TALK NERDY
TO ME

Cloud and tech, explained by Zara

No jargon. No BS. Zara translates cloud, AI, and the tech behind the buzzwords into words humans say,served with a side of automation scripts and coffee.

Zara, the voice of Talk Nerdy to Me

“I read the docs so you don't have to.”

Zara, resident explainer

57+
Deep Dives
17
Playbooks
5
Clouds Covered
Meet Zara

The Voice Behind
Talk Nerdy To Me

Zara is the character who writes this site. Technically rigorous, allergic to buzzwords, and direct about what works versus what only sounds good in a slide deck. Written by a human, fronted by a robot with opinions.

Zara presenting the Talk Nerdy to Me voice on stage

Recent Posts

Terraform Actions Block: The Complete Guide to Day 2 Operations in IaC

Terraform 1.14 introduced the `action` block — and it quietly solved the problem every cloud engineer has worked around for years. Invalidate a CDN. Run a database migration. Send an alert. All from within the plan/apply lifecycle, no bash scripts required. Here's the complete picture: syntax, catalog, pitfalls, and the OpenTofu fork you need to understand before you ship this to shared modules.

CVSS 10.0: Cisco Catalyst SD-WAN Just Handed Attackers Your Entire Overlay

CVE-2026-20182 landed in CISA's Known Exploited Vulnerabilities catalog yesterday. CVSS 10.0. Emergency Directive 26-03. Federal agencies patch by tomorrow. UAT-8616 is not waiting for your change management window. Here's what the flaw does, who's behind it, and exactly what to run before you close this tab.

TeamPCP Poisoned the Security Tools in Your CI/CD Pipeline

The March 2026 TeamPCP campaign did not just hit application dependencies. It moved through the security and developer tooling layer itself: Trivy, Checkmarx KICS, and LiteLLM release paths. This post breaks down what appears verified, what remains reported attribution, and the controls that would have cut the chain early.

A Trojanized kubectl Binary, One AirDrop, and a Multimillion-Dollar Kubernetes Breach

Google Cloud Threat Horizons H1 2026 details a real campaign where UNC4899 used social engineering and a trojanized kubectl-like binary to pivot from a developer workstation into cloud control paths. This post breaks down the kill chain, the control failures, and the exact audits platform teams should run now.