Discussion about this post

User's avatar
Neural Foundry's avatar

Absolutely comprehensive issue as always Chris! The M&A perspectives interview with Varun Badhwar really stands out - his journey from founding Redlock and exiting to PANW to now scaling Endor Labs provides invaluable insights on building and exiting security companies. His candid discussion about evaluating M&A offers and the acquirer's perspective is rarely shared so openly. The timing couldn't be better given how much consolidation we're seeing in the cybersecurity market. The section on AI coding assistants being compromised is particularly alarming - the CamoLeak vulnerability in GitHub Copilot Chat with that 9.6 CVSS is a wake-up call. We're giving these tools access to everything (code, commits, PRs, secrets) without thinking about the attack surface we're creating. Your point about agentic IDEs being the modern attack surface is spot on - they're essentially a gateway to network resources and part of the CI/CD trust boundry now. The combination of invisible comments, prompt injection, and CSP bypasses shows how creative attackers are getting. Thanks for the shout-out to Ken Huang's work on the MAESTRO framework too - that's been instrumental in helping organizations think systematically about AI security. Great issue!

Expand full comment

No posts

Ready for more?