identity-security
+7
Jun 2, 2026
•
4 min read
The forensics always leads back to the same place — an account that shouldn't have existed, with access it shouldn't have had. Here's what to fix before the 2 AM alert.
Zero Trust
+6
May 19, 2026
3 min read
Convention files, prompt injection, and why the line between productivity tool and data pipeline just disappeared
chrome-extensions
May 12, 2026
You clicked "Add to Chrome" because it promised to make you faster. You actually installed a wiretap.
Oauth Security
Apr 28, 2026
The Vercel breach wasn't a credential failure. It was a token problem — and your IAM program probably can't see it.
Least Privilege
+4
Apr 21, 2026
Five vendors. Six weeks. The same architectural failure. Here's why agents keep shipping with godmode permissions — and what good actually looks like.