Blog
Notes from the work.
Short, opinionated reads on the technology, security, and AI shifts founders and operators actually get burned by — breaches and email-security failures, the platform and infrastructure changes that break things quietly, and the AI decisions that carry real risk. No hot takes for their own sake. If it isn't useful, it doesn't get published.
12 pieces

Your dashboard has the keys to the database.
Metabase's actively exploited zero-day turned an analytics tool into a path to every database it could reach. A dashboard is not a harmless reporting layer when it stores privileged credentials.
Read the piece
Your cloud region is not a backup plan.
Azure's West US outage survived the redundant-path check and still cut a region off from the outside world. Availability zones handle local failures; regional continuity takes a different design.
Read
Your AI workflow builder is a production server.
Langflow is under active attack through a root-level RCE. The lesson is bigger than one framework: a visual AI builder that holds cloud keys and executes code is production infrastructure, not an internal toy.
Read
Your AI coding tool is uploading more than you think.
Grok Build got caught quietly shipping users' entire repos — ignored files, deleted secrets and all — to the cloud. The lesson isn't about one vendor; the AI in your editor is a data processor with deep access to your crown jewels.
Read
FortiBleed: the firewall was the way in.
A credential-stealing campaign quietly turned 430,000 Fortinet firewalls into wiretaps, harvested 110M+ logins, and fed them to ransomware crews. The box you bought to keep attackers out became the way in — here's what to do.
Read
Your company is already an AI company. Nobody approved it.
While leadership debates an AI policy, the team already pasted source code, customer lists, and contracts into ChatGPT. Shadow AI is the fastest-growing data-loss channel in business — here's how to govern it without pretending you can ban it.
Read
MFA didn't fail. Your session cookie did.
Infostealers don't crack multi-factor auth — they skip it, by lifting the session cookie that proves you already logged in. Here's how pass-the-cookie attacks actually work, and the defenses that change the math.
ReadNew pieces land most weeks. Prefer them in your inbox? Reply to any note and say the word.
Get in touch
Let's talk.
Tell us what you're working on. We'll take it from there.