Matteo Bisi

@msbiro.net

Italian DevSecOps Team Leader @cloudnativedaysitaly.org 2026 🇮🇹Organizer Based in Galway, Ireland My blog: www.msbiro.net

It's 2026 and I still get asked why encrypting secrets with git-crypt isn't enough. Short answer: encryption solves confidentiality, not revocation, audit logging, or dynamic secrets. DORA and NIS2 remove any remaining excuse. www.msbiro.net/posts/secret...

In 2026 I Am Still Asked Why You Need a Centralized Secrets Manager

Why a centralized secrets manager is non-negotiable in 2026: the operational limits of git-crypt and sealed-secrets style tools, the DORA and NIS2 mandate, and why OpenBao is now the open source secre...

msbiro.net

The ECB told bank CEOs AI is shortening the gap between vulnerability discovery and exploitation. Action plan due 31 October 2026, DORA as the foundation. Also extending the IT Risk Questionnaire deadline to Feb 2027. My breakdown with CNAPP, hardened images and SBOMs www.msbiro.net/posts/ecb-ai...

ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026

ECB letter on AI-enabled cybersecurity threats: action plan due October 2026, ITRQ deadline extension, CNAPP, hardened images, SBOMs and DORA resilience.

msbiro.net

Episode 3 of my "Back to Basics" series: TLS and PKI from the ground up. What an X.509 certificate actually contains, how the chain of trust works, the TLS 1.3 handshake step by step, and the Kubernetes PKI most engineers never look at. www.msbiro.net/posts/back-t...

Back to Basics: TLS and PKI from the Ground Up

TLS and PKI explained from the ground up: what an X.509 certificate actually contains, how the chain of trust works, what happens during a TLS handshake step by step, and how Kubernetes builds a full ...

msbiro.net

In 2026 I still get asked why enterprises need a hardened container image catalog. DORA and NIS2 mandate it. Container base images are infrastructure and deserve the same governance we always applied to operating systems. www.msbiro.net/posts/harden... #devsecops #nis2

In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog

Why hardened container image catalogs are non-negotiable in 2026: the technological case, the DORA mandate, and the NIS2 obligations explained.

msbiro.net

Your engineering culture is not shaped by the all-hands. It is shaped by your EMs in every 1:1 this week. New post connecting McKinsey 2026 data to what I live daily as a team leader: why middle management is a CTO's highest-ROI investment. www.msbiro.net/posts/engine...

Engineering Managers Are Your Real Culture: Why CTOs Must Invest in Middle Management

Engineering managers are the real culture carriers in your organization. McKinsey 2026 data explains why CTOs must prioritize investment in their middle management layer.

msbiro.net

AI finds zero-days faster than disclosure was designed to handle. Athena is a new coalition: 24+ members, coordinated remediation before public disclosure, 20k findings, 2k patches already. My take on what it means for DevSecOps teams: www.msbiro.net/posts/athena...

Athena Coalition: Coordinated Open Source Defense in the AI Vulnerability Era

Athena is a new industry coalition for coordinated open source vulnerability defense. Here is what it means for DevSecOps teams and security leaders.

msbiro.net

@cloudnativedaysitaly.org Italy 2026 is behind us, and Bologna was worth every bit of the work. As one of the organizers, I wrote a short recap of 2 full days, 40 sessions, 4 workshops, and the community conversations that made this edition special. www.msbiro.net/posts/cloud-...

Cloud Native Days Italy 2026: A Wrap-Up from Bologna

Cloud Native Days Italy 2026 wrapped up in Bologna. A personal recap from one of the organizers: speakers, MCs, sponsors, and a community worth celebrating.

msbiro.net

@sentinelone.com purple-mcp: open-source MCP server for Singularity, 22 read-only tools. I tested the integration with Claude Code. One prompt → alert list, asset context, triage brief. ~6 seconds. No tab-switching. Tested against a live tenant. www.msbiro.net/posts/sentin...

SentinelOne Purple MCP: A Hands-On Guide to Singularity AI Integration

Hands-on review of SentinelOne's purple-mcp: how to connect Singularity alerts, vulnerabilities, and threat hunting to Claude Code for faster SOC triage.

msbiro.net

🎉 PLATINUM SPONSOR ANNOUNCEMENT: Spectro Cloud Spectro Cloud helps enterprises orchestrate infrastructure from cloud to edge, and metal to model. They're also the sponsor behind the CNCF Kairos project: an immutable Linux meta-distribution designed for edge Kubernetes.

CVE-2026-31431 "Copy Fail": nine years in the kernel, root in 732 bytes of Python. No race conditions, no kernel offsets. Container namespaces don't protect you the page cache is shared across the host. Only runtime detection catches this. www.msbiro.net/posts/cve-20...

CVE-2026-31431 Copy Fail: A Nine-Year-Old Kernel Bug, a 732-Byte Script, and a Root Shell

CVE-2026-31431 Copy Fail is a local privilege escalation in the Linux kernel exploitable with a 732-byte Python script. This post covers what it is, how to fix it, what to do when patching isn't immed...

msbiro.net

3 supply chain attacks in 3 weeks. Bitwarden CLI, Trivy, Axios , all used postinstall scripts to steal credentials from developer environments and CI/CD pipelines. EDR doesn't see it coming. I wrote up the pattern and 8 controls worth actually putting in place. 🔗 www.msbiro.net/posts/supply...

Supply Chain Attacks Won't Stop: 8 Controls to Reduce Your Exposure

Bitwarden CLI, Trivy, and Axios compromised in three weeks. Your EDR won't catch postinstall scripts. 8 practical controls to reduce the blast radius.

msbiro.net

Tomorrow K8s 1.36 ships. Ingress NGINX retires, but on security side SELinux labeling GA (faster Pod startup on enforcing systems) + external ServiceAccount signing GA (KMS integration). I've written a breakdown focused on why these matter for your infrastructure → www.msbiro.net/posts/kubern...

Kubernetes 1.36: The Release That Said Goodbye to Ingress NGINX

Kubernetes 1.36 releases tomorrow with a significant security focus: the end of Ingress NGINX, SELinux volume labeling reaching GA, and a set of long-overdue removals that tighten the security posture...

msbiro.net

KubeCon EU 2026 swag: 6 months of Copilot Pro+ First thing I did back home: raise the security baseline of my side project. OpenSSF Scorecard as required merge check · Dependabot for Go + GitHub Actions · SHA-pinned workflows · branch protection via gh api Write-up 👇 www.msbiro.net/posts/actui-...

Hardening ACTUI: Dependabot and OpenSSF Scorecard for a Side Project

Back from KubeCon EU 2026 with a free Copilot Pro+ subscription, I turned my attention to the security posture of apple-container-tui. Here's how I added Dependabot and OpenSSF Scorecard using GitHub ...

msbiro.net

🎉 COMMUNITY PARTNER ANNOUNCEMENT: theRedCode TheRedCode.it a tech blog that shares practical tech guides on DevOps, security and AI for dev and not, in small bits. A huge thank you to Serena Sensini for supporting Cloud Native Days Italy and contributing to the broader cloud-native community! 🙌