
Development & Technology121 articles
Architecture, implementation, authentication, and operations. Articles to inform critical decisions in development.


Is your contractor's build environment still running on long-lived tokens? What npm and Actions countermeasures reveal

The Era of AI Finding and Fixing Vulnerabilities — What Clients Must Define in Maintenance Contracts

AI Worm Self-Replication Demonstrated in Copilot for Word: When Internal Documents Become Infection Vectors

Dependabot waits 3 days by default: Redesigning dependency update workflows
Compromised just by placing a video file: The FFmpeg PixelSmash vulnerability and locating affected components

Common AI Integration Standard MCP Updated on July 28 — Will Your Commissioned Internal Integrations Keep Running?

Who oversees the security of AI-written code? Security auditing for Claude Code

Accepting custom-built software: what buyers should verify during user acceptance testing

When told "we will build it with that tech" — 3 criteria clients must evaluate

.NET 8 and .NET 9 in Internal Systems Reach End of Support in November 2026: What Clients Must Check Right Now

"Why Update When It Still Works?": How to Prepare for System End of Support (EOL)

.NET 8 and .NET 9 reach end of support in November — What user enterprises need to decide now

.NET 8 and .NET 9 end of support — Evaluating impact on your organization and deciding by November

What is a vulnerability assessment? | Types, typical costs, tools, and how small businesses should choose a provider

Is AI-generated code safe to run directly in production? Cloud Run sandboxing and key practices for secure execution

How many service account keys have you distributed? The choice of keyless integrations

Delivery is not the finish line: what clients must look for in system maintenance and operations contracts

Before Connecting Internal AI Agents to Business Systems: Essentials of Permission Management (MCP Authorization)

Lost Contact with Your Development Agency? How to Commission Work without Vendor Lock-In

Business system maintenance costs — The real nature of monthly expenses and contracts that prevent stagnation

Before the CEO's Account Gets Taken Over — Two-Step Verification and Passkey Migration for SMEs

Is the inherited authentication code secure? Pitfalls of JWT verification middleware

Demystifying CORS errors and fixing them properly — Ending the outsourcing habit of "just allowing everything"

Continuously checking Python dependency vulnerabilities with uv audit: Institutionalizing vulnerability management for maintenance contracts

Moving beyond login-only authorization: Continuous authorization design for sensitive custom systems

Preserving the "why" behind client systems using architectural decision records (ADRs)

Designing authentication and authorization for AI agents — incorporating permissions and delegation into custom projects

Closing the door on internal network probing — Making SSRF mitigation standard practice in client architecture

Malware Disguised as Attractive Job Offers — Protecting Custom Development Teams from Attacks Targeting Developers

Are You Spending 6 Hours a Week Babysitting AI? — Reducing Hidden Operational Costs of AI in Custom Development

Eliminating Manual SSH Execution on Production Servers — Building Auditable Job Execution Platforms in Custom Development

Implementing Defenses for the AI-Driven Phishing Era via Custom Development — Building in Email Authentication and Spoofing Resilience 2026

Monitoring Starts with Defining "Normal": Designing Monitoring Systems for Handover and Production Operations in Custom Development 2026

Solving "Nobody Knows the Full Picture" with Custom Development — System Inventory Architecture for Visualizing Dependencies 2026

How far should you accept AI refactoring suggestions? — Designing tech debt "decision-making" in custom maintenance

Node.js shifts to an annual major release (Node 27) — LTS strategy and maintenance design for client systems

API Gateway Authorization Bypassed via Trailing Slash — API Authorization Security Audits for Client Systems 2026

Arm Open-Sources Metis ─ Introducing AI Agent-Based AppSec Audits via Custom Development in 2026

Undisclosed URLs discovered in 30 minutes via CT logs: Protecting staging environments in client projects (2026)
Showing 41–80 of 121 articles
Turning concepts into design.
Development Environment↔AI Models
Access Permissions · Data · Logs
Building an environment
to use AI internally
Internal data, development environments, and access permissions. Advancing adoption concepts into concrete technical reviews.
Compare approachesOrganize implementation requirementsTest on a small scale
Read feature 
Google Workspace
administration basics
Resolving administrator uncertainties from rollout to sharing and permissions.
Pricing & rolloutSharing rulesPermissions & security
Read feature 
Getting started with AI
at work
Selecting tasks to delegate, experimenting on a small scale, and operating safely.
How AI worksTesting in workflowsSafe usage
Read feature 
Improvement notebook for
growing your website
Forms, usability, and updates: tackling post-launch improvements one step at a time.
Form optimizationUI refinementsUpdates & operations
Read series