KTKhushi Trivediinkhushitrivedi.hashnode.devĀ·Sep 28 Ā· 7 min readThere's No Shell, So There's Nothing to Pivot IntoThe strongest argument for a shell-less image is not a feature list. It is what happens to an attacker who just got code execution inside your container and then checked what they could do with it. Mo00
KTKhushi Trivediinkhushitrivedi.hashnode.devĀ·Sep 26 Ā· 5 min readAI Is Writing Your Dependencies Now. Here's the New Attack Surface.Ask an LLM to recommend a package and there is a real, measured chance it answers with one that does not exist. Someone noticed this pattern early enough to name it: Seth Larson, a developer-in-reside00
KTKhushi Trivediinkhushitrivedi.hashnode.devĀ·Sep 24 Ā· 5 min readDependency Sprawl: The Transitive Dependencies That Own Your Attack SurfaceWhen a dependency gets exploited, it is almost never the one in your package.json. It is the one three layers under it, maintained by someone whose name you have never seen, pulled in as a side effect00
KTKhushi Trivediinkhushitrivedi.hashnode.devĀ·Sep 23 Ā· 5 min readThe Base-Image Tax: What You Pay for Every Layer You Didn't ChooseYou did not choose most of what is in your base image. Someone else decided it needed a package manager, a shell, a compiler toolchain, and a dozen utilities you will never run in production, and you 00
KTKhushi Trivediinkhushitrivedi.hashnode.devĀ·Sep 22 Ā· 5 min readYou Chose 12 Dependencies. But Actually Shipped 1,400Open your package.json. Count the lines under dependencies. That number is not your attack surface. The number that matters is sitting in node_modules, and almost nobody has actually counted it. The t00