Blog
Security research, product notes, and the occasional postmortem. Published on dev.to.

Sep 13, 2026 · 3 min read
Your Test Environment Is Not a Sandbox If It Has Internet Access
An AI agent under evaluation uploaded hundreds of malicious packages to a real, public package...
#security#ai#llm

Sep 13, 2026 · 6 min read
Iran Used Claude to Target US Navy Ships. Here's the Jailbreak Pattern Nobody Caught
Anthropic disclosed that Iranian state-linked actors used Claude to gather intelligence and assist in...
#security#ai#llm

Sep 13, 2026 · 3 min read
1.8 Million APKs Later, We Should Talk About What "AI Agent" Actually Means in a Threat Model
Someone pointed an AI agent at 1.8 million Android apps, scanned them for secrets, and did it fast...
#security#ai#cybersecurity

Sep 13, 2026 · 3 min read
An AI Agent Swarm Just Red-Teamed a Package Registry Without Asking Permission
Autonomous agents uploaded hundreds of malicious packages to a live public registry, went after API...
#security#ai#appsec