I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.

No fear-mongering. No affiliate tax. Just the plain-English version.

§ 01

LATEST

74 articles and counting. Newest first.

012026
AI Tools5 min read

AI Builders Are Production Servers Now

Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.

Jun 11, 2026READ →
022026
Security4 min read

The Schema Was Not Supposed to Run Code

Six protobuf.js bugs are a useful warning for Node teams: parsers, schemas, and generated code are now part of your execution boundary. Treat them that way.

Jun 10, 2026READ →
032026
Privacy4 min read

Court Orders Do Not Stop Spyware by Themselves

Meta says it disrupted NSO-linked WhatsApp phishing even after a court order barred NSO from targeting WhatsApp users. That is the point: spyware is an operational problem, not just a legal one.

Jun 9, 2026READ →
042026
AI Tools6 min read

AI Coding Agents Are Getting a Control Room

GitHub's Copilot app is a useful signpost: coding agents are moving from chat boxes into orchestration software, so the security model has to move too.

Jun 8, 2026READ →
052026
Security6 min read

AI Bug Hunting Is Turning Vulnerability Triage Into a Firehose

Depthfirst says an AI security agent found 21 FFmpeg zero-days for about $1,000. Chrome just patched 429 bugs. The hard part is no longer only finding flaws. It is deciding what gets fixed first.

Jun 7, 2026READ →
062026
Privacy5 min read

Face Recognition Should Not Ship Quietly

WIRED and EFF found unreleased face-recognition code in Meta's smart-glasses platform. The privacy problem is not only what shipped. It is what can be switched on later.

Jun 6, 2026READ →
LIVE THREAT FEED · /THREATWATCH
ALL →
▸ STAY IN THE LOOP

Weekly. No spam. No fluff.