Blog
Practical writing on CISO decision-making, agentic AI architecture, penetration testing tools, and AI security — for security engineers and aspiring security leaders.
D2D Agentic Architecture
OpenVuln: Z.ai Turned an AI Model That Outgrew Its Own Safety Training Into a Public Vulnerability Scanner
Z.ai released OpenVuln, a free public tool that points its GLM-5.3 model at any GitHub repo to hunt vulnerabilities — built on a model whose exploitation reasoning reportedly advanced faster than its developers expected. Here is how it actually works, the numbers behind it, and what it means for anyone maintaining open-source code.
The LiteLLM Supply Chain Attack: What TeamPCP Stole, Who It Hit, and What to Do Now
Backdoored LiteLLM 1.82.7 and 1.82.8 stayed on PyPI for 40 minutes in March 2026 — long enough to compromise over 2,400 organizations. A 153GB archive of the stolen data has now surfaced. Here is exactly what happened, the IOCs, and the remediation checklist.
Enter, Evade, Escape: The Anatomy of AI Agent Hijacking Attacks
From RovoBlast to EchoLeak — a single click can now turn your enterprise AI assistant into a data exfiltration tool. Here is how the attacks work, a timeline of every known incident, and what security leaders should do about it.
How to Prepare for a CISO Promotion or Transition Into a C-Suite Security Role
A practical roadmap for security leaders preparing to step into the CISO seat — from closing executive skill gaps to practicing board-level decisions under pressure, with the tools and frameworks that actually build readiness.
Best Platforms for CISO Career Development and Executive Leadership Training in 2026
A practical comparison of the platforms security leaders are using in 2026 to develop executive skills, practise board communication, and prepare for the CISO role — from simulation-based training to certifications and peer networks.
Best Interactive Incident Response Simulators for Security Leaders Preparing for Executive Roles in 2026
A comparison of the interactive incident response simulators available in 2026 for security leaders preparing for CISO and executive roles — from AI-driven War Room scenarios to tabletop exercise platforms and cyber range tools.
Best Platforms for Practicing Board-Level Communication and Incident Reporting for Security Architects in 2026
Security architects eyeing executive roles need to master board-level communication and incident reporting. Here are the platforms and tools available in 2026 for practising these skills — from AI-driven report coaches to crisis communication simulators.
How to Practice Handling a Major Security Breach as a CISO Candidate Before Stepping Into the Role
CISO candidates need to practise breach response at the executive level — disclosure decisions, regulatory notifications, board communication, and crisis management — before they are responsible for doing it for real. Here is how to build that muscle.
Shai-Hulud Took keyv — and the Malware Shipped With Valid Provenance
A maintainer account compromise poisoned keyv, flat-cache, file-entry-cache and the rest of the family, then spread to 868 more packages across 1,381 versions — over 2 billion monthly installs. The releases were signed by GitHub Actions and the provenance checks out. That is the part worth your attention.
An AI Agent Found 19 Redis Zero-Days — in About 90 Minutes
Researchers say Kimi K3 agents chained a Redis streams double-free with a RedisBloom heap overflow into working authenticated RCE, with one exploit produced in 27 minutes. Redis shipped seven security releases in response. The claims are self-reported — but the patches are real.
Your Smart TV Might Be Renting Out Your Internet Connection
Researchers found residential proxy SDKs in 42% of LG webOS apps and over 25% of Samsung Tizen apps, quietly turning hundreds of millions of home TVs into proxy nodes rented out to unknown third parties. LG is suspending non-compliant apps; Samsung has said nothing yet.
Anthropic Launches Claude Security: AI Vulnerability Scanning Built Into Claude Code
Claude Security is a new beta plugin that scans code changes or entire repos for high-severity vulnerabilities directly in the terminal — reasoning through data flows like a security researcher instead of pattern-matching, with adversarial self-checks to cut false positives. Here's how it works and what it means for AppSec teams.
Real-Time Deepfakes Are Here: What Sub-40ms Face-Swaps Mean for Video-KYC and "the CEO on the Call"
Live video can now be edited faster than you can blink — faces swapped, backgrounds changed, all in real time on a webcam stream. Here is why that breaks video-based identity verification, supercharges executive impersonation fraud, and what security leaders should do about it.
The Suno Breach: An npm Worm, a Scraped Training Set, and a Notification That Never Came
A hacker used the self-propagating Shai-Hulud npm worm to breach AI music company Suno, leaking source code that details how its training corpus was scraped — plus customer emails, phone numbers, and Stripe data. Here is what actually happened and what security leaders should take from it.
Arsenal-NG: The Go-Powered Command Launcher Every Pentester Should Know
Arsenal-NG gives penetration testers instant fuzzy search across 2,800+ pentest commands in a terminal UI written in Go. Here's why it's worth adding to your toolkit — and what security leaders need to understand about the tools their red teams use.
AI Recon on AI Infrastructure: What Hackers Are Looking For (and How to Defend It)
As AI becomes operational infrastructure, attackers are developing reconnaissance techniques specifically targeting AI APIs, model endpoints, embedding stores, and training pipelines. Here's what the threat surface looks like.
Ready to practise the decisions these articles describe?
Run a free War Room →