·1142 words·6 mins
A practitioner breakdown of the npm worm that sweeps environment variables on install and republishes itself through Trusted Publishing.
·1677 words·8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
·2488 words·12 mins
What to watch at RSAC 2026, filtered for practitioners: the agentic AI themes with substance and the ones that are vendor noise.
·1696 words·8 mins
If your IAM program doesn’t treat non-human identities with the same rigor as human accounts, you have a problem that’s already being exploited.
·1545 words·8 mins
AI agents are already inside your environment making decisions and calling APIs. The question is whether anyone knows what access they have.