Writing and blogging background

Articles

Technical articles, conference debriefs, and security research

The AI Industry's Prescott Moment
AI Infrastructure·June 30, 2026·8 min

The AI Industry's Prescott Moment

Intel killed its fastest chip in 2004 because clock speed had become the wrong metric. AI is approaching the same inflection. 96% of Hugging Face text-generation downloads go to models with 13B parameters or fewer. Compute efficiency, not raw capability, is the bottleneck for commercial AI.

Read
The ICS Exploit Pipeline Is Built for Destruction, Not Theft
OT Security·June 22, 2026·7 min

The ICS Exploit Pipeline Is Built for Destruction, Not Theft

ICS vulnerabilities are structurally biased toward enabling physical disruption over data theft at a 5:1 ratio. Risk quantification frameworks calibrated for data breach systematically underprice OT exposure because they were never designed to model physical-consequence scenarios.

Read
973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
AI Security·June 17, 2026·9 min

973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security

AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. 45% of AI-generated code ships vulnerable. The MCP ecosystem has 973 packages with 71% single-maintainer and 56% published in the last 30 days. 133 prompt injection CVEs in NVD, 78% rated CRITICAL or HIGH.

Read
The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
AI Governance·May 28, 2026·15 min

The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It

Verizon's 2026 DBIR found the median threat actor used AI across 15 MITRE ATT&CK techniques. AI phishing text doubled year over year. Meanwhile, 67% of employees access AI from non-corporate accounts. Shadow AI is the third most common insider DLP action. AI governance should be treated like access control, not a novel category.

Read
The Remediation Paradox
Vulnerability Management·May 21, 2026·15 min

The Remediation Paradox

Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower

Vulnerability exploitation overtook credential theft as the number one initial access vector. Median patch time increased to 43 days. The gap between attacker speed and defender remediation is widening on both sides simultaneously.

Read
The Extension Blind Spot
Supply Chain Security·May 20, 2026·13 min

The Extension Blind Spot

How One VS Code Plugin Gave Attackers GitHub's Source Code

A single VS Code extension on a single employee's device gave attackers access to 3,800 of GitHub's internal repositories. VS Code extensions have full, unrestricted access to everything on the developer's machine, and 97% of the marketplace is unverified.

Read