Help CTOs and security teams understand the attack surface they’re creating when they deploy AI, and how to close it before it becomes an incident.
Apr 29, 2026
•
3 min read
New research confirms MCP servers trust every request by default. Here's what to do before it becomes someone else's exploit
Apr 21, 2026
A persistent context window is a persistent attack surface. Eight production incidents this quarter prove it.
Apr 14, 2026
6 min read
I built a 3-agent coding system this week. First control I added: repo isolation on the write-capable agent.
Apr 8, 2026
5 min read
But only 6% of the security budgets cover it
Mar 31, 2026
7 min read
The payload ran as a systemd service. The Trivy scan still returned green. Nobody noticed.
Mar 24, 2026
The .env file is not an identity system. The ecosystem just forgot. Plus a CVSS 9.8 with no patch.