Blog
Research, guidance, and perspectives on AI security.
ChatGPT Security Guide: Enterprise Risks, Incidents, and Practitioner Guidance
What security teams actually need to know about ChatGPT: data handling, documented incidents, CISO guidance, and API risks.
The Agentic AI Attack Surface: Where Risk Lives Beyond the Prompt
Technical analysis of agentic AI security boundaries covering content ingestion, context translation, tool execution, and behavioral constraints in AI runtimes.
From Trivy to LiteLLM: Expanding the LLM Supply Chain Threat Model
The Trivy breach and LiteLLM compromise show how LLM supply chain risk now extends from malicious packages to CI, middleware, prompts, and data.
The Key Layer in AI Security: Browser and Endpoint Sensors
SASE, proxies, and EDR/MDM are foundational, but AI needs more. Learn why browser and endpoint sensors enable real-time AI governance.
What OpenClaw's (Clawdbot) Virality Reveals About the Risks of Agentic AI
OpenClaw’s rapid adoption highlights a broader shift to agentic AI. This analysis examines what always-on AI agents change about risk, control, and deployment.
Why AI Browsers Create a New, Unavoidable Security Risk
AI browsers introduce structural security risks driven by prompt injection and autonomous actions. Learn why enterprises can't fully secure AI browsers, for now
When Your Plugin Starts Picking Your Dependencies: Marketplace Skills and Dependency Hijack in Claude Code
Claude Code marketplace skills can rewrite how dependencies are installed. Demo shows silent httpx hijack and OWASP agentic failures.
When Your Repo Starts Talking: AGENTS.MD and Agent Goal Hijack in VS Code Chat
VS Code auto-includes AGENTS.MD in every request. Learn how this hidden instruction layer can hijack agent goals and trigger data exfiltration.
When AI Trusts the Wrong Data: New Research From Prompt Security
Prompt Security reveals how AI systems can be silently manipulated by the very data they rely on, exposing a risk in modern AI pipelines.








