Articles
Technical articles, conference debriefs, and security research

The AI Industry's Prescott Moment
Intel killed its fastest chip in 2004 because clock speed had become the wrong metric. AI is approaching the same inflection. 96% of Hugging Face text-generation downloads go to models with 13B parameters or fewer. Compute efficiency, not raw capability, is the bottleneck for commercial AI.
.png&w=3840&q=75&dpl=dpl_ALgEKHF5GEEvEFuRsr3zhRNGxpG4)
The ICS Exploit Pipeline Is Built for Destruction, Not Theft
ICS vulnerabilities are structurally biased toward enabling physical disruption over data theft at a 5:1 ratio. Risk quantification frameworks calibrated for data breach systematically underprice OT exposure because they were never designed to model physical-consequence scenarios.

973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. 45% of AI-generated code ships vulnerable. The MCP ecosystem has 973 packages with 71% single-maintainer and 56% published in the last 30 days. 133 prompt injection CVEs in NVD, 78% rated CRITICAL or HIGH.

The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
Verizon's 2026 DBIR found the median threat actor used AI across 15 MITRE ATT&CK techniques. AI phishing text doubled year over year. Meanwhile, 67% of employees access AI from non-corporate accounts. Shadow AI is the third most common insider DLP action. AI governance should be treated like access control, not a novel category.

The Remediation Paradox
Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
Vulnerability exploitation overtook credential theft as the number one initial access vector. Median patch time increased to 43 days. The gap between attacker speed and defender remediation is widening on both sides simultaneously.

The Extension Blind Spot
How One VS Code Plugin Gave Attackers GitHub's Source Code
A single VS Code extension on a single employee's device gave attackers access to 3,800 of GitHub's internal repositories. VS Code extensions have full, unrestricted access to everything on the developer's machine, and 97% of the marketplace is unverified.