>_ Posts
Blog
Thoughts on development, engineering, and product.
- 01|
Opening a folder in Cursor can run malicious code by itself — and Cursor has known for seven months
An unpatched zero-day in Cursor for Windows lets any repository with a forged git.exe in its root execute code automatically, with no click, no warning, no confirmation. Mindgard reported it in December 2025; it went fully public in July 2026, after seven months of silence.
- 02|
Two attacks in four days, a package with 15,000 weekly downloads, and npm v12 arriving to try to stop the bleeding
Injective SDK and Jscrambler were compromised in July 2026, fitting the same pattern that already hit Axios, Red Hat, and node-ipc this year. npm v12, expected this month, promises to end automatic install scripts — but experts say that doesn't fix the real problem.
- 03|
Hacker Attack on Brazil's Civil Defense: the 'misanthropy' alert that woke up the country
In the early hours of 06/20/2026, millions of Brazilians were woken up by an extreme alert containing the word 'misanthropy'. Here's what happened, how the Defesa Civil Alerta system was compromised, and what this incident tells us about the security of critical infrastructure.
- 04|
SaaS is eating the world — and tearing open just as many holes
The global SaaS market hit $299 billion and the average company runs 371 cloud applications. Meanwhile, 2026 is shaping up as the year of SaaS supply chain attacks — and the preferred entry point isn't the firewall anymore, it's an OAuth token from an integration nobody has reviewed in months.