Blog
What AI changes about cybersecurity. Recent news, explained through the decisions your team needs to make.
- 012 min
Prompt injection
Invisible text, visible risk: what ASCII smuggling means for AI security
Microsoft’s September research connects invisible Unicode text with phishing evasion. What engineering teams should check in email and AI workflows.
- 022 min
Application security
AI makes bot attacks cheaper. Measure what they cost your business.
Cloudflare’s Adaptive Intelligence announcement puts bot economics in focus. A practical way to evaluate abuse defenses without blocking real customers.
- 032 min
Agent security
An AI sandbox needs proof, not a reassuring name
Anthropic’s August security update shows why agent sandboxes need tested boundaries, independent monitoring and a reliable stop mechanism.
- 042 min
Software supply chain
A popular AI agent is still a software dependency
GitHub’s OpenClaw maintainer interview highlights the security work behind a fast-growing AI project. What teams should verify before adoption.
- 052 min
Vulnerability management
AI can find more vulnerabilities. Who is going to close them?
Anthropic’s disclosure dashboard shows the work between finding a vulnerability and getting it patched. How teams can build a useful triage process.
- 062 min
Vulnerability management
The patch is coming. What protects the service until then?
Microsoft’s August patching analysis highlights the gap before remediation. How to track temporary controls, patch ownership and verified recovery.
- 072 min
Agent security
An MCP connection is a permission decision
Cloudflare’s August MCP security update highlights the controls around agent tools. A practical review of identity, server permissions and audit records.
- 082 min
Defensive AI
More capable cyber AI still needs a scoped job
OpenAI’s August Daybreak expansion raises practical questions about authorized scope, security evaluation and evidence quality for defensive AI workflows.
- 092 min
AI data security
Your AI gateway is also a data system
Cloudflare’s AI Gateway update makes request visibility easier. What teams should decide about prompt retention, access and provider routing.
- 102 min
Agent governance
Give AI agents an identity you can review
Microsoft’s August Zero Trust update brings AI and DevSecOps into the same review. How to connect agent identity, code changes and deployment evidence.