A Beta Briefing desk
The Staff Safety Desk
Production-grade dispatches on Django, AI-assisted coding, and the failure modes nobody puts in the tutorial.
Resident skeptic of green success toasts and confident diffs
Subscribe to the audio
— a new briefing each weekdayHow to subscribe in your podcast app
- Apple Podcasts
- Library tab → โขโขโข menu → Follow a Show by URL → paste
- Overcast
- + button → Add URL → paste
- Pocket Casts
- Search bar → paste URL
- Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
- Look for Add by URL or paste into search
Spotify isn't supported yet — it only lists shows from its own directory. Let us know if you need it there.
Recent briefings below
Recent Briefings
The software supply chain has officially become the primary front for automated attacks. As the wave of GitHub Actions exploits we've tracked continues to escalate, we are covering two massive new cam…
Today on The Staff Safety Desk: a wave of new frameworks and post-mortems for reviewing and testing AI-generated code. The central theme is that AI agents consistently miss system-wide intent and non-…
Valid SLSA provenance attestations are providing false comfort in the software supply chain today, as a detailed post-mortem of the AsyncAPI compromise reveals attackers used a project's own trusted r…
Today on The Staff Safety Desk, the data on AI-generated code quality is solidifying into a clear warning. Building on recent reports of skyrocketing vulnerability rates, new metrics show that nearly …
Unpatched servers are facing an immediate risk of takeover today as a critical Django SQL injection flaw sees active exploitation in the wild. The desk is also tracking a foundational shift in corpora…
Today on The Staff Safety Desk, attackers are directly weaponizing the hallucinations of AI coding agents, registering the fake package names they invent to execute a new class of supply chain attacks…
Engineering teams are increasingly moving their focus to the verification layer of AI-assisted development, building elaborate multi-agent reviewers to catch the blind spots of their own coding assist…
The attack surface of AI assistants continues to widen today, with a new vulnerability in tools like Cursor that bypasses human-in-the-loop safeguards. We are also tracking a major npm release that di…
The next layer of tooling for AI-assisted development is taking shape today, as engineering teams shift focus from raw prompting to persistent context and hard rule enforcement. The desk is also analy…
The theoretical technical debt from AI-assisted coding is manifesting as a hard line item today, as dedicated consultancies begin charging upwards of $10,000 a week strictly to clean up auto-generated…