Blog
Security articles on application code, Salesforce orgs and AI coding agents.
How orgs and applications actually get attacked, how attack paths are built, and how to get more security analysis done with fewer tokens. RSS
AI coding agents5 Oct 20268 min readSecuring AI coding agentsAI coding agents write code faster than anyone can review it. How to stop them shipping vulnerabilities: an MCP server, a skill and a hook that checks each file as it is written.Read the post →Token efficiency5 Oct 20268 min readSecurity analysis without wasting tokensAn AI agent that reads your repository to find vulnerabilities spends its context on files that are not the answer. Hand it the finding and the lines instead.Read the post →Developer workflow5 Oct 20266 min readSecurity where Salesforce developers write codeSecurity feedback for Apex, LWC, Aura, Visualforce and Flow usually arrives late, when a fix costs more. What it looks like in the editor, from diagnostics to runs-as.Read the post →Application security5 Oct 20268 min readSupply-chain attacks are a code problemThe npm worm, the hijacked packages and the invented ones of 2025 all ran as code on a developer's machine. What to check before a dependency lands.Read the post →Research5 Oct 202611 min readThe attacks of 2025, and the checks that flag their root causesTwelve attacks and disclosures from 2024 to 2026, the weakness in code or config behind each, and the Vulkro check that flags that weakness.Read the post →Research5 Oct 20269 min readEU law now expects proof: why security tooling is no longer optionalThe CRA, NIS2, DORA, the new Product Liability Directive and the AI Act share one demand: show your security works, continuously. What that means in 2026.Read the post →Salesforce5 Oct 20266 min readWhy Salesforce org security needs continuous reviewSetup edits, new connected apps and permission creep change a Salesforce org every week. Why a one-off audit goes stale, and what continuous review is.Read the post →