Posts
AI-SPM 101: How to Continuously Assess, Monitor, and Secure AI Systems in ProductionMost organizations can tell you, within a reasonable margin, how many servers they run, which ones are exposed to the …
Posts
Explore my latest blog posts.
If you enjoy the content, then consider buying me a coffee.
Posts
AI-SPM 101: How to Continuously Assess, Monitor, and Secure AI Systems in ProductionMost organizations can tell you, within a reasonable margin, how many servers they run, which ones are exposed to the …
Posts
OS Weekly: A New Defender Zero-Day, a Critical vCenter Flaw & Patching SmarterIt was a loud week for patching discipline. A brand-new Microsoft Defender zero-day landed days after Patch Tuesday, …
Posts
OS Weekly: Nation-State Breaches, Rogue AI Agents & a Supply Chain Trust CrisisThis was a heavy seven days for the field. A Russian state actor turned hotel Wi-Fi into an attack surface, a widely …
Posts
OS Weekly: AI Becomes the Adversary's Newest HireThis week made the AI-in-cybersecurity conversation a lot less theoretical. A Russian state-sponsored group turned hotel …
Posts
The keyv Worm Turned Credential Rotation Into a Trigger. Your Playbook Needs a New First Step.On August 4, 2026, a developer somewhere ran npm install. Before a single line of their own code executed, a worm had …
Posts
OS Weekly: Active Exploits, Patch Overload & AI's Double-Edged SwordIt was a patch-heavy week across the industry. Microsoft, 7-Zip, and WordPress core all shipped fixes for actively …
Posts
The Real Scandal in the Hugging Face Breach Isn't the Hacker — It's Who You Can't Call at 2AMHere’s the detail nobody’s leading with: a company got breached, needed its AI tools to analyze the …
Posts
Non-Human Identity (NHI) 101: What It Is and Why It's Suddenly EverywhereEvery time you log into a system, you authenticate with a credential — a username and password, a passkey, an SSO …
Posts
OS Weekly: Zero-Day Ransomware, a Record Patch Tuesday & Cybersecurity's Trust ProblemIt’s been a loud week. A ransomware crew chained two “moderate” SonicWall bugs into full root access, …
Posts
GPT-Red: What OpenAI's Automated Red-Teamer Means for AI SecurityOpenAI dropped research this week on GPT-Red — an automated red-teaming model built to break their own production models …