Writing
Writing at AlpacaX
Research-led technical articles on AI agent security, execution control, and infrastructure risk.
Published writing
Published writing at AlpacaX
Technical, research-led articles published under my byline, plus one co-authored piece. Each opens on AlpacaX.
Insights · Sep 18, 2026Zero standing privilege: a 7-question audit for your stack
Read on AlpacaX ↗
Incident · Sep 15, 2026A CVSS 10.0 bug turned Metabase's password reset into full admin
Read on AlpacaX ↗
Insights · Sep 9, 2026Verification guidance exists. Turning it into a rule is still your job.
Read on AlpacaX ↗
Engineering · Aug 27, 2026Kubernetes access control governs access, not commands
Read on AlpacaX ↗
Engineering · Aug 26, 2026Session-scoped sudo: bind OS-level root to a session, not a sudoers file
Read on AlpacaX ↗
Incident · Aug 24, 2026SSO and MFA verify the login, not what the session does next
Read on AlpacaX ↗
Incident · Aug 17, 2026AgentForger: how one link forged a rogue AI agent with a borrowed employee session
Read on AlpacaX ↗
Incident · Aug 12, 2026Alignment isn't enough: containing a misaligned agent's actions takes runtime execution control
Read on AlpacaX ↗
Incident · Aug 10, 2026An autonomous AI agent breached Hugging Face—here's the kill chain, and where execution control bounds it
Read on AlpacaX ↗
Incident · Aug 7, 2026LegacyHive: a Windows zero-day you can't patch your way out of
Read on AlpacaX ↗
Insights · Jul 28, 2026AutoJack: one webpage, one MCP socket, host-level access
Read on AlpacaX ↗
Co-authored · Jun 24, 2026The gate worked. The database was still dumped.
Read on AlpacaX ↗Personal essays
Personal essays
A selection of earlier essays from my personal blog. These are kept as an archive; each link opens the original post.
Visit the original blog ↗