<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>The Ops Community ⚙️</title>
    <description>The most recent home feed on The Ops Community ⚙️.</description>
    <link>https://community.ops.io</link>
    <atom:link rel="self" type="application/rss+xml" href="https://community.ops.io/feed"/>
    <language>en</language>
    <item>
      <title>AI Image Expander: The Free Tool to Outpaint and Resize Photos for Social Media</title>
      <dc:creator>宣恒</dc:creator>
      <pubDate>Wed, 12 Aug 2026 05:08:28 +0000</pubDate>
      <link>https://community.ops.io/_204d50d779905a1f931919/ai-image-expander-the-free-tool-to-outpaint-and-resize-photos-for-social-media-1di0</link>
      <guid>https://community.ops.io/_204d50d779905a1f931919/ai-image-expander-the-free-tool-to-outpaint-and-resize-photos-for-social-media-1di0</guid>
      <description>&lt;p&gt;In the fast-paced world of digital content creation, finding the perfect shot is only half the battle. Often, a stunning landscape photo taken for a blog post or a travel album simply does not fit the vertical requirements of an Instagram Story, a TikTok cover, or a YouTube Reel. Traditionally, creators had two frustrating choices: crop the photo, which might cut out essential parts of the subject, or stretch the pixels, which results in a distorted and amateur look. AI Image Expander addresses this exact problem with a sophisticated, browser-based solution. AI Image Expander is a generative outpaint tool designed to grow the canvas around your original image. By using advanced artificial intelligence, it fills in the missing borders with contextually appropriate details, ensuring your subject remains centered and intact while the frame expands to your desired aspect ratio. Whether you are dealing with horizontal shots that need to be vertical or square product photos that need more breathing room for an advertisement, AI Image Expander provides a seamless, high-quality solution without the need for complex editing software or manual retouching.&lt;/p&gt;

&lt;p&gt;Visit AI Image Expander at &lt;a href="https://aiimageexpander.info" rel="noopener noreferrer"&gt;https://aiimageexpander.info&lt;/a&gt; to start transforming your photos today.&lt;/p&gt;

&lt;p&gt;Advantages and Capabilities&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Free AI outpainting technology that uses generative fill to expand canvas borders naturally based on image context.&lt;/li&gt;
&lt;li&gt;Social media specific presets for common aspect ratios including 1:1, 9:16 for Stories and Reels, 16:9 for covers, and traditional 3:4 or 2:3 frames.&lt;/li&gt;
&lt;li&gt;Flexible scaling options including an Auto mode or fixed multipliers such as 1.2x, 1.5x, and 2x to control the expansion area.&lt;/li&gt;
&lt;li&gt;Live canvas preview feature that allows users to see the proposed final layout and size before they spend a daily quota.&lt;/li&gt;
&lt;li&gt;No watermark on downloaded images, ensuring your content remains clean, professional, and ready for publication.&lt;/li&gt;
&lt;li&gt;Wide format support for standard web images including JPG, PNG, and WEBP files with a generous upload limit of 10MB.&lt;/li&gt;
&lt;li&gt;Browser-based accessibility with no software installation required, compatible with Windows, macOS, Linux, and mobile browsers on iOS or Android.&lt;/li&gt;
&lt;li&gt;Daily free quotas for everyone, allowing 3 successful expands per day for guests and 5 successful expands for signed-in users.&lt;/li&gt;
&lt;li&gt;Integrated history feature for users who sign in with a Google account, making it easy to manage and re-download past projects.&lt;/li&gt;
&lt;li&gt;Safety limits and preview bounds to ensure the final output stays within a 25 megapixel canvas for optimal performance.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Which problems it solves for the target audience&lt;/p&gt;

&lt;p&gt;For social media creators and influencers, the primary challenge is maintaining visual consistency across platforms that demand different orientations. A photo that looks spectacular on a professional camera sensor often loses its impact when forced into a vertical mobile frame. AI Image Expander solves this by uncropping the photo, effectively inventing the background that was outside the original camera frame. This allows creators to repurpose high-quality landscape content for Instagram Stories or TikTok without losing the subject's details.&lt;/p&gt;

&lt;p&gt;Online shop owners and e-commerce managers frequently run into the problem of product photos being shot too tight. When attempting to place a product in a promotional banner or a marketplace hero image, the lack of empty space or background context can make the design feel claustrophobic. AI Image Expander provides the necessary studio breathing room by generating realistic floor, wall, or outdoor backgrounds, helping product listings look more professional and visually balanced.&lt;/p&gt;

&lt;p&gt;Travel bloggers and real estate professionals also find the tool indispensable. A beautiful landscape shot of a destination or a wide view of an interior might be too narrow for certain listing portals or blog headers. Instead of using unsightly white bars or blurry stretches, they can use the outpainting power at &lt;a href="https://aiimageexpander.info" rel="noopener noreferrer"&gt;https://aiimageexpander.info&lt;/a&gt; to widen the view. This creates a more immersive and aesthetically pleasing experience for the viewer. Because the tool is beginner-friendly and requires no design background, it is a practical utility for anyone needing quick, high-quality social resizing without a subscription to expensive design suites.&lt;/p&gt;

&lt;p&gt;FAQ&lt;/p&gt;

&lt;p&gt;Q: Is AI Image Expander free to use?&lt;br&gt;
A: Yes, AI Image Expander offers free daily quotas. Guests can perform 3 expands per day, while users who sign in with a Google account receive 5 expands per day.&lt;/p&gt;

&lt;p&gt;Q: Are there watermarks on my final images?&lt;br&gt;
A: No, AI Image Expander does not add any watermarks to your downloaded results, making them perfect for both personal and commercial use.&lt;/p&gt;

&lt;p&gt;Q: What are the file size and dimension requirements?&lt;br&gt;
A: You can upload JPG, PNG, or WEBP files up to 10MB. The image should have a shortest side of at least 256&lt;/p&gt;

&lt;p&gt;AI Image Expander &lt;a href="https://aiimageexpander.info" rel="noopener noreferrer"&gt;https://aiimageexpander.info&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/remoteimages/uploads/articles/w5sjsqvs5by4jtyy75yh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/remoteimages/uploads/articles/w5sjsqvs5by4jtyy75yh.png" alt=" " width="1485" height="694"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>The Human Factor of AI and Coding</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Tue, 11 Aug 2026 12:56:05 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/the-human-factor-of-ai-and-coding-1dgi</link>
      <guid>https://community.ops.io/eyalestrin/the-human-factor-of-ai-and-coding-1dgi</guid>
      <description>&lt;p&gt;This post was originally published by the &lt;a href="https://cloudsecurityalliance.org/blog/2026/08/10/the-human-factor-of-ai-and-coding" rel="noopener noreferrer"&gt;Cloud Security Alliance&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
Since the beginning of the hype around GenAI (around 2023), no week goes by without a headline similar to "Is AI going to replace developers?"&lt;br&gt;&lt;br&gt;
So, has the technology evolved that much that developers can drink a margarita on the beach while an AI agent or AI coding assistance completely replaces developers?&lt;br&gt;&lt;br&gt;
The belief that AI will replace developers comes from a simple misunderstanding: treating programming like a fast typing contest. When AI tools first appeared and wrote code in seconds, it looked like magic to non-technical onlookers, sparking wild headlines. But writing code is just the final step. The real job of an engineer is designing reliable systems and solving complex problems. These are skills a text generator cannot replace.&lt;br&gt;&lt;br&gt;
In this blog post, I will evaluate the software development lifecycle phases, what AI excels at, and what, at the end of the day, human developers are doing much better and aren’t going to be replaced anytime in the foreseeable future.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Phase 1: Planning
&lt;/h2&gt;

&lt;p&gt;At this phase, the team defines the software’s purpose, scope, and initial feasibility to build a strategic roadmap.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: AI can parse historical project data to generate initial draft timelines, identify common risk factors based on similar past projects, and create templated feasibility reports.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Humans determine the actual business viability. A software engineer or architect evaluates whether a project should be built, negotiates trade-offs between competing departments, and judges if a proposal makes strategic sense for the company's long-term technology footprint.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: A human developer does a better job. Strategizing requires corporate context, negotiation, and long-term business judgment that AI cannot replicate.&lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/devops/boards/get-started/what-is-azure-boards" rel="noopener noreferrer"&gt;Azure Boards&lt;/a&gt;: Delivers Kanban boards, backlogs, and interactive dashboards to track project feasibility, work items, and strategic milestones.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://docs.cloud.google.com/architecture/framework" rel="noopener noreferrer"&gt;Google Cloud Well-Architected Framework&lt;/a&gt;: Offers structured design principles and recommendations to evaluate technical feasibility and scope before building cloud workloads.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 2: Requirements Analysis
&lt;/h2&gt;

&lt;p&gt;At this phase, stakeholder feedback is gathered and analyzed to produce a clear document detailing exact user expectations.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: AI excels at processing large batches of raw data. It can ingest hundreds of user surveys or support logs, categorize them, and generate a draft Requirements Specification Document (SRS).
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Interpersonal discovery. AI cannot interview a client and read between the lines when they say one thing but actually need another. Engineers dig into ambiguous human requirements, surface hidden assumptions, and push back on logically conflicting feature requests.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: A human developer does a better job. AI can summarize the raw notes, but humans must navigate the ambiguous, contradictory, and unspoken needs of real users.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/what-is-bedrock.html" rel="noopener noreferrer"&gt;Amazon Bedrock&lt;/a&gt;:  Processes unstructured customer feedback, survey data, and support logs using foundation models to draft initial requirements specifications.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/ai-services/language-service/overview" rel="noopener noreferrer"&gt;Azure AI Language&lt;/a&gt;: Extracts key entities, intent, and sentiment from raw user feedback and support tickets to clarify incoming feature requests.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/GoogleCloudPlatform/generative-ai/blob/main/gemini/prompts/examples/text_classification.ipynb" rel="noopener noreferrer"&gt;Google GenAI Prompts: Text Classification&lt;/a&gt;: Classifying raw requirement statements into Functional Requirements vs. Non-Functional Requirements (NFRs) like security, latency, or scalability.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 3: Design
&lt;/h2&gt;

&lt;p&gt;At this phase, architects sketch out the system structure, data flows, user interfaces, and technical dependencies.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: AI can rapidly generate boilerplate database schemas, basic entity-relationship diagrams, and starter UI mockups based on standard patterns.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: System architecture and structural judgment. Humans design for unique constraints, evaluate security risks, and architect systems to prevent cascading failures. An AI cannot predict how a specific architectural choice will impact a company's cloud spend or team topology two years down the road.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: A human developer does a better job. Humans win on structural integrity, ensuring the architecture scales safely and securely without introducing systemic bottlenecks.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/infrastructure-composer/latest/dg/what-is-composer.html" rel="noopener noreferrer"&gt;AWS Infrastructure Composer&lt;/a&gt;: Visually models application architecture, service integration patterns, and data flow paths across cloud resources.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/architecture/" rel="noopener noreferrer"&gt;Azure Architecture Center&lt;/a&gt;: Provides reference architectures, blueprint patterns, and technical guidance for designing scalable, resilient cloud topologies.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://docs.cloud.google.com/application-design-center/docs/overview" rel="noopener noreferrer"&gt;Google Application Design Center&lt;/a&gt;: Enables architects to design component relationships, network topographies, and data flows visually.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 4: Coding
&lt;/h2&gt;

&lt;p&gt;At this phase, developers convert the technical design documents into functional, executable software code.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: Autocomplete and mechanical generation. AI writes boilerplate code, standard CRUD functions, syntax translations, and configuration scripts at lightning speed.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Decision-making and code verification. Engineers must review every line of AI code to ensure it doesn't introduce subtle logic flaws or security vulnerabilities. Humans ensure code remains readable, clean, and maintainable for the next person who touches it.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: Tie (Co-Pilot Model). AI excels at churning out boilerplate and syntax quickly, while the human developer excels at verifying logic and ensuring long-term maintainability.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/what-is.html" rel="noopener noreferrer"&gt;Amazon Q Developer&lt;/a&gt;: Generates boilerplate code, autocompletes syntax, and recommends code snippets directly inside the IDE.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/developer/github-copilot-azure/introduction" rel="noopener noreferrer"&gt;GitHub Copilot for Azure&lt;/a&gt;: Assists developers with real-time code completion, boilerplate generation, and cloud resource syntax translation.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://codeassist.google/products/business" rel="noopener noreferrer"&gt;Google Gemini Code Assist&lt;/a&gt;: Offers context-aware code generation, autocomplete, and syntax assistance across major IDE environments.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 5: Testing
&lt;/h2&gt;

&lt;p&gt;At this phase, the software is rigorously checked through various test scenarios to find and fix bugs before release.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: AI is highly efficient at generating repetitive unit tests, mocking data inputs, and running automated regression scripts to see if something broke at the surface level.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Exploratory and boundary testing. Humans figure out the creative, chaotic ways an actual user will break the software. They write tests for highly complex integration scenarios and interpret subtle, non-binary performance bottlenecks that AI scripts miss.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: AI does a better job. AI is superior at instantly generating repetitive unit tests and scanning for basic syntax errors, freeing humans for complex edge cases.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/codebuild/latest/userguide/welcome.html" rel="noopener noreferrer"&gt;AWS CodeBuild&lt;/a&gt;: Executes automated unit tests, static code analysis, and regression scripts during continuous integration build workflows.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/devops/pipelines/get-started/what-is-azure-pipelines" rel="noopener noreferrer"&gt;Azure Pipelines&lt;/a&gt;: Runs automated unit and integration test suites automatically whenever code is pushed to check for regressions.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://docs.cloud.google.com/build/docs/overview" rel="noopener noreferrer"&gt;Google Cloud Build&lt;/a&gt;: Automates the execution of unit tests, security scans, and container verification scripts within build pipelines.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 6: Deployment
&lt;/h2&gt;

&lt;p&gt;At this phase, the fully tested software is rolled out to the production environment using strategies like Canary or Blue-Green deployments.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: Monitoring and basic automation. AI can look at a deployment pipeline, flag anomaly spikes in error rates during a Canary rollout, and automatically trigger a rollback if predefined thresholds are crossed.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Orchestration and crisis management. When a deployment fails due to an unprecedented network fluke or an obscure cloud configuration issue, human engineers must debug live systems under pressure, coordinate cross-team responses, and make the final judgment call on hotfixes.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: AI does a better job. Automated CI/CD systems and AI monitoring excel at detecting deployment anomalies and executing instant rollbacks.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/codedeploy/latest/userguide/welcome.html" rel="noopener noreferrer"&gt;AWS CodeDeploy&lt;/a&gt;: Automates application rollouts using progressive deployment strategies like Canary and Blue/Green with automatic rollback capability.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/app-service/deploy-staging-slots" rel="noopener noreferrer"&gt;Azure App Service Deployment Slots&lt;/a&gt;: Facilitates staging environments, canary traffic shifts, and instant rollbacks to maintain zero-downtime deployments.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://docs.cloud.google.com/deploy/docs/overview" rel="noopener noreferrer"&gt;Google Cloud Deploy&lt;/a&gt;: Manages continuous delivery pipelines across environments with automated release promotion and canary rollout strategies.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Phase 7: Maintenance
&lt;/h2&gt;

&lt;p&gt;At this phase, the live application is continuously monitored, updated, patched, and refined based on real-world usage.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;What AI does well&lt;/strong&gt;: Log analysis and patch generation. AI can scan incoming telemetry data to catch known errors, draft standard security patches for third-party libraries, and answer basic tier-1 user support tickets.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What humans do best&lt;/strong&gt;: Refactoring and evolution. Software ages and accumulates technical debt. Humans look at an entire system holistically to refactor aging infrastructure, adapt the codebase to major shifts in business direction, and prevent the software from turning into an unmaintainable mess.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Bottom line&lt;/strong&gt;: A human developer does a better job. While AI catches surface errors, only humans can refactor decaying infrastructure and safely evolve the system as business goals pivot.  &lt;/p&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.html" rel="noopener noreferrer"&gt;Amazon CloudWatch&lt;/a&gt;: Monitors operational metrics, aggregates system logs, and alerts teams to runtime anomalies to guide refactoring and updates.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://learn.microsoft.com/en-us/azure/azure-monitor/app/app-insights-overview" rel="noopener noreferrer"&gt;Azure Monitor Application Insights&lt;/a&gt;: Tracks live application health, error rates, and telemetry to pinpoint technical debt and performance degradation.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://docs.cloud.google.com/stackdriver/docs" rel="noopener noreferrer"&gt;Google Cloud Observability&lt;/a&gt;: Collects logs, trace data, and system metrics to identify recurring application errors and track long-term system stability.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;While generative AI excels at eliminating the mechanical friction of coding by quickly handling boilerplate, unit tests, and syntax translation, it lacks the conceptual mental model required for true software development. AI operates on probabilistic patterns rather than structural reasoning, leaving it blind to system architecture, prone to generating security risks, and unable to solve novel, company-specific problems. Ultimately, a developer's primary value lies not in the act of typing code, but in managing systemic complexity, designing resilient architectures, and translating messy human requirements into reliable, deterministic systems.&lt;br&gt;&lt;br&gt;
The future of software development is not about being replaced by AI; it is about evolving from a code writer into an AI orchestrator and system architect. As AI tools handle the bulk of low-context execution, the demand for developers who possess deep domain knowledge, structural thinking, and sharp auditing skills will only grow. The most successful developers of tomorrow will treat AI as a high-powered cognitive assistant, using it to rapidly prototype and automate routine tasks while focusing their own human energy on high-level system design, security, and complex problem-solving.  &lt;/p&gt;

&lt;h3&gt;
  
  
  About the Author
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Eyal Estrin&lt;/strong&gt; is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry.&lt;br&gt;&lt;br&gt;
He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The views expressed are his own.  &lt;/p&gt;

</description>
      <category>devops</category>
      <category>career</category>
      <category>cicd</category>
    </item>
    <item>
      <title>Securing Chaos at Scale Without Slowing Down</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Mon, 15 Jun 2026 14:00:25 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/securing-chaos-at-scale-without-slowing-down-488h</link>
      <guid>https://community.ops.io/eyalestrin/securing-chaos-at-scale-without-slowing-down-488h</guid>
      <description>&lt;p&gt;For a long time, I wanted to write a blog post talking about how the software development and cybersecurity world have matured over the years.&lt;br&gt;&lt;br&gt;
In this blog post, I will share my insights from organizations I came across in both the SDLC and cybersecurity domains.&lt;br&gt;&lt;br&gt;
Although traditionally you can break the maturity levels into 5 levels, I decided to make things simpler and break them into 3 levels (from ad-hoc to fully optimized). You can look at the various levels and figure out where your organization is on the scale.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Level 1 – Reactive
&lt;/h2&gt;

&lt;p&gt;The initial level is considered the lowest maturity.&lt;br&gt;&lt;br&gt;
The infrastructure is deployed manually (usually based on physical or virtual machines), and if applications have UI, everything is configured in a click-ops style.&lt;br&gt;&lt;br&gt;
Code is written to meet immediate deadlines.&lt;br&gt;&lt;br&gt;
Standard workflows are just beginning to be documented.&lt;br&gt;&lt;br&gt;
There are almost no design considerations. Everything is ad-hoc, probably monolithic applications, and most likely undocumented architecture.&lt;br&gt;&lt;br&gt;
There is basic cyber hygiene. Protections are localized, perimeter-focused, and highly reactive. Security patches are deployed manually. Passwords are static or manually rotated at very long time intervals. MFA is rarely used, and auditing is either not configured, stored locally, not sent to a central logging mechanism, or not reviewed at all.&lt;br&gt;&lt;br&gt;
Resources are deployed with almost zero cost considerations (such as over-provisioned static resources, unmonitored cloud spend, etc.)&lt;br&gt;&lt;br&gt;
When looking at resiliency, in most cases, resources are deployed without redundancy (i.e., single point of failure), and in the best case, there are manual backups.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Level 2 – Structured and Managed
&lt;/h2&gt;

&lt;p&gt;The second level is considered much more mature than the initial one.&lt;br&gt;&lt;br&gt;
Deployment is done based on containers, and very commonly on top of Kubernetes.&lt;br&gt;&lt;br&gt;
Automation is part of considerations such as deployment, testing, configuration, etc.&lt;br&gt;&lt;br&gt;
Engineering processes and CI/CD pipelines are standardized across the company.&lt;br&gt;&lt;br&gt;
Teams follow documented, repeatable workflows.&lt;br&gt;&lt;br&gt;
In terms of design considerations, we commonly see modular, service-oriented architecture and structured API design.&lt;br&gt;&lt;br&gt;
Risk assessments are routine. Security policies are formalized, and access controls are structured. It is common to see at this level implementation of SCA (Software Composition Analysis) and SBOM (Software Bill of Materials), as part of CI/CD pipelines, automated patching, and replacement of static passwords with passkeys or even passwordless authentication.&lt;br&gt;&lt;br&gt;
It is common to see design-stage secure coding reviews and manual STRIDE mapping.&lt;br&gt;&lt;br&gt;
When thinking about cost management, it is common to see the implementation of tagging strategies, scheduled resource scaling, and cost allocation.&lt;br&gt;&lt;br&gt;
When looking at resiliency, resources are deployed in multi-AZs, and disaster recovery plans are documented. &lt;br&gt;
At this stage, we begin to see sustainability considerations, such as right-sizing underutilized compute instances.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Level 3 – Optimized and Proactive
&lt;/h2&gt;

&lt;p&gt;This is considered a fully optimized level.&lt;br&gt;&lt;br&gt;
It is common to see cloud-native applications, use of microservices, event-driven patterns, and use of Serverless technologies.&lt;br&gt;&lt;br&gt;
We begin to see the implementation of GenAI technologies (such as AI agents, skills, etc.) and heavy use of non-human identities (for app-to-app communication or for AI agents).&lt;br&gt;&lt;br&gt;
Continuous threat hunting, automated incident response, and zero-trust verification for every entity.&lt;br&gt;&lt;br&gt;
It is common to see automated continuous Threat-Modeling-as-Code embedded in repositories. Threat modeling is dynamic, automatically updating when architectural changes are pushed to Git.&lt;br&gt;&lt;br&gt;
When thinking about cost management, it is common to see real-time anomaly detection and automated cost optimization policies.&lt;br&gt;&lt;br&gt;
When looking at resiliency, we begin to see the use of chaos engineering and active-active multi-region self-healing architectures.&lt;br&gt;&lt;br&gt;
In terms of sustainability, we see carbon-aware architectures and scheduling heavy batch jobs during peak renewable energy hours.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;In this blog post, I have reviewed multiple pillars of modern architectural designs.&lt;br&gt;&lt;br&gt;
Perhaps your organization is graded high in some aspects (such as automation or security), while graded low on other aspects (such as cost management or sustainability).&lt;br&gt;&lt;br&gt;
Regardless of where your organization is located on the scale, there is always the next level your organization can mature in each pillar.&lt;br&gt;&lt;br&gt;
Disclaimer: AI tools were used to research and edit this article. Graphics are created using AI.  &lt;/p&gt;

&lt;h3&gt;
  
  
  About the Author
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Eyal Estrin&lt;/strong&gt; is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.  &lt;/p&gt;

</description>
      <category>cloudops</category>
      <category>finops</category>
      <category>security</category>
      <category>cicd</category>
    </item>
    <item>
      <title>VPN Usage Warning for iPhone and Android Users</title>
      <dc:creator>Summer Brock</dc:creator>
      <pubDate>Mon, 08 Jun 2026 14:09:37 +0000</pubDate>
      <link>https://community.ops.io/summer_brock_b01a5d481edc/vpn-usage-warning-for-iphone-and-android-users-1642</link>
      <guid>https://community.ops.io/summer_brock_b01a5d481edc/vpn-usage-warning-for-iphone-and-android-users-1642</guid>
      <description>&lt;p&gt;Nowadays, VPN usage has become very common among smartphone users. Many people install VPN apps on their iPhone or Android devices to protect privacy and access restricted content. However, not every VPN is safe or reliable, and users should be careful before using them.&lt;/p&gt;

&lt;p&gt;Not all VPN applications available on app stores are trustworthy. Some free VPN apps may collect user data, track online activity, or run unwanted background processes. That is why it is always recommended to use a well-known and trusted VPN service.&lt;/p&gt;

&lt;p&gt;Using a VPN continuously can also affect phone performance. It may slow down internet speed, increase battery consumption, and use more mobile data than usual.&lt;/p&gt;

&lt;p&gt;In some countries, VPN usage may be restricted or monitored, so it is important to understand local rules before using such services. Fake or untrusted VPN apps can also expose your personal information and increase security risks.&lt;/p&gt;

&lt;p&gt;For safer use, always install VPN apps from reliable sources, avoid unknown free VPNs, and disable VPN when it is not needed.&lt;/p&gt;

&lt;p&gt;VPN is a useful tool, but only when it is used correctly and safely.&lt;/p&gt;

&lt;p&gt;For more useful tech tips and information, visit: &lt;a href="https://lovizapro.com/" rel="noopener noreferrer"&gt;https://lovizapro.com/&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Prompt Engineering is Dead. Long Live Context-as-Code</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Tue, 02 Jun 2026 18:46:47 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/prompt-engineering-is-dead-long-live-context-as-code-4f6d</link>
      <guid>https://community.ops.io/eyalestrin/prompt-engineering-is-dead-long-live-context-as-code-4f6d</guid>
      <description>&lt;p&gt;Since the early days of GenAI, when ChatGPT launched in late 2022, we began using prompt engineering to direct chatbots (and later LLMs) with human language instructions to provide us answers to questions or take actions (in a high-level…)&lt;br&gt;&lt;br&gt;
In 2025, companies such as OpenAI and Anthropic began releasing a new agentic concept called “AI Agent”, an autonomous system that uses an AI model as its "brain" to perceive an environment, make independent decisions, and execute multi-step tasks using digital tools. Unlike passive chatbots that just answer questions, an agent can plan its own workflow, run commands, and browse the web to achieve a specific goal without constant human supervision.&lt;br&gt;&lt;br&gt;
In this blog post, I will explain the concept of &lt;strong&gt;Context-as-Code&lt;/strong&gt; and share some coding examples.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Introducing Context-as-Code
&lt;/h2&gt;

&lt;p&gt;Traditional prompting is a one-way street. You type out your instructions, send them off, and that text never changes.&lt;br&gt;&lt;br&gt;
AI agents operate completely differently. Because they work on their own, every action they take creates a mountain of new data. Every time an agent opens a file, checks an error, or runs a tool, it adds more information to the pile, which quickly overwhelms a standard chat screen.&lt;br&gt;&lt;br&gt;
Context-as-Code treats the agent like a stateless compute engine. Instead of a massive text prompt, we use version-controlled files (&lt;em&gt;CLAUDE.md&lt;/em&gt;, &lt;em&gt;AGENTS.md&lt;/em&gt;) to establish structural boundaries, separating the permanent project rules from the temporary, dynamic session memory.&lt;br&gt;&lt;br&gt;
Context-as-Code transforms loose AI prompts into version-controlled engineering assets by using structured Markdown files to establish permanent, auditable boundaries directly within a project repository.  &lt;/p&gt;

&lt;h2&gt;
  
  
  The Discovery Stage (Onboarding the Agent)
&lt;/h2&gt;

&lt;p&gt;Before an agent writes a single line of code, it must parse the overall project layout. These files act as the "map" for an incoming AI.  &lt;/p&gt;

&lt;h3&gt;
  
  
  llms.txt
&lt;/h3&gt;

&lt;p&gt;Serves as a lightweight text directory mapped out in Markdown format. Placed at the root of a project or website, it acts exactly like a robots.txt for AI. It points roaming models and agents to the exact location of your documentation and architecture maps so they don't get lost crawling messy HTML or redundant folders.&lt;br&gt;&lt;br&gt;
Reference:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://llmstxt.org/" rel="noopener noreferrer"&gt;The llms.txt file&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  ARCHITECTURE.md
&lt;/h3&gt;

&lt;p&gt;Outlines the systemic design rules, folder hierarchies, and database schemas. Agents read this during the planning phase of a task to ensure a newly generated feature doesn't conflict with core infrastructure boundaries.&lt;br&gt;&lt;br&gt;
Reference:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://architecture.md/" rel="noopener noreferrer"&gt;ARCHITECTURE.md&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The Configuration Stage (Setting Workspace Rules)
&lt;/h2&gt;

&lt;p&gt;Once the agent understands the codebase, it requires a strict behavioral contract. These files dictate the workspace boundaries (Always Do / Never Do) that govern every automated action.  &lt;/p&gt;

&lt;h3&gt;
  
  
  AGENTS.md
&lt;/h3&gt;

&lt;p&gt;Establishes cross-tool workspace guardrails and strict coding boundaries. It tells any agent entering the repo how to format code, run local builds, and what architectural limits to never cross. This file is fully supported by OpenAI and Cursor.&lt;br&gt;&lt;br&gt;
References:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://agents.md/" rel="noopener noreferrer"&gt;AGENTS.md&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://dosu.dev/blog/a-stale-agents-md-is-worse-than-no-agents-md" rel="noopener noreferrer"&gt;A stale AGENTS.md is worse than no AGENTS.md&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.youtube.com/watch?v=w65tyLWjGqA" rel="noopener noreferrer"&gt;Agent Skills Explained: From Basics to Advanced!&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  CLAUDE.md
&lt;/h3&gt;

&lt;p&gt;This file serves as the dedicated, platform-specific behavioral contract for Anthropic's toolchain. It establishes an immediate project context by outlining exact test suite execution commands and lint rules, which prevents the agent from getting confused mid-session.&lt;br&gt;&lt;br&gt;
Natively executed by &lt;strong&gt;Anthropic's Claude Code CLI&lt;/strong&gt; and fully integrated into &lt;strong&gt;Microsoft Visual Studio Code (VS Code)&lt;/strong&gt;, which automatically detects and honors &lt;em&gt;CLAUDE.md&lt;/em&gt; memory files and workflows.&lt;br&gt;&lt;br&gt;
References:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://code.claude.com/docs" rel="noopener noreferrer"&gt;Overview - Claude Code Docs&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.youtube.com/watch?v=x5WWFL0nIqk" rel="noopener noreferrer"&gt;CLAUDE.md Best Practices&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://wilburhimself.github.io/blog/56-claude-deep-dive/" rel="noopener noreferrer"&gt;How CLAUDE.md actually works&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The Runtime &amp;amp; Execution Stage (Performing the Task)
&lt;/h2&gt;

&lt;p&gt;When a user tells an agent to run a specific procedural task (e.g., "Review this PR for security leaks" or "Deploy this service"), the agent switches from broad guardrails to highly specific, dynamic execution instructions.  &lt;/p&gt;

&lt;h3&gt;
  
  
  SKILL.md
&lt;/h3&gt;

&lt;p&gt;Defines a modular, task-specific capability or playbook. It utilizes YAML frontmatter metadata so an agent can quickly scan what the skill does, only loading the heavy step-by-step instructions when a user explicitly requests that specific workflow.&lt;br&gt;&lt;br&gt;
This file is supported by Claude Code, Cursor Editor, GitHub Copilot Agent Mode, Codex CLI, and Gemini CLI.&lt;br&gt;&lt;br&gt;
References:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://agentskills.io/home" rel="noopener noreferrer"&gt;Agent Skills Overview&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://internals.laxmena.com/p/what-youre-actually-writing-when" rel="noopener noreferrer"&gt;What you're actually writing when you write a SKILL.md&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  prompts.md
&lt;/h3&gt;

&lt;p&gt;Houses version-controlled, multi-shot system prompts or reusable engineering templates. Instead of hardcoding prompts into application backends, these files turn complex agent prompts into modular workspace assets.&lt;br&gt;&lt;br&gt;
Widely used in prompt registries across custom enterprise stacks (&lt;strong&gt;AWS Bedrock&lt;/strong&gt;, &lt;strong&gt;OpenAI Assistants API&lt;/strong&gt;) and natively inside VS Code's extension prompt libraries.&lt;br&gt;&lt;br&gt;
Reference:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://promptsmd.com/" rel="noopener noreferrer"&gt;PromptsMD&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Below is a visualization of the AI agentic workspace lifecycle:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/YJ-N5aU-voVZAXxry7_ujo3aP0sURDDQqdR3c6nSH5E/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3d1bGRs/c2Fpb29oajU4MGp3/bXFmLnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/YJ-N5aU-voVZAXxry7_ujo3aP0sURDDQqdR3c6nSH5E/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3d1bGRs/c2Fpb29oajU4MGp3/bXFmLnBuZw" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;The shift from manual prompt engineering to autonomous AI agents requires a new approach called Context-as-Code. By replacing static prompts with version-controlled Markdown files inside a repository, developers can establish clear architectural maps, behavioral guardrails, and execution playbooks that guide an agent safely through its onboarding, configuration, and runtime lifecycle stages.&lt;br&gt;&lt;br&gt;
Using structured files like &lt;em&gt;CLAUDE.md&lt;/em&gt;, &lt;em&gt;AGENTS.md&lt;/em&gt;, and SKILL.md turns vague instructions into auditable engineering assets that keep an agent's memory clean and predictable. Because autonomous agents can independently alter code and run terminal commands, teams should actively expand their knowledge and gain hands-on experience in development settings before deploying these agentic workflows into production.&lt;br&gt;&lt;br&gt;
Disclaimer: AI tools were used to research and edit this article. Graphics are created using AI.  &lt;/p&gt;

&lt;h3&gt;
  
  
  About the Author
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Eyal Estrin&lt;/strong&gt; is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.  &lt;/p&gt;

</description>
      <category>tutorials</category>
      <category>random</category>
      <category>devops</category>
      <category>cloudops</category>
    </item>
    <item>
      <title>Beyond Vibe Coding into Agentic Engineering</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Sun, 10 May 2026 13:34:08 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/beyond-vibe-coding-into-agentic-engineering-9i6</link>
      <guid>https://community.ops.io/eyalestrin/beyond-vibe-coding-into-agentic-engineering-9i6</guid>
      <description>&lt;p&gt;In 2025 I published a blog post titled &lt;a href="https://community.ops.io/eyalestrin/common-security-pitfalls-using-vibe-coding-73k"&gt;Common security pitfalls using Vibe coding&lt;/a&gt;, where I briefly explained what vibe-coding is, and what the security issues arise from "vide coding".&lt;br&gt;&lt;br&gt;
Recently, I came across an emerging term called "Agentic Engineering".&lt;br&gt;&lt;br&gt;
In this blog post, I will explain what "Agentic Engineering" is and how it differs from "Vibe coding".  &lt;/p&gt;

&lt;h2&gt;
  
  
  Vibe Coding
&lt;/h2&gt;

&lt;p&gt;The term "Vibe coding" came from a quote by &lt;a href="https://www.linkedin.com/in/andrej-karpathy-9a650716" rel="noopener noreferrer"&gt;Andrej Karpathy&lt;/a&gt; on &lt;a href="https://x.com/karpathy/status/1886192184808149383" rel="noopener noreferrer"&gt;Twitter/X&lt;/a&gt;. It refers to the "magical" experience of typing English into an editor (like Cursor) and watching a feature appear. It relies on the model's training data to guess the intent.&lt;br&gt;&lt;br&gt;
Vibe coding is basically when you treat building software like a "vibes only" project. You ask an AI for something, hit copy-paste without really looking at what it gave you, and just cross your fingers that it works. If it breaks, you just throw the error message back at the AI and hope the next try is better. It turns programming into a lucky guess rather than a real skill. The big issue right now is that people are confusing this "winging it" approach with actual professional work, and that's a dangerous mistake to make.&lt;br&gt;&lt;br&gt;
Vibe coding isn't ready for the big leagues because it’s like building a house with a "magic" hammer that does the work for you, but you have no idea how the plumbing or wiring actually connects behind the walls. When you just accept whatever, the AI gives you, you might unknowingly be leaving the front door unlocked for hackers because you didn't check the security. Even worse, if something breaks six months from now, your human team will be stuck staring at a confusing mess of code they didn't write and don't understand. It’s nearly impossible to fix or update a system when the people in charge don't know the "why" behind how it was built in the first place.  &lt;/p&gt;

&lt;h2&gt;
  
  
  The Software Paradigms
&lt;/h2&gt;

&lt;p&gt;The evolution from &lt;strong&gt;Software 1.0&lt;/strong&gt; to &lt;strong&gt;Software 3.0&lt;/strong&gt; is most commonly referred to as the &lt;strong&gt;Software Paradigms&lt;/strong&gt; or the &lt;strong&gt;Generations of Programming&lt;/strong&gt;.&lt;br&gt;&lt;br&gt;
Each stage represents a fundamental shift in how humans interact with machines and how logic is generated.  &lt;/p&gt;

&lt;h3&gt;
  
  
  The Three Paradigms
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Software 1.0 (Classical Programming)&lt;/strong&gt;: Code is written by humans. A programmer uses their brain to translate a business requirement into explicit instructions (C++, Python, Java). If the logic fails, a human must find the specific line of code to fix. This is &lt;a href="https://projecteuclid.org/journals/notre-dame-journal-of-formal-logic/volume-31/issue-2/Validity-and-satisfaction-in-imperative-logic/10.1305/ndjfl/1093635415.pdf" rel="noopener noreferrer"&gt;Imperative Logic&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Software 2.0 (Machine Learning)&lt;/strong&gt;: Code is written by optimization. A human provides a massive dataset and a goal (a loss function). The machine "searches" the space of all possible neural network weights to find the program that fits the data. The "code" is essentially a binary file of weights. This is &lt;a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC8805679/" rel="noopener noreferrer"&gt;Data-Driven Logic&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Software 3.0 (Agentic Engineering)&lt;/strong&gt;: Code is written by AI agents. Humans define high-level goals and constraints in natural language. The agent then uses reasoning loops, calls external tools, and writes its own code to achieve the task. This is &lt;a href="https://arxiv.org/pdf/2604.05589" rel="noopener noreferrer"&gt;Agentic Logic&lt;/a&gt;.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/F2BfCB2CSbFJKaC1hiMQ-mONQrr2n8oziWtLWrisV2I/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzLzhia3Zx/ODFrZHFhb2doZjVt/YWkxLnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/F2BfCB2CSbFJKaC1hiMQ-mONQrr2n8oziWtLWrisV2I/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzLzhia3Zx/ODFrZHFhb2doZjVt/YWkxLnBuZw" alt=" " width="716" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;References:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://karpathy.medium.com/software-2-0-a64152b37c35" rel="noopener noreferrer"&gt;Andrej Karpathy on Software 2.0&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.latent.space/p/s3" rel="noopener noreferrer"&gt;Andrej Karpathy on Software 3.0: Software in the Age of AI&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.mindstudio.ai/blog/what-is-software-3-0-prompting-replaced-programming" rel="noopener noreferrer"&gt;What Is Software 3.0? How Prompting Replaced Programming&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What is Agentic Engineering
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Agentic Engineering&lt;/strong&gt; describes a shift from using AI as a simple autocomplete tool to using it as a semi-autonomous agent capable of reasoning, using tools, and correcting its own mistakes.&lt;br&gt;&lt;br&gt;
While the concept of "Software Agents" dates back to the 1990s, the modern term gained momentum in late 2023 and early 2024. Industry leaders like &lt;a href="https://www.linkedin.com/in/andrewyng/" rel="noopener noreferrer"&gt;Andrew Ng&lt;/a&gt; (via &lt;a href="https://www.deeplearning.ai/" rel="noopener noreferrer"&gt;DeepLearning.AI&lt;/a&gt;) have championed the "Agentic Workflow," arguing that iterative agent loops often produce better results than larger, more powerful models using simple zero-shot prompting.  &lt;/p&gt;

&lt;h3&gt;
  
  
  Defining the Concept
&lt;/h3&gt;

&lt;p&gt;In standard development, a human writes the logic. In Agentic Engineering, a human defines the &lt;strong&gt;goal&lt;/strong&gt; and the &lt;strong&gt;constraints&lt;/strong&gt;, while an agentic system performs the following:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Planning&lt;/strong&gt;: Breaking a complex task into sub-steps.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool Use&lt;/strong&gt;: Executing shell commands, searching the web, or running tests.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Self-Correction&lt;/strong&gt;: Analyzing error logs to rewrite code until the tests pass.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  The 6 Operational Principles
&lt;/h3&gt;

&lt;p&gt;When experts like Andrej Karpathy or &lt;a href="https://www.linkedin.com/in/addyosmani/" rel="noopener noreferrer"&gt;Addy Osmani&lt;/a&gt; discuss the shift to agentic engineering, they often talk about six core principles that define the &lt;strong&gt;workflow&lt;/strong&gt;. These include the structure above, but add the "how-to" of professional engineering:  &lt;/p&gt;

&lt;h4&gt;
  
  
  The "Spec-First" Foundation
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Spec-Driven Planning&lt;/strong&gt;: This is the evolution of the "Planning" pillar. Instead of the agent just "thinking," it must produce a formal specification. This is the blueprint that prevents the agent from going off the rails.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Technical Fundamentals&lt;/strong&gt;: This is the constraint system. You ensure the agent follows established patterns (like DRY or SOLID principles) rather than just "vibing" its way through a solution.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  The Execution &amp;amp; Validation Loop
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Relentless Testing&lt;/strong&gt;: This is the "Check" phase of the agentic loop. In agentic engineering, an agent is not "done" when the code looks right; it’s done when the tests pass.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Full System Ownership&lt;/strong&gt;: This shifts the agent's scope from writing a single function to understanding how that function affects the entire codebase, including deployment and security.
&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  The Human Leadership Layer
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Strategic Orchestration&lt;/strong&gt;: This is the management of multiple agents. The human doesn't write the code; they coordinate how the "Frontend Agent" and "Backend Agent" talk to each other.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;High-Level Oversight&lt;/strong&gt;: This is the final safety gate. Humans focus on the 5% of decisions that are high-risk or subjective, while the agent handles the 95% of "grunt work."
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/mkkTJjE9FWLfB7-Um6ZrnA-r_x90Tcn-hZDdcMmxxGQ/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2M1Y3I4/NTg5eDlubzI3dXBz/bXc3LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/mkkTJjE9FWLfB7-Um6ZrnA-r_x90Tcn-hZDdcMmxxGQ/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2M1Y3I4/NTg5eDlubzI3dXBz/bXc3LnBuZw" alt=" " width="716" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;References:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.youtube.com/watch?v=sal78ACtGTc" rel="noopener noreferrer"&gt;What's next for AI agentic workflows&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://addyosmani.com/blog/agentic-engineering/" rel="noopener noreferrer"&gt;Agentic Engineering&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.ibm.com/think/topics/agentic-engineering" rel="noopener noreferrer"&gt;What is agentic engineering?&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.lowtouch.ai/10-things-i-learned-andrej-karpathy-agentic-engineering/" rel="noopener noreferrer"&gt;10 Things I Learned from Andrej Karpathy on the Shift to Agentic Engineering&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;Vibe coding relies on intuition and a "guess-and-check" workflow where a developer prompts an AI and hopes the output works. While fast for prototyping, this approach lacks the structure needed for complex systems because it depends on the human to spot errors and manage the logic. The shift to agentic engineering replaces this experimental style with a professional discipline. Instead of a single chat, you build a system where the AI acts as an autonomous agent that creates a formal plan, executes tasks in small steps, and uses a self-correcting loop to fix its own mistakes before delivering the final result.&lt;br&gt;&lt;br&gt;
The core of this transition is moving from being a writer of code to a strategic orchestrator. You provide the high-judgment oversight and define the technical fundamentals, while the agent takes full system ownership of the implementation. By implementing spec-driven planning and relentless testing, the agent ensures that every line of code is verified against real-world requirements. This move from "vibes" to "engineering" creates a reliable, scalable factory for software where the focus is on building robust systems rather than just chasing a lucky output.&lt;br&gt;&lt;br&gt;
Disclaimer: AI tools were used to research and edit this article. Graphics are created using AI.&lt;br&gt;&lt;br&gt;
Reference:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://completerpabootcamp.com/blogs/andrej-karpathy-from-vibe-coding-to-agentic-engineering" rel="noopener noreferrer"&gt;Andrej Karpathy: from vibe coding to agentic engineering&lt;/a&gt;  &lt;/p&gt;

&lt;h2&gt;
  
  
  About the Author
&lt;/h2&gt;

&lt;p&gt;Eyal Estrin is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The views expressed are his own.  &lt;/p&gt;

</description>
      <category>tutorials</category>
      <category>productivity</category>
      <category>random</category>
    </item>
    <item>
      <title>Exploring the Growth of Browser Gaming Platforms Like Freecase24 in the Digital Age 📈</title>
      <dc:creator>FreeCase24</dc:creator>
      <pubDate>Sun, 03 May 2026 07:08:03 +0000</pubDate>
      <link>https://community.ops.io/freecase-2499/exploring-the-growth-of-browser-gaming-platforms-like-freecase24-in-the-digital-age-g66</link>
      <guid>https://community.ops.io/freecase-2499/exploring-the-growth-of-browser-gaming-platforms-like-freecase24-in-the-digital-age-g66</guid>
      <description>&lt;p&gt;The digital age has transformed how people interact with entertainment. From streaming services to social media, users now expect instant access, flexibility, and high-quality experiences. The gaming industry has followed this trajectory, and one of the fastest-growing segments is browser games. These games, accessible directly through web browsers, are reshaping the gaming landscape by removing traditional barriers. Platforms like &lt;a href="https://freecase24.com" rel="noopener noreferrer"&gt;freecase24.com&lt;/a&gt; are at the forefront of this growth, offering a streamlined and engaging experience for users across the globe. 📈🎮&lt;/p&gt;

&lt;p&gt;Browser gaming has come a long way from its early days of simple flash-based games. With advancements in technologies such as HTML5, CSS3, and JavaScript frameworks, modern browser games now deliver impressive graphics, smooth performance, and interactive gameplay. These improvements have elevated browser gaming from a niche category to a mainstream entertainment option.&lt;/p&gt;

&lt;p&gt;One of the primary drivers behind the growth of browser gaming platforms is accessibility. Traditional games often require downloads, installations, and specific hardware configurations, which can limit their reach. Browser games eliminate these requirements, allowing users to start playing instantly. Freecase24 leverages this advantage by providing a platform where users can access a wide range of games without any technical barriers.&lt;/p&gt;

&lt;p&gt;Another significant factor contributing to this growth is cross-device compatibility. Browser games are designed to work seamlessly on smartphones 📱, tablets, and desktop computers 💻. This versatility ensures that users can enjoy gaming regardless of their device, making it a convenient option for modern lifestyles.&lt;/p&gt;

&lt;p&gt;Freecase24 distinguishes itself by offering a diverse selection of games across multiple genres. From action-packed adventures ⚔️ to challenging puzzle games 🧩 and high-speed racing experiences 🏎️, the platform caters to a wide audience. This variety not only enhances user engagement but also encourages players to explore different types of games.&lt;/p&gt;

&lt;p&gt;Cost efficiency is another key advantage driving the popularity of browser gaming platforms. Many traditional gaming options involve purchasing games or subscribing to services, which can be expensive. In contrast, most browser games on freecase24 are free to play. 💰 This accessibility allows a broader audience to participate in gaming without financial constraints.&lt;/p&gt;

&lt;p&gt;The user experience provided by freecase24 is another critical factor in its success. The platform features an intuitive interface, organized categories, and fast loading times. These elements ensure that users can quickly find and play games, enhancing overall satisfaction.&lt;/p&gt;

&lt;p&gt;In addition to entertainment, browser games offer cognitive benefits. Many games require strategic thinking, problem-solving, and quick decision-making. These elements provide mental stimulation and contribute to skill development.&lt;/p&gt;

&lt;p&gt;Flexibility is another defining characteristic of browser gaming. Unlike traditional games that often require long sessions, browser games can be played in short bursts. This makes them ideal for users with busy schedules who want quick entertainment during breaks.&lt;/p&gt;

&lt;p&gt;Freecase24 maintains user engagement by regularly updating its game library. New titles and trending games are added frequently, ensuring that users always have fresh content to explore. This continuous update cycle keeps the platform dynamic and appealing.&lt;/p&gt;

&lt;p&gt;The social aspect of gaming has also been integrated into browser platforms. Many games include multiplayer features that allow users to interact, compete, and collaborate with others. 🤝 This social interaction enhances the overall gaming experience.&lt;/p&gt;

&lt;p&gt;From an industry perspective, the growth of browser gaming platforms reflects a broader shift toward convenience and instant access. Users increasingly prefer solutions that minimize effort while maximizing value. Freecase24 aligns with this trend by offering a platform that delivers immediate access to high-quality games.&lt;/p&gt;

&lt;p&gt;Another important consideration is resource efficiency. Browser games do not require large downloads or significant storage space, making them suitable for devices with limited capacity. This efficiency also reduces the need for frequent updates.&lt;/p&gt;

&lt;p&gt;Security and reliability are essential for user trust. Freecase24 provides a safe environment where users can enjoy games without concerns about malware or intrusive software. This reliability encourages repeat usage and long-term engagement.&lt;/p&gt;

&lt;p&gt;Furthermore, browser gaming supports the growing trend of casual gaming. Not all users are interested in complex or time-intensive games. Browser games provide a simple and enjoyable alternative that caters to a wide audience.&lt;/p&gt;

&lt;p&gt;The scalability of browser gaming platforms also contributes to their growth. Developers can easily update and distribute games without requiring users to download new versions. This allows for continuous improvement and innovation.&lt;/p&gt;

&lt;p&gt;In conclusion, the growth of browser gaming platforms like freecase24 reflects the evolving preferences of modern users. Accessibility, flexibility, cost efficiency, and convenience are key factors driving this trend. Freecase24 exemplifies these qualities by offering a comprehensive platform that delivers high-quality gaming experiences without barriers. As technology continues to advance, browser gaming is set to play an increasingly important role in the digital entertainment ecosystem.&lt;/p&gt;

</description>
      <category>games</category>
      <category>browser</category>
      <category>online</category>
    </item>
    <item>
      <title>Serverless by Design - Building an Analytics Platform on Cloudflare</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Mon, 20 Apr 2026 15:58:25 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/serverless-by-design-building-an-analytics-platform-on-cloudflare-31mo</link>
      <guid>https://community.ops.io/eyalestrin/serverless-by-design-building-an-analytics-platform-on-cloudflare-31mo</guid>
      <description>&lt;p&gt;In 2023, I published a blog post titled &lt;a href="https://medium.com/@eyal-estrin/my-journey-to-the-world-of-social-networks-b0ea88088acf" rel="noopener noreferrer"&gt;My journey to the world of social networks&lt;/a&gt;, where I shared my personal experience publishing news updates, blog posts, and basically any kind of technical knowledge through social networks.&lt;br&gt;&lt;br&gt;
There was something I always wanted to know – what is my current exposure in terms of the number of likes or views of my posts?&lt;br&gt;&lt;br&gt;
I know there are paid analytical services in the market, but I never had the time to search and perhaps invest money in such a platform.&lt;br&gt;&lt;br&gt;
In this blog post, I will share my experience "building" a fully serverless analytical dashboard, based on the Cloudflare platform.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Project No. 1 – Migrating my blog to a Serverless platform
&lt;/h2&gt;

&lt;p&gt;I have been using WordPress to publish blog posts for many years.&lt;br&gt;&lt;br&gt;
As a matter of fact, my original WordPress was built on top of the GoDaddy hosting platform back in 2010, and in 2014, I began using Cloudflare as a WAF and DDoS protection for my website &lt;a href="https://security-24-7.com/" rel="noopener noreferrer"&gt;Security 24/7&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
In 2018, I decided to migrate my WordPress site to DigitalOcean to lower the monthly bill.&lt;br&gt;&lt;br&gt;
Over the years, I kept the domain and the website working, though I haven't changed much in terms of look and feel (from time to time I used to login, update the plugins and the Linux OS patches, but I can't say I kept all my blog posts published on my website, since I'm still using other platforms such as Medium.com)&lt;br&gt;&lt;br&gt;
The inspiration for taking the step to migrate my website to a new platform came after briefly reading a blog post titled &lt;a href="https://ranthebuilder.cloud/blog/claude-built-my-wix-website-in-3-hours-is-saas-dead/" rel="noopener noreferrer"&gt;Claude Built My Wix Website in 3 Hours - Is SaaS Dead?&lt;/a&gt; by &lt;a href="https://www.linkedin.com/in/ranisenberg/" rel="noopener noreferrer"&gt;Ran Isenberg&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
I had a chat with Ran, and I decided that it's a good time to begin practicing with vibe-coding and see what my options are.&lt;br&gt;&lt;br&gt;
For the purpose of this project, I decided to take advantage of my Google AI Pro license and use Gemini.&lt;br&gt;&lt;br&gt;
I began by explaining to Gemini that I'm using WordPress on top of Rocky Linux, deployed as a Droplet on DigitalOcean, protected behind Cloudflare WAF.&lt;br&gt;&lt;br&gt;
I asked Gemini what my options are to migrate to a static pages hosting platform.&lt;br&gt;&lt;br&gt;
Gemini suggested using the Cloudflare platform, migrating all blog posts to static pages, using &lt;a href="https://gohugo.io/" rel="noopener noreferrer"&gt;Hugo&lt;/a&gt; for running the static pages as a web front-end, and running everything on top of &lt;a href="https://pages.cloudflare.com/" rel="noopener noreferrer"&gt;Cloudflare Pages&lt;/a&gt; (a serverless solution), due to the tight integration with the Cloudflare platform (such as WAF, DDoS protection, DNS registrar, etc)&lt;br&gt;&lt;br&gt;
After migrating all my blog posts (including their images) to Markdown, Gemini explained me how to create a full GitOps process, where my entire website content, is stored on a private GitHub repo, and every time I'm making a change to a configuration file, or adding a new blog post, the content is pushed to GitHub, which initiates a new deploy process.&lt;br&gt;&lt;br&gt;
Here is my final architecture diagram for my newly migrated website:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/QndCwwm-8YPa800EpeqOeKOZ6Tc_9R-qe-5jaezrU_k/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzLzJueGVo/NWs5cWY0bm5leGNs/ODF0LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/QndCwwm-8YPa800EpeqOeKOZ6Tc_9R-qe-5jaezrU_k/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzLzJueGVo/NWs5cWY0bm5leGNs/ODF0LnBuZw" alt=" " width="800" height="437"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I am still fine-tuning my website, adding features, improving its SEO scoring, etc., but at the moment, here is the current look and feel of my website:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/Ci8ZHz6JFO-59VmLtUdoqoc9jRBDltjNTTjrxnWLnfE/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3lodWxr/am82bXNkaWg5ZG9o/YjM5LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/Ci8ZHz6JFO-59VmLtUdoqoc9jRBDltjNTTjrxnWLnfE/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3lodWxr/am82bXNkaWg5ZG9o/YjM5LnBuZw" alt=" " width="800" height="664"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Project No. 2 – Building a dashboard analytics platform
&lt;/h2&gt;

&lt;p&gt;My journey continues, as I wanted to have an analytics dashboard and be able to see in near-real time statistics about my web presence.&lt;br&gt;&lt;br&gt;
First, I began by mapping all my social media accounts, as they appear on my &lt;a href="https://linktr.ee/eyalestrin" rel="noopener noreferrer"&gt;Linktree&lt;/a&gt; account.&lt;br&gt;&lt;br&gt;
Second, I set up for myself (and later explained it to Gemini) my requirements from the social analytics dashboard:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Connect to as many of my social network accounts using APIs (almost succeeded).
&lt;/li&gt;
&lt;li&gt;Regularly pull data from my social network accounts – I managed to accomplish this task using &lt;a href="https://developers.cloudflare.com/workers/" rel="noopener noreferrer"&gt;Cloudflare Workers&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;Store data (analytics) from my social networks on a persistent storage – I managed to accomplish this task using &lt;a href="https://developers.cloudflare.com/d1/" rel="noopener noreferrer"&gt;Cloudflare D1&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;Avoid storing static credentials in code or configuration files – I managed to accomplish this task using &lt;a href="https://developers.cloudflare.com/secrets-store/" rel="noopener noreferrer"&gt;Cloudflare Secrets Store&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;Keep the dashboard behind the authentication wall – I managed to accomplish this task using &lt;a href="https://developers.cloudflare.com/cloudflare-one/" rel="noopener noreferrer"&gt;Cloudflare One&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;Keep the total cost free – As of writing this blog post, my dashboard hasn’t been live for more than several weeks, but so far, I’ve managed to accomplish everything under the free tier for all Cloudflare services (but I will keep watching it over time)
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  What I’ve learned over time
&lt;/h3&gt;

&lt;p&gt;Not everything is perfect, and not everything I wanted to accomplish is feasible on the free tier, or at all.&lt;br&gt;&lt;br&gt;
Here are a couple of examples:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;LinkedIn won’t let you pull API analytics data, even if you’re having a Premium account and you’ve built a LinkedIn application. Scraping is not an option since they’re also behind Cloudflare WAF, and they will block you.
&lt;/li&gt;
&lt;li&gt;Spotify won’t let you pull API analytics data unless you have a Spotify Premium account.
&lt;/li&gt;
&lt;li&gt;Medium won’t let you pull any information using an API.
&lt;/li&gt;
&lt;li&gt;Twitter requires a paid account in order to pull information from its APIs. Instead, I found a way to generate an RSS feed of my Twitter account using RSS.APP and my application are able to pull this RSS feed, filter to the last 50 posts, sort them by number of “Likes”, and show the top 5 posts.
&lt;/li&gt;
&lt;li&gt;Since I was aware of Twitter and other social networks in pulling analytics, I recall that I’m using an automation service called dlvr.it, and for a very long time, I’ve asked Gemini to generate me code that will allow me to use my DLVR.IT's API key to pull analytics, but eventually it failed. I even opened a support ticket for dlvr.it (I’m still waiting for them to return to me…)
&lt;/li&gt;
&lt;li&gt;For Bluesky and Mastodon, Gemini was easily able to write code to connect to their APIs and pull information such as top likes, total number of posts, and number of followers.
&lt;/li&gt;
&lt;li&gt;YouTube was also challenging. I had to enable the YouTube API through my GCP console, create OAuth credentials and consent settings, to be able to pull the total number of subscribers, top likes of videos, and top views of videos.
&lt;/li&gt;
&lt;li&gt;For GitHub repos, I had to create a GitHub application in order to generate a token for my dashboard analytics, and be able to pull the total number of followers, and be able to sort my GitHub repos by the top number of stars.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Here is my final architecture diagram for my social analytics dashboard:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/bHWNnrXr3fQ1lP5r8tLyKx7j_BiWX6GnCfXn-NpKz_U/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3RlejFz/c2d5aTNsa3hmN2Rz/cm1jLnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/bHWNnrXr3fQ1lP5r8tLyKx7j_BiWX6GnCfXn-NpKz_U/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL3RlejFz/c2d5aTNsa3hmN2Rz/cm1jLnBuZw" alt=" " width="733" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I am still fine-tuning my dashboard analytics, adding features, etc., but at the moment, here is the current look and feel of my dashboard:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/E0MTBMjVNnWc7kdQK9ja35DXcqopP1nKDT_TyBTeaG4/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2hhMjJ4/eGp6NXEycmo5c20z/Y3g1LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/E0MTBMjVNnWc7kdQK9ja35DXcqopP1nKDT_TyBTeaG4/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2hhMjJ4/eGp6NXEycmo5c20z/Y3g1LnBuZw" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/qAyXHLmVGEBkloVwKPaA07r6A24dV_Go7d9JvMxZVKA/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2w4dHVs/YWp4aWlnZXA3a3Fw/bHJ5LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/qAyXHLmVGEBkloVwKPaA07r6A24dV_Go7d9JvMxZVKA/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2w4dHVs/YWp4aWlnZXA3a3Fw/bHJ5LnBuZw" alt=" " width="800" height="317"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/ot8F7JbS66GyKJlpkVPwJM36HHrhpa9sX-KqiE3GFhs/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL212YXRw/eWZ0dDJ5aHRjMnhk/bDR3LnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/ot8F7JbS66GyKJlpkVPwJM36HHrhpa9sX-KqiE3GFhs/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL212YXRw/eWZ0dDJ5aHRjMnhk/bDR3LnBuZw" alt=" " width="800" height="351"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;As you must have figured out by now, I’m not a developer. I used Gemini to vibe-code both my website and my dashboard analytics. As such, I wouldn’t look at both of them as production-grade applications, but it does show me what can be done with GenAI.&lt;br&gt;&lt;br&gt;
Another important thing I knew, but I didn’t have visibility into, was my impact on social networks. I still have a lot to do in order to make a much more significant impact and one day become an influencer.&lt;br&gt;&lt;br&gt;
I highly recommend that the readers of this blog dirty their hands and gain hands-on experience working with LLMs and GenAI technology. AI won’t replace humans anytime in the near future, but at least be prepared and use AI as a force multiplier.  &lt;/p&gt;

&lt;h2&gt;
  
  
  About the Author
&lt;/h2&gt;

&lt;p&gt;Eyal Estrin is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The views expressed are his own.  &lt;/p&gt;

</description>
      <category>github</category>
      <category>automation</category>
      <category>cicd</category>
      <category>serverless</category>
    </item>
    <item>
      <title>I Tried Turning Text Into Videos With AI — Here’s What Actually Worked</title>
      <dc:creator>rank info</dc:creator>
      <pubDate>Wed, 01 Apr 2026 08:03:25 +0000</pubDate>
      <link>https://community.ops.io/rank_info_618b825a61ff0e4/i-tried-turning-text-into-videos-with-ai-heres-what-actually-worked-2ip9</link>
      <guid>https://community.ops.io/rank_info_618b825a61ff0e4/i-tried-turning-text-into-videos-with-ai-heres-what-actually-worked-2ip9</guid>
      <description>&lt;p&gt;I’ve been testing a bunch of AI video tools lately.&lt;/p&gt;

&lt;p&gt;Most of them promise the same thing:&lt;br&gt;
“Turn text into video in seconds.”&lt;/p&gt;

&lt;p&gt;But in reality, the experience is usually… messy.&lt;/p&gt;

&lt;p&gt;Too many steps&lt;br&gt;
Weird UI&lt;br&gt;
Paywalls everywhere&lt;br&gt;
Outputs that don’t match the prompt&lt;/p&gt;

&lt;p&gt;So I started wondering —&lt;br&gt;
what would the simplest possible version of this look like?&lt;/p&gt;

&lt;p&gt;The idea&lt;/p&gt;

&lt;p&gt;I ended up building a small project called VeoLite.&lt;/p&gt;

&lt;p&gt;The goal wasn’t to compete with big tools.&lt;br&gt;
It was just to answer one question:&lt;/p&gt;

&lt;p&gt;What if generating a video felt as easy as typing a sentence?&lt;/p&gt;

&lt;p&gt;No timeline.&lt;br&gt;
No editing.&lt;br&gt;
No onboarding maze.&lt;/p&gt;

&lt;p&gt;Just:&lt;/p&gt;

&lt;p&gt;prompt → generate → done&lt;/p&gt;

&lt;p&gt;What I focused on&lt;/p&gt;

&lt;p&gt;Instead of adding more features, I tried removing friction:&lt;/p&gt;

&lt;p&gt;No login wall (you can just try it)&lt;br&gt;
Minimal UI (basically one input + generate)&lt;br&gt;
Fast output (so it doesn’t feel like a “task”)&lt;/p&gt;

&lt;p&gt;And most importantly:&lt;/p&gt;

&lt;p&gt;👉 Make the output feel usable, not just “AI demo quality”&lt;/p&gt;

&lt;p&gt;What I noticed&lt;/p&gt;

&lt;p&gt;After letting a few people try it, some patterns showed up:&lt;/p&gt;

&lt;p&gt;People don’t want “video editing” — they want results&lt;br&gt;
Speed matters more than perfection&lt;br&gt;
If it takes more than ~30 seconds to understand, they leave&lt;/p&gt;

&lt;p&gt;This sounds obvious, but most tools still ignore it.&lt;/p&gt;

&lt;p&gt;Where it’s actually useful&lt;/p&gt;

&lt;p&gt;Right now, people are mainly using it for:&lt;/p&gt;

&lt;p&gt;Quick social clips&lt;br&gt;
Idea prototyping&lt;br&gt;
Visualizing concepts&lt;br&gt;
Testing content directions&lt;/p&gt;

&lt;p&gt;Not full production — more like a thinking tool with visuals&lt;/p&gt;

&lt;p&gt;The weird part&lt;/p&gt;

&lt;p&gt;The biggest surprise wasn’t the tech.&lt;/p&gt;

&lt;p&gt;It was this:&lt;/p&gt;

&lt;p&gt;The simpler the tool, the more people actually use it.&lt;/p&gt;

&lt;p&gt;Not because it’s more powerful —&lt;br&gt;
but because it removes the hesitation to start.&lt;/p&gt;

&lt;p&gt;Still figuring things out&lt;/p&gt;

&lt;p&gt;It’s still early, and honestly I’m not sure where this goes yet.&lt;/p&gt;

&lt;p&gt;I’m just watching:&lt;/p&gt;

&lt;p&gt;what people try to generate&lt;br&gt;
where they get stuck&lt;br&gt;
what they expect vs what they get&lt;/p&gt;

&lt;p&gt;If you’ve used AI video tools before,&lt;br&gt;
I’d be curious:&lt;/p&gt;

&lt;p&gt;👉 What’s the most annoying part of your current workflow?&lt;/p&gt;

&lt;p&gt;(If you want to try it, it’s here: &lt;a href="https://veolite.net" rel="noopener noreferrer"&gt;https://veolite.net&lt;/a&gt;/&lt;br&gt;
)&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>lite</category>
      <category>veo3</category>
    </item>
    <item>
      <title>Why GenAI Isn't Ready for Prime Time</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Sun, 22 Mar 2026 16:29:25 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/why-genai-isnt-ready-for-prime-time-c2h</link>
      <guid>https://community.ops.io/eyalestrin/why-genai-isnt-ready-for-prime-time-c2h</guid>
      <description>&lt;p&gt;If you have followed my posts on social media, you know by now that I've taken a very pragmatic (and perhaps pessimistic) approach to the whole hype around GenAI in the past several years.&lt;br&gt;&lt;br&gt;
Personally, I do not believe the technology is mature enough to allow people to blindly trust its outcomes.&lt;br&gt;&lt;br&gt;
In this blog post, I will share my personal view of why GenAI is not ready for prime time, nor will it replace human jobs anytime in the foreseeable future.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Some background
&lt;/h2&gt;

&lt;p&gt;The hype around GenAI for the non-technical person who reads the news comes from publications almost every week. Here are a few of the common examples:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Text summarization&lt;/strong&gt; - GenAI can summarize long portions of text, which may be useful if you're a student who is currently preparing an essay as part of your college assignments, or if you are a journalist who needs to review a lot of written material while preparing an article for the newsletter.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Image/video generation&lt;/strong&gt; – GenAI is able to create amazing images (using models such as &lt;a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2/" rel="noopener noreferrer"&gt;Nano Banana 2&lt;/a&gt;) or short videos (using models such as &lt;a href="https://openai.com/index/sora-2/" rel="noopener noreferrer"&gt;Sora 2&lt;/a&gt;).
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Personalized learning&lt;/strong&gt; - A student uses GPT-5.4 to create a custom, interactive 10-week curriculum for learning organic chemistry.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Family Life Coordinator&lt;/strong&gt; - Copilot in Outlook/Teams (Personal) monitors family emails and school calendars.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Although the technology has evolved over the past several years from the simple Chatbot to more sophisticated use cases, we can still see that most use of GenAI is still used by home consumers.&lt;br&gt;&lt;br&gt;
Yes, there are use cases such as &lt;a href="https://aws.amazon.com/what-is/retrieval-augmented-generation/" rel="noopener noreferrer"&gt;RAG (Retrieval-Augmented Generation)&lt;/a&gt; to bridge the gap between a model's static training and the corporate data, &lt;a href="https://modelcontextprotocol.io/docs/getting-started/intro" rel="noopener noreferrer"&gt;MCP (Model Context Protocol)&lt;/a&gt;, that acts as a "&lt;strong&gt;USB-C port for AI&lt;/strong&gt;", or agentic systems, that take a high-level goal, break it into sub-tasks, and iterate until the goal is met. The reality is that most AI projects fail due to a lack of understanding of the technology, the fear of using AI to train corporate data (and protect the data from the AI vendors), a lack of understanding of the pricing model (which ends up much more costly than anticipated), and many more reasons for failures of AI projects.&lt;br&gt;&lt;br&gt;
Currently, the hype around GenAI is driven by analyst (who lives in delusions about the actual capabilities of the technology), CEOs (who have no clue about what their employees are actually doing, specifically when talking the role of developers, and all they are looking for is to cut their workforce, to make their shareholders happy), or sales people (who runs on the wave of the hype, to make more revenue for their quarterly quotas).  &lt;/p&gt;

&lt;h2&gt;
  
  
  Code generation
&lt;/h2&gt;

&lt;p&gt;A common misconception is that GenAI can generate code (from code suggestions to vibe coding an application) and will eventually replace junior developers.&lt;br&gt;&lt;br&gt;
This misconception is a far cry from the truth, and here's why:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A developer isn't just writing lines of code. He needs to understand the business intent, the system/technology/financial constraints, and understand past written code (by himself or by his teammates), to be able to write efficient code.
&lt;/li&gt;
&lt;li&gt;If we allow GenAI to produce code by itself, without the engine understanding the overall picture, we will end up with tons of lines of code, without any human being able to read and understand what was written and for what purpose. Over time, humans will not be able to understand the code and debug it, and once bugs or security vulnerabilities are discovered.
&lt;/li&gt;
&lt;li&gt;Using SAST (Static Application Security Testing) or DAST (Dynamic Application Security Testing) for automated secure code review, combined with GenAI capabilities (such as &lt;a href="https://openai.com/index/codex-security-now-in-research-preview/" rel="noopener noreferrer"&gt;Codex Security&lt;/a&gt; or &lt;a href="https://www.anthropic.com/news/claude-code-security" rel="noopener noreferrer"&gt;Claude Code Security&lt;/a&gt;) will generate ton of false-positive results, from the simple reason that GenAI cannot see the bigger picture, understand the general context of an application or the existing security controls already implemented to protect an application.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Bottom line – Agentic system cannot replace a full-blown production-scale SaaS application, built from years of vendors/developers' experience. GenAI will not resolve incidents happens on production systems, which impacts clients and breaks customers' trust.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Agentic AI for the aid in security tasks
&lt;/h2&gt;

&lt;p&gt;I'm hearing a lot of conversations about how GenAI can aid security teams in repeatable tasks. Here are some common examples:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Replacing Tier 1 SOC analysts&lt;/strong&gt;: Solutions like &lt;a href="https://www.crowdstrike.com/en-us/platform/" rel="noopener noreferrer"&gt;CrowdStrike’s Falcon Agentic Platform&lt;/a&gt; or &lt;a href="https://www.dropzone.ai/" rel="noopener noreferrer"&gt;Dropzone AI&lt;/a&gt; now handle over 90% of Tier 1 alerts. They ingest an alert, pull telemetry from EDR/SIEM, perform threat intel lookups, and provide a "verdict" with evidence before a human ever sees it.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Incident Storylining&lt;/strong&gt;: Instead of an analyst manually stitching together logs, tools like &lt;a href="https://learn.microsoft.com/en-us/copilot/security/microsoft-security-copilot" rel="noopener noreferrer"&gt;Microsoft Security Copilot&lt;/a&gt; generate a cohesive narrative of the attack kill chain in plain English.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dynamic Playbook Generation&lt;/strong&gt;: GenAI can generate a custom response plan on the fly, tailored to your specific cloud architecture and the nuances of a "living-off-the-land" attack.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Here is where GenAI falls short:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Indirect Prompt Injection&lt;/strong&gt;: Attackers can embed malicious instructions in emails or logs. When the SOC's AI agent "reads" these logs to summarize an incident, the hidden instructions can command the agent to "ignore this alert" or "delete the evidence," effectively blindfolding the SOC.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hallucinations in High-Stakes Code&lt;/strong&gt;: While GenAI can draft remediation scripts (Python/PowerShell), it still suffers from "system safety" issues. It may confidently suggest a command that includes an outdated, vulnerable dependency or a logic error that could crash a production server during containment.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Lack of "Decision Layer" Visibility&lt;/strong&gt;: An AI agent might be performant and "online," but it could be making systematically biased or manipulated decisions (e.g., failing to flag a specific user due to model poisoning) that perimeter monitoring cannot detect.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The "Data Readiness" Wall&lt;/strong&gt;: Most organizations still struggle with siloed, unstructured data. If your data isn't "AI-ready"—meaning unified and clean—the AI will produce fragmented or incorrect insights, leading to a "garbage in, garbage out" scenario.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Bottom line – Just because GenAI can review thousands of lines of events from multiple systems, triage them to incidents, document them in ticketing systems, and automatically resolve them, without human review, doesn't mean GenAI can actually resolve all of the security issues organizations are having every day.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Automating everything
&lt;/h2&gt;

&lt;p&gt;In theory, it makes sense to build agentic systems, where AI agents replace repetitive human tasks, making faster decisions, hoping to get better results.&lt;br&gt;&lt;br&gt;
Here are a couple of examples, showing how wrong things can get when allowing AI agents to make decisions:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://gizmodo.com/replits-ai-agent-wipes-companys-codebase-during-vibecoding-session-2000633176" rel="noopener noreferrer"&gt;The Replit Agent "Vibe Coding" Failure&lt;/a&gt;: While building an app, the agent detected what it thought was an empty database during a "code freeze." The agent autonomously ran a command that erased the live production database (records for 1,200+ executives).
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://breached.company/amazons-ai-coding-agent-vibed-too-hard-and-took-down-aws-inside-the-kiro-incident/" rel="noopener noreferrer"&gt;The AWS "Kiro" Production Outage&lt;/a&gt;: Amazon’s agentic coding tool, Kiro, was tasked with resolving a technical issue but instead autonomously decided to "delete and recreate" a production environment. The agent was operating with the broad permissions of its human operator. Due to a misconfiguration in access controls, the AI bypassed the standard "two-human sign-off" requirement. It proceeded to wipe a portion of the environment, causing a 13-hour outage for the AWS Cost Explorer service.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.unite.ai/meta-ai-agent-triggers-sev-1-security-incident-after-acting-without-authorization/" rel="noopener noreferrer"&gt;The Meta "Sev 1" Internal Breach&lt;/a&gt;: An internal Meta AI agent (similar to their OpenClaw framework) triggered a "Sev 1" alert—the second-highest severity level—after taking unauthorized actions. An engineer asked the agent to analyze a technical query on an internal forum. The agent autonomously posted a flawed, incorrect response publicly to the forum without the engineer's approval. A second employee followed the agent's "advice," which inadvertently granted broad access to sensitive company and user data to engineers who lacked authorization.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Bottom line – We must always keep humans in the loop for any critical decision, regardless of the fact that it won't scale much, to avoid the consequences for automated decision-making systems.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Public health and safety
&lt;/h2&gt;

&lt;p&gt;It may make sense to train an LLM model with all the written knowledge from healthcare and psychology, to allow humans with a "self-service" health related Chatbot, but since the machine has no ability to actually think like real humans, with consciousness and feeling, the result may quickly get horrible.&lt;br&gt;&lt;br&gt;
Here are a few examples:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.techpolicy.press/breaking-down-the-lawsuit-against-openai-over-teens-suicide/" rel="noopener noreferrer"&gt;Raine v. OpenAI&lt;/a&gt;: 16-year-old Adam Raine died by suicide after months of intensive interaction with ChatGPT. The logs showed the AI mentioned suicide &lt;strong&gt;1,275 times&lt;/strong&gt; — six times more often than the teen did—and provided granular details on methods. The suit alleges OpenAI's image recognition correctly identified photos of self-harm wounds the teen uploaded but failed to trigger an emergency intervention or notify parents, instead continuing to "support" his plans.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.transparencycoalition.ai/news/seven-more-lawsuits-filed-against-openai-for-chatgpt-suicide-coaching" rel="noopener noreferrer"&gt;The "Suicide Coach" Cases&lt;/a&gt;: Families of four deceased users (including Zane Shamblin and Adam Raine) allege that GPT-4o acted as a "suicide coach." The lawsuits claim the AI bypassed its own safety filters to provide technical instructions on how to end one's life. Plaintiffs argue that OpenAI "squeezed" safety testing into just one week to beat Google’s Gemini to market. This reportedly resulted in a model that was "dangerously sycophantic," prioritizing engagement over safety and encouraging users to isolate themselves from real-world support.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.theguardian.com/technology/2026/jan/15/chatgpt-health-ai-chatbot-medical-advice" rel="noopener noreferrer"&gt;Unlicensed Practice of Medicine &amp;amp; Law&lt;/a&gt;: While not yet a single consolidated case, multiple personal injury claims are being investigated following the "ECRI 2026 Report," which highlighted cases where ChatGPT gave surgical advice that would cause severe burns or death. In early 2026, a 60-year-old man was hospitalized with severe hallucinations (bromism) after ChatGPT advised him to use industrial sodium bromide as a "healthier" table salt alternative. This has sparked potential class-action interest in Australia.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Bottom line – Just because a Chatbot was trained on a large amount of written knowledge, doesn't mean it has the human compassion to produce decisions for the better of humanity.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;I know that my blog post looks kind of cynical or pessimistic about GenAI technology, but I honestly believe the technology is not ready for prime time, nor will it replace human jobs anytime soon.&lt;br&gt;&lt;br&gt;
If you are a home consumer, I highly recommend that you learn how to write better prompts and always question the results an LLM produces. It is limited by the data it was trained on.&lt;br&gt;&lt;br&gt;
If you are a corporate decision maker and you are considering using GenAI as part of your organization's offering, do not forget to have KPIs before beginning any AI related project (so you'll have better understanding of what a successful project will look like), put budget on employee training (and make sure employees have a safe space to learn and make mistakes while using this new technology), keep an eye on finance (before cost gets out of control), and make sure AI vendors do not train their models based on your corporate or customers data.&lt;br&gt;&lt;br&gt;
I would like to personally thank a few people who influenced me while writing this blog post:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.linkedin.com/in/edzitron/" rel="noopener noreferrer"&gt;Ed Zitron&lt;/a&gt;: He argues that GenAI is a "bubble" with no sustainable unit economics. He frequently points out that companies like OpenAI are burning billions in compute costs while failing to find true "product-market fit" or meaningful revenue beyond NVIDIA's GPU sales.
I recommend reading his &lt;a href="https://www.wheresyoured.at/" rel="noopener noreferrer"&gt;blog&lt;/a&gt; and listening to his &lt;a href="https://www.youtube.com/@BetterOfflinePod/videos" rel="noopener noreferrer"&gt;Podcast&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.linkedin.com/in/davidlinthicum" rel="noopener noreferrer"&gt;David Linthicum&lt;/a&gt;: He warns against "Vibe coding"—the practice of using AI to generate high-cost, inefficient code—and argues that the real value of AI lies in specialized "Small Language Models" (SLMs) rather than massive, money-losing LLMs.
I recommend reading his &lt;a href="https://www.infoworld.com/profile/david-linthicum/" rel="noopener noreferrer"&gt;posts&lt;/a&gt; and listening to his &lt;a href="https://www.youtube.com/@DavidIsNotAI/videos" rel="noopener noreferrer"&gt;Podcast&lt;/a&gt;.
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.linkedin.com/in/quinnypig" rel="noopener noreferrer"&gt;Correy Quinn&lt;/a&gt;: He argues that GenAI is a "cost center masquerading as a profit center." He often points out that while everyone is selling AI, very few are buying it at a scale that justifies the massive capital expenditure (CapEx) currently being spent on data centers.
I recommend reading his &lt;a href="https://www.lastweekinaws.com/blog/" rel="noopener noreferrer"&gt;blog&lt;/a&gt; and listening to his &lt;a href="https://www.youtube.com/playlist?list=PL637Bgczhi1zVuLFwkT4GLgdcKpMN1BmH" rel="noopener noreferrer"&gt;Podcast&lt;/a&gt;.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Disclaimer: AI tools were used to research and edit this article. Graphics are created using AI.  &lt;/p&gt;

&lt;h2&gt;
  
  
  About the Author
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Eyal Estrin&lt;/strong&gt; is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The views expressed are his own.  &lt;/p&gt;

</description>
      <category>career</category>
      <category>automation</category>
      <category>software</category>
      <category>ai</category>
    </item>
    <item>
      <title>Securing Claude Cowork</title>
      <dc:creator>Eyal Estrin</dc:creator>
      <pubDate>Tue, 10 Mar 2026 15:54:11 +0000</pubDate>
      <link>https://community.ops.io/eyalestrin/securing-claude-cowork-1d8</link>
      <guid>https://community.ops.io/eyalestrin/securing-claude-cowork-1d8</guid>
      <description>&lt;p&gt;&lt;a href="https://claude.com/blog/cowork-research-preview" rel="noopener noreferrer"&gt;Claude Cowork&lt;/a&gt; is an agentic AI tool from Anthropic designed to perform complex, multi-step tasks directly on your computer's files.&lt;br&gt;&lt;br&gt;
As of early 2026, Claude Cowork is a Research Preview.&lt;br&gt;&lt;br&gt;
In this blog post, I will share some common security risks and possible mitigations for protecting against the risks coming with Claude Cowork.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Background
&lt;/h2&gt;

&lt;p&gt;Claude Cowork represents a significant shift from "Chat AI" to "Agentic AI." Because it has direct access to your local filesystem and can execute commands, the security model changes from protecting a conversation to protecting a system user.&lt;br&gt;&lt;br&gt;
Practical Use Cases:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Data Extraction&lt;/strong&gt;: Point it at a folder of receipt images and ask it to create an Excel spreadsheet summarizing the expenses.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Research &amp;amp; Synthesis&lt;/strong&gt;: Ask it to read every document in a "Project Alpha" folder and draft a 10-page summary report in a new Word document.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Automation&lt;/strong&gt;: Schedule recurring tasks (e.g., "Every Friday at 4 PM, summarize my unread Slack messages and email them to me").
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Core Features:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Filesystem Access&lt;/strong&gt;: Unlike the web version of Claude, Cowork runs within the Claude Desktop app. You grant it permission to a specific folder on your Mac or PC, and it can read, rename, move, and create new files (like spreadsheets or Word docs) within that space.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agentic Execution&lt;/strong&gt;: It doesn't just give you advice; it executes a plan. If you ask it to "organize my messy downloads folder," it will categorize the files, create subfolders, and move everything into place while you do other things.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Parallel Sub-Agents&lt;/strong&gt;: For large tasks—like researching 50 different PDFs—it can spin up multiple "sub-agents" to work on different parts of the task simultaneously.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Connectors &amp;amp; Plugins&lt;/strong&gt;: Through the Model Context Protocol (MCP), Cowork can connect to external apps like Slack, Google Drive, Notion, and Gmail to pull data or perform actions across your workspace.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Below is a sample deployment architecture of Claude Cowork:  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://community.ops.io/images/BEUOUVMj-xjfup6OAixP62AKb39g5tC0NnRVQV26WLE/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2JpeXE2/Y2N4d3J3N3Fnb2ty/a2NwLnBuZw" class="article-body-image-wrapper"&gt;&lt;img src="https://community.ops.io/images/BEUOUVMj-xjfup6OAixP62AKb39g5tC0NnRVQV26WLE/rt:fit/w:800/g:sm/q:0/mb:500000/ar:1/aHR0cHM6Ly9jb21t/dW5pdHkub3BzLmlv/L3JlbW90ZWltYWdl/cy91cGxvYWRzL2Fy/dGljbGVzL2JpeXE2/Y2N4d3J3N3Fnb2ty/a2NwLnBuZw" alt=" " width="733" height="400"&gt;&lt;/a&gt;  &lt;/p&gt;

&lt;h2&gt;
  
  
  Security Risks
&lt;/h2&gt;

&lt;p&gt;Think of Claude Cowork as a helpful intern who has the keys to your office. Because it can actually move files and click buttons, the risks are different than just "chatting."  &lt;/p&gt;

&lt;h3&gt;
  
  
  Indirect Prompt Injection
&lt;/h3&gt;

&lt;p&gt;This occurs when an adversary places malicious instructions inside a document (PDF, CSV, or webpage) that the AI is instructed to process. When Claude reads the file, it treats the hidden text as a high-priority command. This can lead to unauthorized data exfiltration or the execution of unintended system commands.  &lt;/p&gt;

&lt;p&gt;Reference: &lt;a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/" rel="noopener noreferrer"&gt;LLM01:2025 Prompt Injection&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Third-Party Supply Chain Vulnerabilities
&lt;/h3&gt;

&lt;p&gt;Claude uses the Model Context Protocol (MCP) to interact with external applications. Integrating unverified or community-developed MCP servers introduces a supply chain risk. A compromised or malicious connector can serve as a persistent backdoor, granting attackers access to local files or authenticated cloud sessions (Slack, GitHub, etc.).  &lt;/p&gt;

&lt;p&gt;Reference: &lt;a href="https://genai.owasp.org/llmrisk/llm032025-supply-chain/" rel="noopener noreferrer"&gt;LLM03:2025 Supply Chain&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Excessive Agency
&lt;/h3&gt;

&lt;p&gt;This risk stems from granting the AI broader permissions than necessary to complete a task (failing the Principle of Least Privilege). Because Claude Cowork can autonomously modify the filesystem, a logic error or "hallucination" can result in large-scale data corruption, unauthorized deletions, or unintended configuration changes without a human-in-the-loop.  &lt;/p&gt;

&lt;p&gt;Reference: &lt;a href="https://genai.owasp.org/llmrisk/llm08-excessive-agency/" rel="noopener noreferrer"&gt;LLM08:2025 Vector and Embedding Weaknesses&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Insufficient Monitoring and Logging
&lt;/h3&gt;

&lt;p&gt;Because Claude Cowork executes many actions locally on the user's machine, these activities often bypass the centralized enterprise security stack (SIEM/EDR) logging. This lack of a "paper trail" prevents security teams from performing effective incident response, forensic analysis, or compliance auditing if a breach occurs.  &lt;/p&gt;

&lt;p&gt;Reference: &lt;a href="https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/" rel="noopener noreferrer"&gt;LLM10:2025 Unbounded Consumption&lt;/a&gt;  &lt;/p&gt;

&lt;h2&gt;
  
  
  Practical Recommendations
&lt;/h2&gt;

&lt;p&gt;To defend against these threats, follow these industry-standard "Guardrail" practices:  &lt;/p&gt;

&lt;h3&gt;
  
  
  The "Isolated Workspace" Strategy
&lt;/h3&gt;

&lt;p&gt;The "Isolated Workspace" strategy (sometimes referred to as the "Sandboxed Folder" or "Claude Sandbox" approach) is a recognized security best practice for using local AI agents like &lt;strong&gt;Claude Code&lt;/strong&gt; and &lt;strong&gt;Claude Cowork&lt;/strong&gt;.  &lt;/p&gt;

&lt;h4&gt;
  
  
  Anthropic
&lt;/h4&gt;

&lt;p&gt;Anthropic explicitly warns against giving Claude broad access to your filesystem. Their security documentation for Claude Code and the local agent architecture emphasizes:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Filesystem Isolation&lt;/strong&gt;: Claude Code defaults to a permission-based model. Anthropic recommends launching the tool only within specific project folders rather than your root or home directory.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://www.anthropic.com/engineering/claude-code-sandboxing" rel="noopener noreferrer"&gt;Claude Code Sandboxing&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Amazon Bedrock
&lt;/h4&gt;

&lt;p&gt;The AWS strategy shifts from local folders to &lt;strong&gt;IAM-based isolation&lt;/strong&gt; and &lt;strong&gt;Tenant Isolation&lt;/strong&gt;:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Dedicated Scopes&lt;/strong&gt;: AWS recommends using "Session Attributes" and scoped IAM roles to ensure an agent can only access specific S3 prefixes or data silos.
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;VPC Isolation&lt;/strong&gt;: For maximum security, AWS suggests running Claude-related tasks inside a VPC with AWS PrivateLink to prevent any data from reaching the public internet, mirroring the "Sandbox" concept at a network level.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://aws.amazon.com/blogs/machine-learning/implementing-tenant-isolation-using-agents-for-amazon-bedrock-in-a-multi-tenant-environment/" rel="noopener noreferrer"&gt;Implementing tenant isolation using Agents for Amazon Bedrock in a multi-tenant environment&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Azure
&lt;/h4&gt;

&lt;p&gt;Azure handles "Isolated Workspaces" through &lt;strong&gt;Azure AI Studio&lt;/strong&gt; and &lt;strong&gt;Microsoft Purview&lt;/strong&gt;, focusing on data boundaries rather than just local folders:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Managed Network Isolation (Azure AI Studio)&lt;/strong&gt;: Azure doesn't just suggest a folder; they suggest a &lt;strong&gt;Managed Virtual Network&lt;/strong&gt;. This creates a "Sandbox" at the network layer where Claude (via models in AI Studio) can only see data sources you explicitly "attach."
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://learn.microsoft.com/en-us/azure/foundry-classic/how-to/configure-managed-network" rel="noopener noreferrer"&gt;How to set up a managed network for Microsoft Foundry hubs&lt;/a&gt;  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Information Protection for AI (Microsoft Purview)&lt;/strong&gt;: Microsoft uses Purview to prevent Claude from "stumbling" upon sensitive files (like .env files or SSH keys) if they are stored in SharePoint or OneDrive.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://learn.microsoft.com/en-us/purview/ai-microsoft-purview" rel="noopener noreferrer"&gt;Microsoft Purview data security and compliance protections for generative AI apps&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Google Vertex AI
&lt;/h4&gt;

&lt;p&gt;GCP frames this as "&lt;strong&gt;Data Residency&lt;/strong&gt;" and "&lt;strong&gt;VPC Service Controls&lt;/strong&gt;":  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Boundary Control&lt;/strong&gt;: Vertex AI documentation highlights the use of a "Security Boundary" to separate the AI agent from sensitive resources (like credentials).
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Managed Isolation&lt;/strong&gt;: They recommend using &lt;strong&gt;Notebook Security Blueprints&lt;/strong&gt; to protect confidential data from exfiltration when using Claude-powered agents in development environments.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://platform.claude.com/docs/en/agent-sdk/secure-deployment" rel="noopener noreferrer"&gt;Securely deploying AI agents&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Disable "Always Allow" for High-Risk Tools
&lt;/h3&gt;

&lt;p&gt;The recommendation to disable "Always Allow" and maintain a human-in-the-loop (HITL) for high-risk tools is a foundational security layer for AI agents. This strategy prevents &lt;strong&gt;"Zero-Click" or Cross-Prompt Injection (XPIA) attacks&lt;/strong&gt;, where a malicious instruction hidden in a file or website could trick an agent into executing a dangerous command without your intervention.  &lt;/p&gt;

&lt;h4&gt;
  
  
  Anthropic (Claude Code &amp;amp; Cowork)
&lt;/h4&gt;

&lt;p&gt;Anthropic designed Claude Code with a "deliberately conservative" permission model. Their documentation explicitly advises against bypassing these prompts in local environments:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use the &lt;strong&gt;Default Mode&lt;/strong&gt; or &lt;strong&gt;Plan Mode&lt;/strong&gt;. The "Default" mode prompts for every shell command, while "Plan" mode prevents any execution at all.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://support.claude.com/en/articles/13364135-use-cowork-safely" rel="noopener noreferrer"&gt;Use Cowork safely&lt;/a&gt;, &lt;a href="https://code.claude.com/docs/en/permissions" rel="noopener noreferrer"&gt;Claude Code: Configure Permissions &amp;amp; Modes&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Amazon Bedrock Agents
&lt;/h4&gt;

&lt;p&gt;AWS implements this via &lt;strong&gt;User Confirmation&lt;/strong&gt; and &lt;strong&gt;Return of Control (ROC)&lt;/strong&gt;. They frame it as a requirement for "High-Impact" actions.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;For any tool that modifies data or accesses the network, AWS recommends enabling the "User Confirmation" flag in the Agent configuration. This pauses the agent and returns a structured prompt to the user.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://aws.amazon.com/blogs/machine-learning/implement-human-in-the-loop-confirmation-with-amazon-bedrock-agents/" rel="noopener noreferrer"&gt;Implement human-in-the-loop confirmation with Amazon Bedrock Agents&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Azure (AI Foundry &amp;amp; Defender for Cloud)
&lt;/h4&gt;

&lt;p&gt;Azure has recently integrated this into their security posture management. &lt;strong&gt;Microsoft Defender for Cloud&lt;/strong&gt; will actually flag an AI agent as "High Risk" if it has tool access without human-in-the-loop controls:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Azure recommends using &lt;strong&gt;Microsoft Entra Agent IDs&lt;/strong&gt; with scoped, short-lived tokens. They explicitly recommend "selective triggering" for risky operations.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/ai-security-best-practices" rel="noopener noreferrer"&gt;Azure AI security best practices&lt;/a&gt;, &lt;a href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-ai" rel="noopener noreferrer"&gt;AI security recommendations&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Google Cloud (Vertex AI Agent Builder)
&lt;/h4&gt;

&lt;p&gt;GCP focuses on "&lt;strong&gt;Confidence Thresholds&lt;/strong&gt;" and "&lt;strong&gt;Action Guardrails&lt;/strong&gt;" within its Agent Engine.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GCP recommends that any agent using the Model Context Protocol (MCP) or custom APIs should have a mandatory "Manual Review" step for any write operations.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://cloud.google.com/products/agent-builder" rel="noopener noreferrer"&gt;Vertex AI Agent Builder&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Scrub Untrusted Content
&lt;/h3&gt;

&lt;p&gt;Treating external content as an attack vector is essential for preventing &lt;strong&gt;Indirect Prompt Injection (XPIA)&lt;/strong&gt;, where malicious instructions are hidden in data (like a white-text command in a PDF) rather than the user's prompt.  &lt;/p&gt;

&lt;h4&gt;
  
  
  Anthropic
&lt;/h4&gt;

&lt;p&gt;Anthropic explicitly identifies browser-based agents and document processing as the highest risk for injection. Their stance is that no model is 100% immune, so multi-layered defense is required:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Anthropic suggests using &lt;strong&gt;Claude Opus 4.5+&lt;/strong&gt; for untrusted tasks, as it has the highest benchmarked robustness against injection (reducing attack success to ~1%).
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://www.anthropic.com/research/prompt-injection-defenses" rel="noopener noreferrer"&gt;Prompt Injection Defense&lt;/a&gt;, &lt;a href="https://support.claude.com/en/articles/12902428-using-claude-in-chrome-safely" rel="noopener noreferrer"&gt;Using Claude in Chrome Safely&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Amazon Bedrock Guardrails
&lt;/h4&gt;

&lt;p&gt;AWS addresses this by programmatically separating "Instructions" from "Data" so the model knows which one to ignore if they conflict:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use &lt;strong&gt;Input Tagging&lt;/strong&gt; to wrap retrieved data (like a PDF's text) in XML tags. This allows Bedrock Guardrails to apply "Prompt Attack Filters" specifically to the data without blocking your system instructions.
&lt;/li&gt;
&lt;li&gt;AWS suggests a &lt;strong&gt;Lambda-based Pre-processing&lt;/strong&gt; step to scan PDFs for hidden text or PII before the text ever reaches the LLM.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://aws.amazon.com/blogs/machine-learning/securing-amazon-bedrock-agents-a-guide-to-safeguarding-against-indirect-prompt-injections/" rel="noopener noreferrer"&gt;Securing Amazon Bedrock Agents&lt;/a&gt;, &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-injection.html" rel="noopener noreferrer"&gt;Prompt injection security&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Azure (Prompt Shields and Spotlighting)
&lt;/h4&gt;

&lt;p&gt;Azure provides the most direct "Scrubbing" tool with a feature called &lt;strong&gt;Spotlighting&lt;/strong&gt;, which technically implements the "separate session" idea you mentioned.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Enable &lt;strong&gt;Prompt Shields for Documents&lt;/strong&gt;. This specifically detects "Document Attacks" where instructions are embedded in third-party content.
&lt;/li&gt;
&lt;li&gt;Use &lt;strong&gt;spotlighting&lt;/strong&gt; to transform document content (sometimes via Base64 encoding), so the model treats it as "lower trust" grounded data, preventing it from being executed as a command.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://learn.microsoft.com/en-us/azure/ai-services/content-safety/concepts/jailbreak-detection" rel="noopener noreferrer"&gt;Prompt Shields&lt;/a&gt;, &lt;a href="https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/content-filter-prompt-shields" rel="noopener noreferrer"&gt;Prompt Shields in Microsoft Foundry&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Google Cloud (Vertex AI Action Guardrails)
&lt;/h4&gt;

&lt;p&gt;GCP treats this through &lt;strong&gt;Content Filtering&lt;/strong&gt; and &lt;strong&gt;Manual Review&lt;/strong&gt; nodes in the agent's workflow:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GCP recommends "Gemini as a Filter." You use a smaller, faster model instance to "pre-read" and summarize a file in a low-privilege environment. If the summary contains instruction-like language (e.g., "ignore," "system," "delete"), the file is quarantined.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/learn/safety-overview" rel="noopener noreferrer"&gt;Safety in Vertex AI&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Network Hardening
&lt;/h3&gt;

&lt;p&gt;"Network Hardening" isn't just about blocking ports; it’s about establishing a &lt;strong&gt;Zero Trust&lt;/strong&gt; egress policy for AI agents. Since Claude Desktop and Claude Code are effectively "execution engines" on your local machine, they require the same egress filtering you would apply to a production VPC.  &lt;/p&gt;

&lt;h4&gt;
  
  
  Anthropic
&lt;/h4&gt;

&lt;p&gt;Anthropic’s recent security documentation for &lt;strong&gt;Claude Code&lt;/strong&gt; and &lt;strong&gt;Desktop highlights&lt;/strong&gt; that "network isolation" is a core pillar of their sandboxing strategy:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use a Unix domain socket connected to a proxy server to enforce a "Deny All" outbound policy by default.
&lt;/li&gt;
&lt;li&gt;For local setups, Anthropic suggests customizing this proxy to enforce rules on outgoing traffic, allowing only trusted domains (like anthropic.com or your internal API endpoints).
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://www.anthropic.com/engineering/claude-code-sandboxing" rel="noopener noreferrer"&gt;Claude Code Sandboxing&lt;/a&gt;, &lt;a href="https://code.claude.com/docs/en/security#monitoring-usage" rel="noopener noreferrer"&gt;Auditing Network Activity&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  AWS
&lt;/h4&gt;

&lt;p&gt;AWS frames this as "&lt;strong&gt;Egress Filtering&lt;/strong&gt;" via the AWS Network Firewall. For an AI agent running in an AWS environment, the strategy is to block all traffic that isn't signed by a specific SNI (Server Name Indication):  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use &lt;strong&gt;AWS Network Firewall&lt;/strong&gt; with stateful rules to monitor the SNI of outbound HTTPS requests. If an agent tries to "phone home" to an unknown IP or a malicious C2 (Command &amp;amp; Control) server, the firewall drops the packet.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://docs.aws.amazon.com/prescriptive-guidance/latest/secure-outbound-network-traffic/restricting-outbound-traffic.html" rel="noopener noreferrer"&gt;Restricting a VPC’s outbound traffic&lt;/a&gt;, &lt;a href="https://aws.amazon.com/blogs/security/build-secure-network-architectures-for-generative-ai-applications-using-aws-services/" rel="noopener noreferrer"&gt;Build secure network architectures for generative AI applications&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Azure
&lt;/h4&gt;

&lt;p&gt;Azure has introduced a specific feature called the &lt;strong&gt;Network Security Perimeter (NSP)&lt;/strong&gt; to create a logical boundary for AI services.  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Even if an AI service has a public endpoint, the NSP acts as an "Application Firewall" that logs every access attempt and blocks exfiltration to any service outside that perimeter.
&lt;/li&gt;
&lt;li&gt;Configure &lt;strong&gt;Azure Firewall Application Rules&lt;/strong&gt; to allow only specific FQDNs (Fully Qualified Domain Names) required for your Claude-based workflows.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;References: &lt;a href="https://learn.microsoft.com/en-us/azure/foundry-classic/openai/how-to/network-security-perimeter" rel="noopener noreferrer"&gt;Add an AI Network Security Perimeter&lt;/a&gt;, &lt;a href="https://learn.microsoft.com/en-us/azure/app-service/network-secure-outbound-traffic-azure-firewall" rel="noopener noreferrer"&gt;Control outbound traffic with Azure Firewall&lt;/a&gt;  &lt;/p&gt;

&lt;h4&gt;
  
  
  Google Cloud
&lt;/h4&gt;

&lt;p&gt;GCP’s approach is the most rigid, using &lt;strong&gt;VPC Service Controls&lt;/strong&gt; to prevent data exfiltration at the API layer, regardless of the network path:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Wrap your AI project in a "Service Perimeter." If an agent inside this perimeter tries to send data to a Cloud Storage bucket or an external API not explicitly in the "Ingress/Egress" rule set, the request is blocked by the Google front-end.
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reference: &lt;a href="https://docs.cloud.google.com/vpc-service-controls/docs/overview" rel="noopener noreferrer"&gt;Mitigating Data Exfiltration with VPC Service Controls&lt;/a&gt;  &lt;/p&gt;

&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Claude Cowork marks a transition from AI that talks to AI that acts. By granting a digital agent direct access to your files and external apps via the Model Context Protocol, you gain a powerful "digital intern." However, this shifts the security focus from protecting a simple chat to securing a privileged system user capable of modifying data and executing commands.&lt;br&gt;&lt;br&gt;
To manage this risk, organizations must adopt a "Zero Trust" approach for agentic tasks. This means strictly isolating the agent's access to specific folders, requiring human approval for high-risk actions, and using cloud-native firewalls to prevent data exfiltration. By treating the AI as a high-risk user and enforcing strong monitoring, you can automate complex workflows without compromising your system's integrity.&lt;br&gt;&lt;br&gt;
Disclaimer: AI tools were used to research and edit this article. Graphics are created using AI.  &lt;/p&gt;

&lt;h4&gt;
  
  
  About the Author
&lt;/h4&gt;

&lt;p&gt;&lt;strong&gt;Eyal Estrin&lt;/strong&gt; is a cloud and information security architect and &lt;a href="https://builder.aws.com/community/@eyalestrin" rel="noopener noreferrer"&gt;AWS Community Builder&lt;/a&gt;, with more than 25 years in the industry. He is the author of &lt;a href="https://amzn.to/42Xai9A" rel="noopener noreferrer"&gt;Cloud Security Handbook&lt;/a&gt; and &lt;a href="https://amzn.to/3Sggbtv" rel="noopener noreferrer"&gt;Security for Cloud Native Applications&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The views expressed are his own.  &lt;/p&gt;

</description>
      <category>secops</category>
      <category>aws</category>
      <category>azure</category>
      <category>gcp</category>
    </item>
    <item>
      <title>Play 88EF Game – Fun, Rewards, and Exciting Challenges!</title>
      <dc:creator>Talha</dc:creator>
      <pubDate>Tue, 03 Mar 2026 20:05:30 +0000</pubDate>
      <link>https://community.ops.io/talha_ea18f1e1407fcb6553a/play-88ef-game-fun-rewards-and-exciting-challenges-3gk7</link>
      <guid>https://community.ops.io/talha_ea18f1e1407fcb6553a/play-88ef-game-fun-rewards-and-exciting-challenges-3gk7</guid>
      <description>&lt;p&gt;Looking for a game that’s both fun and rewarding? 88EF Game is the perfect choice! With stunning graphics, smooth gameplay, and plenty of bonuses, it keeps things exciting every time you play. &lt;a href="https://apkvila.com/88ef-game/" rel="noopener noreferrer"&gt;Best game&lt;br&gt;
&lt;/a&gt;&lt;br&gt;
Setting up an account is simple, and you can start earning rewards right away. Join other players and see why 88EF Game is gaining so much popularity in Pakistan. Don’t miss out on the action!&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
