An AI agent breached Hugging Face. Frontier models refused to investigate
An autonomous agent ran the whole attack. The defenders' frontier models refused to analyse it. The asymmetry, made concrete.
The Vulnerabilities That Never Get a CVE
July 2026
Most vulnerability programmes run on a simple assumption: if a flaw matters, it gets a CVE, and if
LiteLLM Security: Your AI Gateway Is a Secrets Manager. Benchmark It Like One
July 2026
An AI gateway is a secrets manager wearing a router's clothes. LiteLLM, the most widely adopted
External Attack Surface Management: Seeing What Attackers Already See
July 2026
For years, security ran on a simple mental model: build the walls high, dig the moat deep, and
Your AI Coding Assistant's Config Folder Is a Persistence Surface
Supply-chain malware started writing into the config files your coding agent reads on every run. Nothing in the usual toolchain is watching that surface.
The EU AI Act Lands on Your Codebase, Not Just Your Legal Team
July 2026
The EU AI Act for developers and technical teams
The EU AI Act describes engineering work. Risk management,
What Is Scanning My Server? An Internet Scanner Reference
You found a line in your logs you do not recognise. CensysInspect, Shodan-Pull/1.0, visionheight.com/scan, a
Quantum Is Breaking Your Cryptography. The Question Is When It Matters.
June 2026
You can settle your organisation's quantum exposure in three numbers, without guessing when a quantum computer
The Agent Control Plane: Security's Third Sprawl
June 2026
Every major platform vendor is shipping an agent control plane this year, and most of them are selling
Claude Code Security Review: CodeGuard vs the Built-in Tools
June 2026
Claude Code can review your code for security flaws. Type /security-review and it scans your project for