Apr 10, 2026
•
8 min read
On RSAC and BSidesSF, AI snake-oil salesmen, and the myth of the One True Secure Framework.
Mar 27, 2026
9 min read
On democratizing vulnerability management, executive positions, and non-linear career growth--all the way back from 2023.
Mar 20, 2026
On the Agentic Development Lifecycle
Mar 6, 2026
On the Risks of "AI-Native" Security Products and Rapid Software Development
Mar 2, 2026
LLM AppSec Disruption, Limitations of AI in Security, and AppSec Oversight
Feb 20, 2026
A cost/benefit analysis of vibe coding and the subsequent security burnout, and the potential democratizing of responsibility through AppSec scorecards.
Feb 13, 2026
Feb 6, 2026
7 min read
How AI tooling is transforming the security industry, development velocity, and what the malware campaign targeting ClawHub can teach us.
Jan 31, 2026
Privacy, AppSec Conferences, OWASP
Jan 9, 2026
We bring on Paul McCarty, the NPM hacker, to discuss software supply-chain security researcher, malware and npm hacking/attacks in the AI-powered era.
Dec 12, 2025
How GenAI is changing the game for career newcomers, and the exploitative nature of Generative AI Engine Optimization.
Nov 26, 2025
Lingering thoughts on the OWASP Top 10, and the impact of AI tools on AppSec consulting.