Thought Leadership

You Can’t Crowdsource Your Way to a Live Adversary
Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…

AI Will Make Software More Secure. The Transition Won’t Be Pretty
I believe AI is going to make us much more secure. But probably not tomorrow. In fact, I think the next two years may be exactly the opposite: attackers will have the upper hand before defenders eventually turn the economics of cybersecurity in their favor. For decades, we have built software with vulnerabilities and then…

Why Buyers Remember Solving a Demo, Not Watching One
Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story
Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…

The Risk Isn’t What You Prompt, It’s What You Built
Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…

AI Proves the Real Bottleneck Was Never Finding Vulnerabilities
Let this sink in: finding security vulnerabilities was never the bottleneck, vulnerability prioritization was. AI-scale discovery is about to make that impossible to ignore, and the teams that see it coming will pull ahead of the rest. Here's what kept me up this week. Anthropic ran a frontier model against some of the world's most…

Security AI Needs an Honest Scoreboard: What It’s Superhuman At, and Where It Comes Up Short
If you follow AI at all, you know the leaderboards. Every few weeks a model takes the top spot, and we all check where our favorite landed. But a leaderboard only tells you who's ahead, and it stays quiet about where any of those models still come up short. Which, conveniently, is the part that…

The Pyramid of Agents Is Also a Pyramid of Identities
Key Takeaways When Anthropic published its piece on recursive self-improvement, the line that traveled was the efficiency one. A 100-person company doing the work of a much larger one, because each person sits atop a pyramid of agents. It's a striking image, and it's probably right. But there's a second diagram hiding inside the first…

Trust Is Full-Duplex
Key Takeaways A few weeks ago, Mira Murati's lab, Thinking Machines, put out a research preview of something they're calling interaction models. If you haven't seen it, it's worth your time. This is a serious effort from serious people, the kind of lab that trains a 276-billion-parameter model from scratch and stands up a whole…

Is your AI governance actually governing anything?
Key Takeaways Most organizations believe they have AI governance because they have policies, risk classifications, even responsible AI principles documented and approved. What they do not have, in most cases, is the ability to answer a basic question: what is every AI agent in our environment doing right now, and should it be doing that?…

Why Cloud Security UX Is Broken, and How We’re Fixing It
As a design team, we spend a lot of time watching where users slow down, where they hesitate, and where the product makes them work harder than it should. In cloud security, one pattern shows up again and again: A security engineer starts their day by opening the platform and scanning a long list of…

Who’s watching the code AI writes?
It’s probably no shocker that most of the code shipping into production this year wasn't written by a person. The real question isn't whether it's any good, but who's watching what it does once it's running, because no human ever held the context for it in the first place. Here's a startling number that may…