Workstation Is Still the Breach: Zero Trust Tactics from Bybit to Bitwarden
February 2025: $1.5B stolen from one developer's laptop. April 2026: the worm came back, targeting ~/.claude.json and MCP configs by name. Same surface, same trust assumptions, new vector. We'll map the developer workstation through Kindervag's Zero Trust methodology, dissect how recent attacks (Bybit, Shai-Hulud, TeamPCP, Bitwarden CLI) actually executed, and walk through eight defender techniques on a four-level maturity ladder, starting with what you can do solo on Monday morning.
Eight defender techniques. Four maturity rungs. One protect surface. For security, AppSec, and DevSecOps engineers ready to govern the developer workstation as deliberately as they govern production.
The talk dissects how recent supply chain attacks executed against the workstation (Bybit, Shai-Hulud, TeamPCP, the April 22 Bitwarden CLI compromise that hunted ~/.claude.json by name), then walks the hardening ladder from Solo to Fleet. Techniques cover secrets, package pinning with cooldowns, extension allowlisting, binary auth, no-standing-admin, ephemeral environments, sandboxed builds, and AI agent runtime guardrails.
Which rung does your team actually sit on today?
Evan Borysko, of Greenbelt Advisors, is a fractional CISO and security adviser with 20 years of hands-on experience across enterprise IT, application development, and security programme leadership in energy, healthcare, and SaaS. He works with executive teams and boards to build security functions that open regulated markets, accelerate enterprise sales cycles, and sustain audit readiness across complex compliance environments.