Zero Trust
+6
May 19, 2026
•
3 min read
Convention files, prompt injection, and why the line between productivity tool and data pipeline just disappeared
chrome-extensions
+7
May 12, 2026
You clicked "Add to Chrome" because it promised to make you faster. You actually installed a wiretap.
AppSec
May 5, 2026
A self-spreading worm just ran through the tools developers use to build every app you touch. Here's what that means for you — and what to do about it.
Oauth Security
Apr 28, 2026
The Vercel breach wasn't a credential failure. It was a token problem — and your IAM program probably can't see it.
Least Privilege
+4
Apr 21, 2026
Five vendors. Six weeks. The same architectural failure. Here's why agents keep shipping with godmode permissions — and what good actually looks like.
Apr 14, 2026
6 min read
The Agent Permission Paradox
identity-governance
+2
Apr 7, 2026
7 min read
Most enterprises are carrying identity debt they can't see. Here's what it looks like — and where to start paying it down.