Our Server Got a Second Job: The Fourth of July Cryptominer
Even a security engineer can get pwned. How we traced a cryptominer consuming 12.5 CPU cores to a vulnerable Next.js app—and what the incident taught us about patching,…
11 min readQUENTIN MAYO / FIELD NOTES
Search the notebook for a topic, a tool, or a passing thought.
Even a security engineer can get pwned. How we traced a cryptominer consuming 12.5 CPU cores to a vulnerable Next.js app—and what the incident taught us about patching,…
11 min readAI helped me build more software—and accumulate nearly 1,000 security findings. Then I put agents to work on the backlog. Here’s what I learned about remediation, independent verification,…
15 min readI have a love-hate relationship with cloud computing. Let me start by making something clear: I’m not anti-cloud. AWS is actually my default cloud provider. I use Route…
8 min readThis isn’t one of those posts where I’m going to tell you that I’ve figured out the perfect development environment. I haven’t. There isn’t even necessarily a winner…
13 min readI type the date often enough that copying and pasting it every time became a nuisance. My preferred format is the compact, sortable ISO format: 2026-08-09 On a…
3 min readA step-by-step guide to deploying GitHub Safe-Settings — policy-as-code for a GitHub organization — on a self-hosted Coolify instance. This guide reflects the live securelyprogramming deployment (app served…
4 min read