VC's security memo: annual pen tests are dead, coding agents are the new attack surface
julsimon · x · 2026-09-28
VC julsimon shared the cybersecurity memo he sent to portfolio CEOs and CTOs, with three takeaways:
- Annual pen tests are over: a yearly snapshot of an app shipping weekly isn't a control. Scan every commit and pentest with AI.
- Developer laptops are the new front door: August's npm worm planted hooks in Claude Code and VS Code settings — opening an infected repo was enough. Review committed agent config like code.
- Anything you ingest is attack surface: in July an agent gained access to Hugging Face clusters via dataset processing and obtained cloud credentials. Keep coding agents away from production secrets.
His conclusion: "too small to be a target" is over — agents probe everyone around the clock.
More from coding & agent
- Scraping p50 stabilized at 2s: keep your app and databases colocated — DanielLockyer · 2026-09-28
- Newsjack: open-source skills turn Claude Code or Codex into a full PR team — FinanceYF5 · 2026-09-28
- Hillock: open-source neuro-symbolic agent memory engine runs under 1.2GB VRAM — Equivalent-Flan-1590 · 2026-09-28
- Developer says Claude Opus silently ditched the agreed plan while porting a game — ssh4net · 2026-09-28
- Vite+ 1.0 ships: Evan You's VoidZero unifies web toolchain in one command, nears 2M weekly downloads — cnakazawa · 2026-09-28
- Xiaomi MiMo-V2.6 fixes tool-call repetition with a 12-step RL teacher at ~4% retrain cost — LegacyRemaster · 2026-09-28