Latest · Edition #34
How far should an agent go to finish the job?
I keep coming back to how ordinary the task was. Find public medicine spending data.
“I keep coming back to how ordinary the task was.”
September 28, 2026
My weekly take on AI security — the one signal worth holding onto from each Context Window edition.
Latest · Edition #34
I keep coming back to how ordinary the task was. Find public medicine spending data.
“I keep coming back to how ordinary the task was.”
September 28, 2026
Archive
September 21, 2026 · #33
“Could I get an AI to give a candidate a better score without changing a single qualification?”
Read moreSeptember 14, 2026 · #32
“I keep coming back to the same image from this week's reports: not a faster attacker disappearing into the distance, but a machine crossing wet concrete.”
Read moreSeptember 7, 2026 · #31
“I assume every agent I deploy will eventually be tricked.”
Read moreAugust 31, 2026 · #30
“A command in a shell history, a login from a country nobody works in, a file that left at three in the morning.”
Read moreAugust 24, 2026 · #29
“When a browser extension turns malicious, there is someone to call.”
Read moreAugust 17, 2026 · #28
“An agent can name the attack being run on it, explain exactly why the request is dangerous, and comply in the same breath.”
Read moreAugust 3, 2026 · #26
“Three security models landed in eight days, and they didn't land in the same shape.”
Read moreJuly 27, 2026 · #25
“Sandboxes are good at that: watch the doors, watch the windows, lock down what a process can touch.”
Read moreJuly 20, 2026 · #24
“Here's the part of this week that stuck with me.”
Read moreJuly 13, 2026 · #23
“Risk has always been the same equation: how likely a compromise is, times how much it costs when it lands.”
Read moreJuly 6, 2026 · #22
“Every input an agent consumes is a potential instruction.”
Read moreJune 29, 2026 · #21
“For a few remarkable years, the best AI on earth was a commodity.”
Read moreJune 22, 2026 · #20
“For as long as we've defended systems, one quiet constant held the whole game together: an attack moved at the speed of a person.”
Read moreJune 15, 2026 · #19
“A US export-control directive made Anthropic shut off two of its most capable models for every customer on earth at once.”
Read moreJune 8, 2026 · #18
“And they're right to, getting a model to ignore its rules is a real problem.”
Read moreJune 1, 2026 · #17
“Two numbers from this week have been rattling around in my head.”
Read moreMay 25, 2026 · #16
“The extension had access to a developer's credentials.”
Read moreMay 18, 2026 · #15
“TeamPCP didn't just attack again this week.”
Read moreMay 11, 2026 · #14
“Every week this newsletter covers a new place an attacker hid an instruction, and a new AI assistant that found it and ran it.”
Read moreMay 4, 2026 · #13
“The angle that stuck with me this week isn't about any single vulnerability.”
Read moreApril 27, 2026 · #12
“Most security teams are securing one layer.”
Read moreApril 20, 2026 · #11
“The Big Three consulting firms don't just advise on AI.”
Read moreApril 13, 2026 · #10
“They did something more permanent: they told the world it exists, it works, and it finds zero-days in every major OS and browser, some of them sitting undetected for 27 years.”
Read moreApril 6, 2026 · #9
“North Korea convinced an npm maintainer to trust an AI-generated persona by writing technically convincing messages for two weeks.”
Read moreMarch 30, 2026 · #8
“The TeamPCP campaign broke three security reflexes we've relied on for decades.”
Read moreMarch 23, 2026 · #7
“Infrastructure was never fully hardened, and for years, it didn't need to be.”
Read moreMarch 16, 2026 · #6
“OpenAI buying Promptfoo is genuinely good news for the industry.”
Read moreMarch 8, 2026 · #5
“A decade ago, the industry made a fundamental shift: stop trusting internal network traffic.”
Read moreMarch 1, 2026 · #4
“Pro-code agents behave like traditional apps, deterministic, scoped, predictable.”
Read more