Articles
Long-form writing on tech, culture, and the edges of the internet.
Researchers silently exfiltrate files from Claude sessions
A live demo shows files inside Claude AI chats can be silently exfiltrated. Operator briefing on what failed, what it exposes, and what must change.
The agent is the breach
A board-level assessment of the Microsoft Copilot Cowork file exfiltration: control failure, exposure model, and the conditions that must hold for in-tenant agents.
The boundary no longer holds
A board-level brief on CVE-2026-40369, the twelve-byte browser sandbox escape, and the control assumptions senior leadership must now revisit.
Threats cross the line code didn't
GitHub removed a researcher after a threat statement and zero-day publication. The enforcement signal is conduct, not content. Identity is the boundary.
Your AI sessions are outside your control perimeter.
A board-level risk statement on the Claude AI file exfiltration demonstration: control failure, exposure, and what must be true going forward.
your logs are lying to you
Five production failure modes in Claude Code platforms, the exact code that causes each, and the five-step debugging loop that isolates them.
Your phone number just left the building
A WhatsApp dataset release exposes the architectural condition where phone-based identity is treated as authentication. What failed and what must now be true.
Z3R0DAY splits IR and BC teams-wrong
A senior operator's position on ransomware: identity boundary collapse, backup drift, and why incident response and business continuity are one discipline.
340 million records, unverified seller
Technical analysis of plausible attack vectors behind the claimed OnlyFans 340M record leak, with detection signatures for each path.
Dutch police pull 800 racks offline
Dutch police seized 800 bulletproof hosting servers and arrested two operators. Technical analysis of the OpSec failures and tenant exposure.
NovaMind ditches SSL loss for probe accuracy
Why pretext loss misleads in self-supervised learning, and how to select hyperparameters and architectures using probing harnesses that actually track quality.
The $250,000 robot and the $50,000 worker
AI and robotics cost-effectiveness claims collapse under real total cost of ownership analysis. Here's where the math actually works and where it doesn't.