Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sichere ProgrammierungWhat is Programming And How i can Enjoy it?(24.09.2026 um 11:54 Uhr)
•
Sichere ProgrammierungYou Don't Need Adobe Commerce Cloud to Survive Black Friday(24.09.2026 um 11:55 Uhr)
••••
Malware / Trojaner / VirenBeyond Lazarus: Organization of DPRK cyber capabilities(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenBeyond Lazarus: Organization of DPRK Cyber Capabilities(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenThe fake worker threat and the rise of human infiltration(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenPolinRider Spreads Through Compromised GitHub Accounts and Packagist(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenWeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials(24.09.2026 um 11:59 Uhr)
•
Sichere ProgrammierungWhat is Programming And How i can Enjoy it?(24.09.2026 um 11:54 Uhr)
•
Sichere ProgrammierungYou Don't Need Adobe Commerce Cloud to Survive Black Friday(24.09.2026 um 11:55 Uhr)
••••
Malware / Trojaner / VirenBeyond Lazarus: Organization of DPRK cyber capabilities(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenBeyond Lazarus: Organization of DPRK Cyber Capabilities(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenThe fake worker threat and the rise of human infiltration(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenPolinRider Spreads Through Compromised GitHub Accounts and Packagist(24.09.2026 um 11:59 Uhr)
•
Malware / Trojaner / VirenWeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials(24.09.2026 um 11:59 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

From Years to Hours

It's not a brag for me to say "I've been visualizing infrastructure since 2018" - it's the actual truth. That was the year I joined a lovely Portland-based startup called Stackery, which took infrastructure as code (IaC for those familiar)…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

It's not a brag for me to say "I've been visualizing infrastructure since 2018" - it's the actual truth. That was the year I joined a lovely Portland-based startup called Stackery, which took infrastructure as code (IaC for those familiar) and generated an architecture diagram that looked like this:



A Stackery diagram



The secret sauce was that it went both ways: drag and drop resources, get IaC back that you can then deploy. Though the startup has not existed since 2021, you can actually still play with the live editor ;)



Why am I bringing up ancient history? Well, Stackery went on to be acquired by AWS (something I can say now that I'm no longer employed by them) and became AWS Infrastructure Composer (née Application Composer), which takes infrastructure as code and generates an architecture diagram that looks like this:



AWS Infrastructure Composer



And it also works both ways: drag and drop resources, get a Cloudformation template that you can then deploy. More importantly though, it's a powerful way to visually understand the distributed systems that make up serverless services and how they interact with each other.






Modern times



Today I'm at Stripe, which is not a cloud provider, so one would think there's no use case for visualizing IaC at my new job.



That was true until last month, when Stripe Projects was released and suddenly the Stripe CLI became a means to building anything!



With Projects, anyone can use the Stripe CLI to provision services from a quickly-expanding catalog of providers for hosting, auth, AI, databases, and so on - just about anything a hobby or real-world application may need. More commonly though, users are setting up their agents with the CLI and saying "build me an app that does X" and the agent can figure out that this use case requires a database and provision it straight from the CLI, as the gods intended.



So now we have an application composed of multiple services with increasing complexity that the developer may not fully understand - sound familiar for anyone around in the #believeinserverless days?






Visualizing Projects



I used Projects recently to build a transcription app for my team and wrote about the process here: From init to deploy. Even though that application is fairly simple and uses just two providers, Vercel and OpenRouter, I still thought a visualization would be useful for any of my teammates wanting to contribute to it, so I built a stripe-projects-visualizer app in a somewhat manic single afternoon.



This app looks at a project's .projects/state.json file, which is the source of truth for its provisioned services, analyzes how provider environment variables are used throughout the codebase, and comes up with an architecture diagram showing how your provisioned services connect and how data flows between them.



For example, here's the generated diagram for my transcription app:



A complete architecture diagram for the CLI






From years to hours



Is this tool cool and useful? Sure, I'd like to think so. Is it missing features? Of course, but not as many as one would think for the time spent on it. My biggest takeaway from building it in one afternoon is that I could.



Stackery took six engineers many, many years to build and maintain. Infrastructure Composer started with five engineers, then expanded to nearly a dozen plus a UX team, but even the initial preview version launched at re:Invent 2022 took over 9 months of intense building. Then, my former team spent another year re-architecting the canvas part of it to be more portable and extensible.



The Stripe Projects Visualizer took one person one afternoon to build. I could probably launch a web app version of it tomorrow. This is an entirely different paradigm than I was in eight years ago. It's entirely different from eight months ago, when I was still fumbling while trying to use Kiro and Claude Code to improve the underlying canvas tech of Infrastructure Composer.



I almost titled this post "The Terrifying Reality of Years to Hours" because in some aspects (the ones where I would very much like to stay employed), this is terrifying. Security aspects as well, for that matter, though my adversarial agent assures me there are no security gaps in my repo (whew!).



But this is also exciting, because projects that would have taken years or never gotten off the ground now have a chance to at least exist in a rough state that a team can polish and maintain.



So I guess I'm along for the terrifyingly awesome ride.



If you want to be as well, give Stripe Projects a try:




brew install stripe/stripe-cli/stripe && stripe plugin install projects






then visualize your terrifyingly awesome creation with:




npx stripe-projects-visualizer visualize






Let's see what you come up with!

SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - From Years to Hours
id: 8fbdc2dd-fb6c-487f-8f64-b242e8f4014d
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "From Years to Hours" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich From Years to Hours.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten From Years to Hours

Thematisch verwandte Begriffe: From, Years, Hours · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY Kritische Sicherheitsmeldung
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick