Blog
Malware breakdowns, threat intel, and offensive notes from the field.
AI Security2 min read
AI Agent Skills - the new target
At this point we've all heard about AI agents as well as subagents. More recently, however, are skills....
read →
CVE Analysis2 min read
Critical Splunk Enterprise Flaw — CVE-2026-20253 (CVSS 9.8)
Splunk patched a critical bug that lets an unauthenticated, network-reachable attacker pull off remote code execution...
read →
AI Security2 min read
Google AI Overviews Liability: German Court Rules "AI Can Make Mistakes" Isn't a Defense
GitHub nuked 73 Microsoft repos in 105 seconds. The Miasma worm's trick: opening the repo in your AI editor is what runs the payload — no install required.
read →
Threat Intel5 min read
Miasma Worm Explained: How a GitHub Supply Chain Attack Weaponizes Your AI Coding Tools
GitHub nuked 73 Microsoft repos in 105 seconds. The Miasma worm's trick: opening the repo in your AI editor is what runs the payload — no install required.
read →