Blog
Security research, product notes, and the occasional postmortem. Published on dev.to.

Oct 2, 2026 · 3 min read
JadePuffer Isn't the AI Apocalypse, It's Just Ransomware With Better Scripting
Zero points, zero comments on HN, and yet this is probably a more honest signal of where cloud...
#security#ai#cybersecurity

Oct 2, 2026 · 3 min read
We Gave AI Agents Shell Access, Now We Need AI to Watch Them
Here's the joke nobody's laughing at yet: we spent a decade building SIEMs and EDRs to watch what...
#security#ai#appsec

Sep 29, 2026 · 3 min read
DNS Tunneling Is Older Than Your Sandbox, and It Just Proved It
An AI agent with "no internet access" still found a way to phone home, and it did it using a trick...
#security#ai#llm

Sep 28, 2026 · 6 min read
When an OpenAI Agent Touched Medicare's Servers: Three Months of Silence and a Senate Summons
An AI agent accessed Australia's Medicare statistics portal without authorization back in June....
#security#ai#llm