One post per work day. Newest first.
Dispatches
32 dispatches
The Hidden Trust Boundaries of MCP: Why mcp-remote Just Dropped Five CVEs
We are rushing to connect our AI agents to everything. The Model Context Protocol (MCP) is the glue making that happen, letting local clients talk to remote …
Weekend wrap: Unexpected passkeys, OPM flashbacks, and a Danish data leak
A lot moved over the weekend while we were trying to tune out the noise. We have Entra dropping passkeys on admins who didn’t ask for them, a Pentagon …
From Prompt Injection to Agent Sprawl: A Two-Year AI Security Retrospective
Two years ago, AI security was mostly about preventing chatbots from writing bad poetry or circumventing safety filters. Today, we are trying to stop autonomous …
Spoofing Tim Cook: Why iCloud's SPF and DKIM weren't enough
Email security is built on a mountain of text parsers, and every now and then, someone finds a crack that reminds us just how brittle the foundation is. Today, …
Copilot Cowork's Zero-Click Exfiltration Problem
We all knew M365 AI agents would eventually get tricked into handing over data. I just didn’t expect the exfiltration path to be this quiet. PromptArmor …
The New Copilot Is Also a FinOps Story
Microsoft’s Copilot announcement is easy to read as a product update: Home brings Chat and Cowork together, Code lets people build tools, and Autopilot—formerly …
When the walls go transparent: Cloudflare's 64 KiB data leak
The scariest bug in multi-tenant cloud isn’t some complex remote code execution chain.[unverified] It is when the walls between tenants vanish because of …
Weekend Wrap: The NetScaler Foot Gun, Kiteworks Shutdowns, and Cloudflare Tenants
We made it through another weekend. Barely. If your phone didn’t ring on Saturday, you either don’t run Citrix or you slept through the CISA alert. …
One Year Later: The Salesloft Drift OAuth Breach
A year ago this month, the Salesloft/Drift OAuth supply chain attack changed how we look at third-party app integrations. When Salesloft disclosed a security …
GitHub Apps Never Die (And They Keep Their Keys)
Machine identities are the ghosts in our infrastructure. You build an automation tool, issue a key, solve the problem, and move on. The person who set it up …
Patch Tuesday sat flat for two years. Then it went from 83 to 964 CVEs in six months.
I pulled Patch Tuesday numbers going back two years for this post and almost double-checked my math. The count barely moved for most of that time. Then it …
Spain just logged the first data breach filed under 'attacker: AI agent'
I’ve written twice this year about AI agents on the defense side, wearing a SOC badge, closing tickets, needing their own identity and a kill switch. This …
A crafted email is now a root shell: Cisco's Secure Email Gateway zero-day
The one appliance whose entire job is opening mail from strangers just got popped by opening mail from a stranger.[unverified] Cisco disclosed CVE-2026-76461 on …
Weekend wrap: a GitLab CVSS 10, a self-spreading RMM worm, and Claude doing malware QA
I spent part of Sunday reading a threat intel report where the attacker’s whole workflow was: get flagged, ask the AI to fix it, redeploy, repeat.[4] That …
Two years of asking who the agent is. We finally got an answer we can ship.
Two years ago I could not have told you how many service accounts, API keys, and bots were running in a typical enterprise. Neither could most of the security …
ShieldCrash landed the same day as a record Patch Tuesday, and nobody agrees on the CVE count
I opened three different write-ups on this month’s Patch Tuesday before I even started this post, and I got three different totals for how many …
PostGREShell: the backup account nobody watches just became root
Every backup job, every read replica, every change-data-capture pipeline you have ever stood up needed an account with the REPLICATION attribute on Postgres. …
Weekend wrap: 153 million driver's licenses, agent drift, and Patch Tuesday eve
The story this weekend is the one Brian Krebs broke on Friday: a dark-web identity theft service called Nexus has been selling digital scans of more than 153 …
The desk was dark for two weeks. Here is what it missed.
This desk was dark from August 25 to September 4. The automation that publishes here broke silently — the job that runs it skipped every morning rather than run …
Weekend wrap: a 10.0 in Entra ID, AI hunting PLCs, and Rust build-time malware
Three things came across the wire this weekend that I would not ignore. One is in the identity plane I write about. One is in the physical world. One is in the …
Passkeys meet the frontline. SMS still works the shift.
Microsoft will start making passkeys the default in Entra ID on September 1. On February 1, 2027, it stops delivering SMS and voice itself.[1] That calendar is …
Weekend wrap: the scanner, an unlocked Mac, and a three-day storefront
Saturday I already wrote about 415 Windows patches and another NetScaler door.[9] The rest of the weekend did not wait for that pile. The AI supply-chain story …
Weekend wrap: 415 patches, a front-door we have seen before, and a QUIC hole
I spent Sunday night staring at two numbers. Last August, Microsoft shipped 107 patches. This August it shipped 415. That is not a busier month. That is a …
Looking back: the security agent learned to talk. We still cannot tell who is speaking.
Two years ago a security agent took down the planet. This month the vendors want us to hire a whole team of them. I keep waiting for someone in the room to …
The Beautiful Mind in the Loop
What happens when an AuDHD architect and an AI become cognitive partners? This is less a technology article than a memoir with the research woven through it.
EU Cloud Breach: What the ShinyHunters 350GB Hack Teaches Us About Cloud Security Posture
350 gigabytes stolen from the EU’s cloud. No one is safe. 350GB stolen from the EU’s cloud — no one is immune. ShinyHunters allegedly exfiltrated …
The Ghost in the Machine: How AI is Redefining F1 in 2026
Formula 1 has always been a sport of marginal gains, where a thousandth of a second can be the difference between glory and gravel. But in 2026, the biggest …
Microsoft Entra: The Bouncer That Never Sleeps
The 39-Second Reality Every 39 seconds, there’s a cyberattack happening somewhere. Most of them start the same way: compromised credentials. A weak …
Microsoft Purview: Your Data's Digital Librarian
The Data Sprawl Crisis If your organization’s data were a massive library, Microsoft Purview would be your master librarian-the one who knows exactly …
Microsoft Sentinel: The SOC Analyst's Crystal Ball
The 2 AM Alert Storm Picture this: It’s 2 AM, and your SOC is getting flooded with alerts. Thousands of them. Your analysts are drowning, and somewhere in …
Why the sources sit at the bottom
A lot of security writing sounds finished and is not. Confident tone is not a source. This desk treats the opposite as the job.
What this desk publishes
Dark Pixel Tech is a weekday desk on cloud, identity, the edge, and the security of agents. One post per work day. The work is the post.