JD Tech Consulting

Blog

Notes from the work.

Short, opinionated reads on the technology, security, and AI shifts founders and operators actually get burned by — breaches and email-security failures, the platform and infrastructure changes that break things quietly, and the AI decisions that carry real risk. No hot takes for their own sake. If it isn't useful, it doesn't get published.

11 pieces

Two network paths to a geometric datacenter island severed by a single automated sweep.
Latest
Tech3 min read

Your cloud region is not a backup plan.

Azure's West US outage survived the redundant-path check and still cut a region off from the outside world. Availability zones handle local failures; regional continuity takes a different design.

Read the piece
A visual workflow graph pierced by an external path that descends into a dark server core containing credential-like capsules.
Security3 min read

Your AI workflow builder is a production server.

Langflow is under active attack through a root-level RCE. The lesson is bigger than one framework: a visual AI builder that holds cloud keys and executes code is production infrastructure, not an internal toy.

Read
A laptop emitting a stream of glowing code that flows along a thin conduit up into a distant cloud server.
AI3 min read

Your AI coding tool is uploading more than you think.

Grok Build got caught quietly shipping users' entire repos — ignored files, deleted secrets and all — to the cloud. The lesson isn't about one vendor; the AI in your editor is a data processor with deep access to your crown jewels.

Read
A luminous security wall protecting a network, quietly bleeding streams of data out through a hairline crack to the other side.
Security3 min read

FortiBleed: the firewall was the way in.

A credential-stealing campaign quietly turned 430,000 Fortinet firewalls into wiretaps, harvested 110M+ logins, and fed them to ransomware crews. The box you bought to keep attackers out became the way in — here's what to do.

Read
Luminous particles and data threads drifting out through a faint geometric boundary against a near-black background.
AI3 min read

Your company is already an AI company. Nobody approved it.

While leadership debates an AI policy, the team already pasted source code, customer lists, and contracts into ChatGPT. Shadow AI is the fastest-growing data-loss channel in business — here's how to govern it without pretending you can ban it.

Read
A glowing key looping past an open vault-lock ring, bypassing the barrier rather than passing through it.
Security4 min read

MFA didn't fail. Your session cookie did.

Infostealers don't crack multi-factor auth — they skip it, by lifting the session cookie that proves you already logged in. Here's how pass-the-cookie attacks actually work, and the defenses that change the math.

Read
A clean channel of luminous data being diverted off-course by a single intruding thread splicing into the flow.
AI3 min read

Prompt injection is not a bug you can patch.

Everyone shipping an AI agent is quietly betting they've solved prompt injection. They haven't — nobody has. It's an architectural flaw in how LLMs read instructions, and the only real defense is designing agents that can't be talked into doing damage.

Read

New pieces land most weeks. Prefer them in your inbox? Reply to any note and say the word.

Get in touch

Let's talk.

Tell us what you're working on. We'll take it from there.