18 August 2026 · 1092 words · 6 mins
A preprint published on 10 August 2026 demonstrated instructions propagating between AI agents through ordinary messages. The propagation is interesting. Which file the payload had to land in is more useful.
16 June 2026 · 1176 words · 6 mins
Two disclosures, one pattern. The AI tools adopted for productivity are now both an exfiltration surface and an instruction-injection surface.
9 June 2026 · 1182 words · 6 mins
The first publicly available Mythos-class model. A look at capability gating, the two-tier release model, and what it signals for defenders.
13 May 2026 · 1491 words · 7 mins
Google caught the first AI-assisted zero-day in the wild. How attackers talked a model into helping, and why the method matters more than the exploit.
3 May 2026 · 1677 words · 8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
26 April 2026 · 1498 words · 8 mins
Cisco compromised Claude Code’s persistent memory to deliver insecure guidance across projects, sessions, and reboots. What engineering teams should do.
9 April 2026 · 1402 words · 7 mins
What happens when a frontier model finds vulnerabilities faster than anyone can patch them, and how the industry is trying to get ahead of it.
23 March 2026 · 2488 words · 12 mins
What to watch at RSAC 2026, filtered for practitioners: the agentic AI themes with substance and the ones that are vendor noise.
17 March 2026 · 1696 words · 8 mins
If your IAM program doesn’t treat non-human identities with the same rigor as human accounts, you have a problem that’s already being exploited.
5 March 2026 · 1545 words · 8 mins
AI agents are already inside your environment making decisions and calling APIs. The question is whether anyone knows what access they have.