Blog & Insights
2026-08-31 · AI Security
Agentic browsers removed the same-origin policy — on purpose, as a feature. Why the PleaseFix vulnerability class demonstrated at Black Hat USA 2026 isn't an AI problem but a web security problem, and what it means when the load-bearing wall of the browser security model is deleted by design.
2026-08-24 · AI Security
The 2026 OWASP Top 10 for LLM Applications didn't just reorder — it changed its own thesis. Stop trying to build a model that cannot be fooled; build the system so that when the model is fooled, nothing important breaks. Why this quietly invalidates half the AI security tooling being sold right now.
2026-08-19 · AI Security
You can't govern an AI system you can't inventory — the models, datasets, prompts, MCP servers, tools, and dependencies it's assembled from. How an AI Bill of Materials (AI-BOM) makes that whole supply chain visible in a standards-based CycloneDX/SPDX inventory, with risk folded in and mapped to NIST AI RMF and the EU AI Act.
2026-08-10 · AI Security
An AI agent assembled from individually reasonable permissions can still end up able to read every secret and reach the open internet in the same breath. Why excessive agency is a graph problem, not a checklist, and how to audit an agent — its tools, scopes, and toxic combinations — down to least privilege before it ships.
2026-08-03 · AI Security
A pickled model file isn't data — it's a program that executes the moment you load it. How pickle-based remote code execution actually works, why the 2025 bypass wave slips past naive scanners, and how a static analyzer can disassemble the opcode stream to catch it without ever deserializing the file.
2026-08-03 · AI Security
When an evaluation harness and the system under test quietly share assumptions, the benchmark can end up grading itself generously — and the numbers drift up for the wrong reasons. A debugging story about catching a benchmark inflating its own score, and what it taught me about honest measurement in ML systems.
2026-07-27 · AI Security
Airlock scans the parts. Warden scans the assembly. Manifest inventories it. How Bulwark's three-tool security suite inspects the uninspected AI supply chain — models, packages, and agentic pipelines — before they ever reach production.
2026-07-20 · AI Security
Your AI coding assistant installs packages, spins up MCP servers, and runs code it pulled from people you've never met — and almost none of it is ever inspected. Why the agentic supply chain is a genuine security problem, and what it takes to put a gate in front of it.
2026-07-14 · AI Security
Built for the Hack2skill PromptWars Virtual Challenge: what happens when you hand an autonomous AI agent real authority over a critical system — an 80,000-seat stadium's operations — and how to bound that authority so one bad decision can't cascade. A practical take on agent guardrails, least privilege, and keeping excessive agency in check.
2026-09-04 · Multi-Agent Systems
How a multi-agent AI system investigates suspicious emails in seconds — and, unlike traditional tools, tells you exactly why.
2026-04-02 · Security
A practical reminder about encoding vs. encryption, single-byte XOR, and why client-side "hiding" is never security — with full solutions to my own mini-CTF.
2025-08-11 · AI Research
A multi-agent system for automated research discovery and synthesis using LangGraph. Published on ReadyTensor.
2025-08-11 · Social Impact
A voice-first system to streamline access to government welfare schemes for farmers in rural India. Published on Annam.ai.