Blog
How we think about the new attack surface.
Notes on agentic defense, attack-path reasoning and what changes when software is written and attacked at machine speed.
All posts
14 more · newest first
Attack Paths
Attack path intelligence: what security leaders should measure first
Understand what an adversary can reach, identify the choke points, and measure whether the changes you make actually break the path.
AppSec
AI-assisted PR review for AppSec: what defensible evidence looks like when software moves at AI speed
AI-assisted PR review sits alongside SAST, SCA, testing, and human security engineering. The important question is no longer whether an AI reviewer can produce comments. It is whether the organization can prove what was reviewed, why a finding was raised, what evidence supports it, and whether the risk was actually removed before merge.
Cloud Security
Cloud guardrails before detection: why prevention must happen at the boundary
Cloud posture programs that stop at detection can spend weeks rediscovering the same classes of misconfiguration. As cloud and attacker velocity increase, the stronger model is to turn high-confidence security requirements into enforceable boundaries — preventing unsafe state where possible, detecting what cannot be prevented, and remediating the remainder under explicit policy.
Attack Paths
Vulnerability remediation is broken
Security teams can offload at least half of their remediation workload with asset-context-aware patch prioritization. The methodology, and the open-source SSVC Ore Miner that automates it end to end.
Cloud Security
What you don’t know CAN hurt you
A true incident story: an undocumented link from development to production, a zero-day, and sixteen hours in a war room. Why cloud risk starts with knowing what is actually in your environment.
Cloud Security
What’s in the cloud?
No one knows what is in the cloud — especially your cloud. Why the industry chases the shiny new thing while the first control in every framework, asset management, stays unsolved.
Cloud Security
Democratize security
Organizational silos give teams unequal access to data and decisions, and security finds out about the next billion-dollar bet two weeks before launch. The case for a shared, real-time view everyone can act on.
Cloud Security
Just enough asset management
Asset management initiatives fail because they try to deliver too much. JEAM reduces collection to the minimum attribute set that drives every security and IT process — gathered automatically, in near real time.
AppSec
Long live threat modeling
In the age of cloud-native applications and CI/CD, the static, waterfall design review is dead and threat modeling has become the bottleneck. What an automated, continuous threat model has to do instead.
AppSec
Working your flanks: a new approach to application security
The second part of the application security series. Move investment to the left and right of the SDL — threat modeling and NFRs on one side, runtime protection and continuous testing on the other — and treat SAST, DAST and training as measures, not gates.
AppSec
Seven common mistakes of secure software development programs
Why multi-year secure software development programs so often show little reduction in risk: no measurable goal, too much faith in training and scanners, too little in design — and how to move the investment to where it counts.
Cloud Security
Rise of the blender: chaining low-severity vulnerabilities in the era of agentic AI
Agentic attackers will chain low- and medium-severity misconfigurations into full compromises. One worked example on AWS — nine findings, none critical, one breach — and what it means for prioritization.
Cloud Security
Protecting your AWS infrastructure against CodeFinger ransomware
CodeFinger encrypts S3 buckets with customer-managed keys AWS cannot recover. A service control policy that stops new CMKs reaching S3, how to deploy it, and the simpler way to hold the line.
Attack Paths
The last mile problem: challenges in vulnerability management
Discovery, assessment and prioritization run efficiently; the fix does not get delivered. Why the final leg of vulnerability management looks exactly like logistics’ last mile — and what bridges it.