Practitioner intelligence on identity, AI agents, and enterprise trust.
A hidden comment in a pull request is all it takes to hijack the AI gatekeeper your team trusts to ship safe code
Zero Trust
+6
One email is all it takes to plant a permanent lie in your AI assistant's memory — and there's no patch coming, because it isn't a bug.
identity-security
Symlink attacks, hallucinated packages, and prompt injection are turning your AI pair programmer into an attacker's easiest way in
NHI
ConsentFix and ClickFix attacks are turning OAuth consent prompts into skeleton keys — no password theft, no MFA bypass required. Here's how they work and what to revoke today.
Microsoft 365
Malicious code is now delivered as helpful app features — and 26,000 AI agents just installed one.
third-party integrations
+3
The attack that broke Microsoft's login doesn't need your password at all.
authentication