800 posts, where am I and what are the insights
I've started in September. I've reached 500 in May, I am reaching 800 in November. It's clearly less posts per month.
Of course, I've started to focus on relevance.
Popular posts are clearly related to LLMs.
NVD is not on the top of the news today, strongly replaced by supply chain attacks. In fact, I think supply chain security was one of the most important subjects this year, as anyone could notice from OWASP Top 10 2025.
LLMs are still hot as hell subject.
Expanding my sources helped me not to get more news, but to get more tools and more evidence that the most important subjects were the ones I've thought, because most sources were talking about the same things.
One thing I'd love to have is some sort of integration with linkedin because I am always reading there. I think linkedin is like a professional blog for many great professionals that I am always following (Madden, Janca, Shostack, Hughes, Hovesepyan, Cipollone, Rexha, Collman, Buchanan and the list goes on).
Here's what chatgpt gave to me from the blog dump. Sounds accurate.
Main topics from May → November 2025
-
AI-Driven Security
Multiple posts discuss the rise of artificial intelligence in cybersecurity — including AI threat detection, AI code security, and the impact of large-scale AI models on defensive strategy. -
Supply-Chain Security & Developer Tooling Risks
Entries focus on software supply-chain threats, package-repository attacks, and vulnerabilities emerging from development tools or build infrastructure. -
Secure Software Development Practices
There are recurring themes around secure-by-design approaches, updated security standards, and developer-friendly security improvements. -
Vulnerability Discovery & High-Impact CVEs
The feed frequently highlights new vulnerabilities, exploitation research, and analysis of high-risk CVEs circulating in the ecosystem. -
Cloud & Container Security
Several posts relate to the security of cloud platforms, container images, and infrastructure-as-code, reflecting ongoing industry concerns. -
Industry Shifts & Security Strategy
Some posts look at broader changes—such as corporate movements, emerging security products, and strategic trends impacting defenders.
ChatGPT also offered to provide some predictions, let's see.
| Prediction | What Will Happen in 2026 | Rationale |
|---|---|---|
| AI leads vulnerability discovery & prioritization | Security tools use AI exploit telemetry and AI scoring to rank risks, reducing noise. | Rising CVE volume + shift from “scan everything” to “prioritize what’s exploited.” |
| Supply-chain security becomes top budget priority | Organizations invest heavily in provenance, SBOMs, secure dev tooling. | Feed shows constant npm attacks, poisoning, dev-tool compromises. |
| Secure-by-default IDEs become standard | VS Code, JetBrains, build systems embed security linting, safe deps, AI remediation. | AI-generated code explosion + dev environment emerging as key attack surface. |
| Cloud security shifts to “AI infra security” | Focus moves to securing GPUs, model pipelines, inference clusters, vector DBs. | Growing AI data-center buildouts + new AI-specific attack surfaces. |
| Real-time intelligence replaces static feeds | Honeypots, canaries, and AI threat behavior tracking become standard intel. | Feed trends emphasize real exploitation vs. theoretical IOCs. |
| Disclosure rules become more regulated | More legal pressure around CVE disclosures and bug bounty NDAs. | Feed mentions increasing tension around researcher restrictions. |
| New “AI AppSec” teams emerge | Specialized roles secure models, prompts, training data, inference policies. | Traditional AppSec can’t handle model drift, prompt attacks, LLM misuse. |
| AI fuzzing becomes mainstream | Automated exploit generation and test-case generation integrated into CI/CD. | AI makes generating exploit variations trivial, boosting dynamic testing. |
I liked it :-)
For previous stats and insights, check these posts
https://appsecadventures.blogspot.com/2025/05/500-posts-where-am-i.html
https://appsecadventures.blogspot.com/2025/05/500-posts-more-insights.html
Comments
Post a Comment