Writing
Long-form articles on cloud security, AI, and the intersection. Roughly monthly.
Subscribe via RSS →- 2026-07-10·8 min read
How 14 CVEs finally forced my Next.js upgrade (and what the migration actually looked like)
I deferred the Next.js 14 to 15 upgrade for over a year. Then a security audit counted 14 high-severity CVEs sitting in my production next package. Every code change, every build-pipeline gotcha, and the lessons that came out of it.
next-jscvesmigrationsecurity - 2026-06-09·19 min read
Trends in the Cybersecurity Industry
AI, zero trust architecture, and software supply chain attacks are reshaping modern cyber operations. This paper examines all three and argues that provenance-based build controls should replace the SBOM-centric compliance posture inherited from 2021.
cybersecurityAIzero-trustsupply-chainresearch - 2026-05-15·7 min read
A bad week to ship 'next: latest'
Three CVEs, one almost-mistaken major version jump, and a build cache that kept lying to me. Notes from patching dependency vulnerabilities on a brand-new Next.js site within hours of going live.
cloud-securitysupply-chainnext-jsincident

