Skip to main content

Posts

Sandbox Testing for API-Heavy Systems: What Changes When You Don’t Own the Dependency

Sandbox testing works well when your team controls both sides of the integration. You define the service, you define the mock, you know exactly what the sandbox should return. That setup holds up fine for internal microservices and first-party APIs. It starts to break down when you don’t own the dependency. Payment processors, identity providers, SMS gateways, banking APIs, shipping integrations—these are services your system depends on but can’t fully replicate. Their providers give you a sandbox environment, but that sandbox is a simulation they maintain, not a mirror of what production actually does. The gap between the two is where production incidents are born. Sandbox Drift Is Quieter Than You Think Teams writing integration tests against third-party sandboxes are placing a bet. The bet is that the sandbox accurately reflects how production behaves today, not six months ago when someone last checked. That bet loses more often than teams expect. Provider sandboxes l...
Recent posts

AWS Adds Agentic Workspace to Kiro AI Coding Tool

Amazon Web Services (AWS) this week added an open source workspace for its Kiro artificial intelligence (AI) coding tool that enables application developers to asynchronously assign tasks to an AI agent that is capable of autonomously performing tasks, such as testing code as it is created, in a way that maintains context across multiple sessions. Darko Mesaros, a distinguished developer advocate at AWS, said the Kiro Crew workspace is also capable of creating reusable AI skills by observing the tasks developers assign to Kiro as they write code. Kiro Crew orchestrates agents using the Agent Client Protocol (ACP) to ensure every step is observable in real time as sub-agents are spawned. For example, developers can also hand off a ticket queue to Kiro Crew for it to triage issues and flag what needs their attention or ask it to investigate the root cause of an incident while a developer continues to work on another task. An Activity view shows each agent’s reasoning, every tool call,...

RapidFort Extends Open Source Software Security Reach to Runtime Environments

RapidFort today at the Black Hat USA conference announced it has extended its ability to secure open source software to the runtimes that DevOps teams deploy in production environments. Michael Wood, chief marketing officer for RapidFort, said the RapidFort Runtime platform makes it possible to now monitor open source software deployed within a container image to detect unauthorized or unexpected changes, and proactively assess the impact any report of a newly discovered Common Vulnerabilities and Exposures (CVE) might have. The overall goal is to make it simpler for DevOps teams to run the curated open source software packages that RapidFort already provides in their production environments, adds Wood. At the core of RapidFort Runtime is a Runtime Bill of Materials (RBOM) capability that integrates with pipelines in continuous integration/continuous delivery (CI/CD) platforms and uses application programming interfaces (APIs) and instrumentation to map system calls, network and m...

From API Integration to Agent Governance: What Backend Teams Need to Know About MCP

Many MCP projects begin with an existing API and a simple request: expose one backend capability to an LLM client. The quickest route is to wrap an endpoint as a tool and connect it to Claude or another MCP host. Users can then ask for data in natural language instead of navigating a fixed interface. This creates a production boundary because the model, rather than application code, chooses which operation to call. At Fullinfo, more than 1 million company profiles are served through a GraphQL backend on AWS AppSync. Users previously searched a portal and worked with the results using deterministic flows. With MCP, a user can ask, “Find SaaS companies in Germany with 50-200 employees,” and receive structured records in the conversation. The wrapper was straightforward in TypeScript and Go, but defining the model’s authority required more work. What Changes With MCP Governance? Existing API controls still apply, but they no longer cover the full decision path. A chang...

Shift Left Security: 4 Automated Security Gates in GitHub Actions

A security researcher filed a report against our Node.js API two years ago. The vulnerability was prototype pollution in an npm package we had been shipping for eight months. The fix took about 20 minutes. The internal review to figure out how it got through took two days. The package had a known CVE. It had been sitting in the NVD for months before we found it. Our CI never checked. Code review didn’t catch it. The researcher did. There’s a stat from IBM’s Cost of a Data Breach 2024 report that I keep referencing when this comes up: The average breach costs $4.88 million. Teams running DevSecOps practices save $1.68 million from that cost on average. The number I actually find more useful is smaller. A vulnerability caught in CI costs about $80 to fix. Caught in production, the same costs $7,600. That gap is why this article exists. Four automated security gates wired into GitHub Actions, running on every push and pull request — none of them require an enterprise license: Gate 1:...

N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon

Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing use of generative AI by bad actors and targeting of code repositories to financially focused attacks by nation-state hackers and the abuse of trust by development teams. It also is the latest report to point to the group – known by such names as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces – linked to the Democratic People’s Republic of Korea (DPRK) to supply chain attacks over the past couple of years that involve placing malicious code into packages in the npm repository. “When an attacker compromises a widely used open source package, every organization that depends on that package is potentially affected,” CJ Moses, CISO of Amazon Integrated Security, wrote in the report , adding that they have “observed the volume and s...

Common Risks of Outsourcing Software Development, and How to Tackle Them

Both SMBs and large enterprises often choose software development outsourcing over developing software in-house. It is no surprise, as partnering with external developers enables companies to bridge IT talent gaps that cannot be filled internally, avoid time-consuming recruiting and training processes, and eliminate expenses associated with salaries and benefits, eventually accelerating software delivery and reducing development costs. While software development outsourcing can be highly advantageous from the business perspective, it also introduces various risks, ranging from diminished project control to provider lock-in and security-related issues. Managing these risks proactively is critical to preventing them from escalating, minimizing their impact on the project timeline, budget, and software quality, and ensuring smoother project execution. In this article, experts from Itransition, an outsourcing partner with over 25 years of experience, outline common risks of outsourcing ...