Help CTOs and security teams understand the attack surface they’re creating when they deploy AI, and how to close it before it becomes an incident.
Jun 12, 2026
•
4 min read
I've been quietly shipping. Six assets are live, they're all free, and most of you have never seen them.
Jun 9, 2026
5 min read
CVE-2026-48710 turns a malformed Host header into an auth bypass across the production AI stack. Here's how to check if you're exposed in five minutes.
Jun 4, 2026
SymJack and TrustFall broke every major AI coding agent this month: Claude Code, Cursor, Gemini, Copilot, Codex. The dialog you click through doesn't say what you're approving. Here's what to do.
May 31, 2026
6 min read
The progressive-autonomy model, the identity-first mandate, and why a regex blocklist turned an AI agent into a remote shell.
mcp
+2
May 20, 2026
7 min read
Claude Mythos found thousands of zero-days in 20 hours. Three new MCP research papers landed. And no existing defense covers the full attack surface.
May 9, 2026
1,467 exposed servers. 9 of 11 registries poisoned. Memory that spreads across users. The week in MCP security.