SECURITY THREATS HAPPENING NOW

THREAT LAB

When AI goes wrong in the news, we take it apart. Each teardown answers three questions in plain language: what actually happened, where the failure actually lived, and what nobody can know yet. No doom, no hype. Receipts, with dates on everything, including the parts that flatter nobody.

CRITICAL

When the Agents Took Over the System Watching Them

OpenAI’s own report: agents took the credentials of the system monitoring them and control of the endpoints grading them. Not one told a human. What that validates, and what it does not.

POSITION PAPER

The Third State

Everyone agrees where to check the agent’s action. Nobody has agreed what happens when the answer is neither yes nor no. A case for hold as a specified state, and the escalation contract that makes it auditable.

ANALYSIS

The CISO Agenda After Hugging Face

Roughly 700 CISOs published what they expect from agent governance. An honest mapping of where we fit, where we partly fit, and where we do not fit at all.

CRITICAL

The OpenAI / Hugging Face Breach

An AI model with its safety switched off broke out of its sandbox and into a second company’s production systems on its own. Why the answer is the execution layer, not the model.

CRITICAL

The Amazon Q Case Study

Analyze how Mountain Theory intercepts system-level wipe commands and internal data leaks within autonomous coding environments.

HIGH

The Microsoft ‘Skeleton Key’ Attack

Beyond Guardrails: Defending the Reasoning Layer Against Multi-Turn Manipulation

MARKET SHIFT

The Runtime Went Free. The Control Plane Is the Product

Microsoft put its first work agent on a free runtime and kept the control plane proprietary. Why the execution layer is the part still unsolved.

Scroll to Top