by Stephen Kuenzli | Sep 7, 2026 | Security
On August 25 our weekly triage deferred a Starlette alert with a 2% EPSS score. On September 1 the same alert, same code, same 2% score, was the only advisory in a 127-alert backlog that had to be fixed that day. Nothing about the vulnerability changed in that week....
by Stephen Kuenzli | May 9, 2026 | Security
“I’m sorry, Dave. I’m afraid I can’t do that.” NIST said it more politely on April 15. The NVD change is permanent, not a temporary glitch. CVE volume has outpaced NIST’s analysis capacity. For 25 years, vulnerability-management...
by Stephen Kuenzli | Apr 10, 2026 | Announcements
Cross-account event buses are one of the most powerful integration patterns in AWS, and an easy place to make an access policy mistake. A single overly permissive Allow statement can let principals from outside your organization publish events to your bus. With k9-cdk...
by Stephen Kuenzli | Apr 2, 2026 | AI, Security
We’re building an AI agent that triages cloud security findings. It reads a finding from AWS Security Hub or Prowler, assesses the risk, and tells an engineer exactly what to do about it with specific AWS CLI commands they can run. The agent worked. We had 620...
by Chase Christy | Aug 1, 2025 | The Effective IAM Newsletter
NCC Group’s AI Red Team recently published key findings after penetration testing dozens of AI applications. Analyzing Secure AI Architectures reveals that major AI vulnerabilities stem not from model flaws, but from misunderstanding how AI systems interact with...
Recent Comments