Insights

Opinions and research from people who do this for a living.

Essays and research, open to read.

Subscribe to insights
The archive
2026
The Wrapper Trap: Silent Persistence in Gradle and MavenVulnerability ResearchAug 6, 2026 · 11 minThe exploit window went negative. Here's what that breaks.ThreatsAug 5, 2026 · 5 minEAP, AEV, CTEM: what the acronyms mean and where Incenter fitsStrategyAug 4, 2026 · 5 minThe Persistence Bridge: When npm Writes pnpm's FutureVulnerability ResearchJul 31, 2026 · 10 minOSec and Faction Networks Announce Partnership to Deliver Continuous Cyber Assurance for Owner-Controlled Zero Trust NetworksNewsJul 29, 2026 · 3 minThe Persistence Engine: Configuration Reinstatement in uvVulnerability ResearchJul 27, 2026 · 14 minPip Dreams and Security Schemes, Part II: The Interpreter in the MachineVulnerability ResearchJun 4, 2026 · 11 minRotten Apples Returns — macOS Codesigning Translocation RevisitedVulnerability ResearchMay 7, 2026 · 5 minWhat Claude Security gets right — and what it missesAIMay 5, 2026 · 3 minHollywood Has Always Run on Fragmentation. AI Is Making That Everyone's Problem.AIApr 14, 2026 · 4 minCIP-003-11 Is Here. Here's How to Comply Without Breaking Your OT EnvironmentComplianceApr 9, 2026 · 5 minTest Your People, Not Just Your FiltersOffensive SecurityApr 7, 2026 · 7 minNobody Gives a S##t About Cybersecurity: A Postcard from the Edge of the IndustryStrategyMar 23, 2026 · 11 minThe Validation Layer for AI: Why Verifying Vulnerabilities Matters as Much as Finding ThemAIMar 18, 2026 · 4 minThe Day Zero Trust DiedStrategyMar 9, 2026 · 8 minWrongfully Accused: AI and the Death of Cyber SecurityAIMar 4, 2026 · 7 minAI Agents Are Already Hacking You. Your Internal Controls Won't Save You.AIFeb 24, 2026 · 6 minThe $10M Distraction: Why 50,000 CVEs Don't Matter (But 3 Attack Paths Do)StrategyFeb 16, 2026 · 3 min