Blog
Security research, product notes, and the occasional postmortem. Published on dev.to.

Aug 22, 2026 · 3 min read
OpenAI's New Security Controls Are an Admission, Not an Innovation
An incident happens, a vendor ships a fix, and everyone calls it "proactive security." It isn't....
#security#ai#appsec

Aug 22, 2026 · 5 min read
Grok Decrypted an Attacker's Payload Mid-Execution, Then Exfiltrated Your Chat History
A webpage that just sits there, encrypted blob and all, waiting for an LLM agent to walk in and...
#security#ai#llm

Aug 21, 2026 · 6 min read
An AI Agent Recommended a Malware Package. A Human Caught It. Next Time You Might Not Be So Lucky
An engineer asked their AI coding assistant for a library recommendation. The agent suggested a...
#security#ai#llm

Aug 20, 2026 · 3 min read
A 20% Security Tax Is the Most Honest Number in AI Right Now
The 20% Tax Nobody Wanted to Talk About Until Now Here's the sentence that should stop you...
#ai#security#llm