisioning

Thomas Maurer explains Azure Local Simplified Machine Provisioning, a new workflow for provisioning physical Azure Local nodes with minimal on-site work while keeping configuration and control centralized in Azure.
Hidde de Smet shows how to add fast local guardrails for Azure Terraform by running fmt, validate, tflint, Trivy, and terraform-docs on every git commit. The post includes a working pre-commit config, Azure-specific lint rules, and an MCP-based workflow to keep generated HCL current and policy-aligned.
Rick Strahl walks through an edge-case but practical .NET Framework/WPF tool that packages a static documentation website into a single Windows EXE, then unpacks and renders it offline using WebView2. He covers the packaging approach, ILRepack-based single-file builds, embedding native dependencies, and the SmartScreen/code-signing trade-offs.
Thomas Maurer explains how LAPS for Azure Arc extends Windows LAPS so teams can centrally audit and enforce local admin password rotation across Azure VMs and Arc-enabled servers, with Azure Policy-based compliance reporting that works in hybrid and regulated environments.
John Edward outlines practical ALM and environment strategy guidance for Microsoft Copilot Studio, focusing on how to run copilots like enterprise applications with multi-environment setups, solution-based development, source control, CI/CD pipelines, configuration management, governance, and ongoing monitoring.
Rick Strahl explains why ASP.NET Core cookie-auth logins can “disappear” after IIS app pool recycles: the Data Protection key ring isn’t persisting, so previously issued auth cookies can’t be decrypted/validated. He shows how to fix it by enabling Load User Profile or by explicitly persisting keys to a known location.
Jesse Houwing shows how to automate GitHub Copilot AI Credits budgeting by assigning per-user budgets based on Microsoft Entra ID group membership, using a GitHub Actions workflow and a PowerShell script that calls the GitHub enterprise billing API via the GitHub CLI.
John Edward outlines common enterprise AI agent architecture patterns you can implement with Microsoft Copilot Studio, including single-agent designs, multi-agent orchestration, RAG, human-in-the-loop workflows, and event-driven automation, with notes on integrations, governance, and compliance considerations.
DevClass reports on GitHub’s investigation into a poisoned VS Code extension that led to exfiltration of internal repositories, and the downstream risks for credentials, private code exposure, and follow-on access if stolen secrets were present.
DevClass reports on a Shai-Hulud supply-chain attack where a compromised npm account published malware into 314 packages, then hid reports by closing GitHub issues. The piece summarizes the payload’s credential-stealing behavior and practical cleanup steps like rotating secrets and checking for unauthorized repos and services.
DevClass reports on TanStack’s incident follow-up after a supply-chain attack that abused a GitHub Actions workflow to run untrusted code and poison shared caches, and on the project’s proposed hardening steps—including potentially moving to invitation-only pull requests.
Emanuele Bartolesi shares a quick fix for the Windows error “Your organization has deleted this device” (error code 700003) on Microsoft Entra-joined devices, avoiding a full disconnect/reconnect of the work account.
Harald Binkle demonstrates a practical BMAD workflow using GitHub Copilot to turn fuzzy requirements into reviewable artifacts: a PRD, project context, epics/stories, architecture decisions, risk-based test design, and traceability. The example focuses on enterprise authentication concerns like MFA, tenant isolation, RBAC, and auditability.
Rob Bos introduces the GitHub Copilot App technical preview and shares a practical first look at using it for repository maintenance, including parallel agent sessions, session modes (Interactive/Plan/Autopilot), and the Agent Merge workflow for handling CI failures, merge conflicts, and security-related alerts.
John Edward explains how GitHub Copilot changes team workflows around pull requests, code review expectations, and knowledge sharing. The article focuses on the trade-offs of faster AI-assisted coding, why review discipline matters more, and how teams can add guardrails like testing and security scanning without losing collaboration.
Rick Strahl shows where to read the client IP address in ASP.NET Core, and how to handle reverse proxies by parsing common forwarding headers or enabling the built-in Forwarded Headers Middleware.
John Edward outlines an architecture for a “Daily Stand-Up Agent”: a custom AI copilot that pulls sprint activity from Jira and Azure DevOps, detects blockers, and generates consistent stand-up summaries. The post focuses on connectors, grounding ticket data, conversational reporting, and practical considerations like security and data quality.

My Open Source Projects

Rob Bos shares an overview of his open source projects spanning GitHub and CI/CD tooling, Azure-backed services, security reporting, and local-first AI utilities, with links to each repo and a clear description of what each tool does.
Rob Bos breaks down five GitHub Copilot and agent extensibility surfaces that create supply-chain and governance gaps in large enterprises, and explains what controls exist today (and where they don’t) across Copilot CLI plugins, APM, gh skill, MCP servers, and VS Code extension registries.

End of content

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.