Blog
Notes from the field.
Research, product updates, and lessons from building AI-native security tooling and running it against real environments.
August 2026 — Case Study
Anatomy of a Long-Dwell Business Email Compromise
A forensic case study in session-token replay and multi-month vendor fraud — how a stolen session persisted undetected for over three months.
Read more → April 2026 — WhitepaperFrom Build to Breach
Anatomy of the Claude Code source map leak and the Axios supply chain attack — root causes, blast radius, and prescriptive release-pipeline controls.
Read more →