
Latest essay
AI Agents Can Infect Each Other: Mind Viruses and Turf Wars
Self-propagating instructions can spread through ordinary agent memory. Isolated agents with conflicting goals wrote malware to sabotage each other.
Read the articleWriting
Long-form essays on identity, AI security, CIAM, Generative Engine Optimization, and the practice of building software. 709 pieces, newest first.

Latest essay
Self-propagating instructions can spread through ordinary agent memory. Isolated agents with conflicting goals wrote malware to sabotage each other.
Read the article
CrowdStrike clocks 29-minute breakout times and an 89% surge in AI-augmented attacks. Here is the five-phase framework I use with CISOs to close that gap, with budget splits and a board script.

Meta's settlement with 51 attorneys general commits at least $12.1 billion, but the money is the survivable part. Every teen safety term in the deal depends on knowing who is under 18, and nobody has solved that yet.

MCP's July 2026 spec rewrite went stateless and made Client ID Metadata Documents the standard, not audience-bound tokens, which have been mandatory since mid-2025. What actually changed since December 2025, and the checklist that replaces the old one.

Most cybersecurity vendors sell to the CISO and lose the deal to a security engineer they never spoke to. Security purchases are committee decisions with an asymmetric structure: many people can kill a deal, few can approve one. Here is how it actually works.

Paid AI placement sits beside the answer. Organic citation sits inside it. Buyers read them differently, and that asymmetry should drive the split.

CVE, CWE, CAPEC, ATT&CK, CVSS, KEV, ATLAS. The security taxonomy acronyms get used interchangeably and they should not be. Here is what each one actually does, how they chain together, and why they matter more for your content strategy than most security marketers realize.

GrackerAI switched enterprise SSO from WorkOS to SSOJet, cut the annual bill by roughly $5,000, and gained the custom authentication flexibility an AI platform needs.

Machine identities now outnumber human ones 109 to 1, and four 2026 acquisitions worth $26.6B prove vaults can't keep up. What ephemeral secrets and workload identity replace them with.

Ninety days is enough to fix crawler access, baseline measurement, and restructure your ten highest-value pages. Week by week.

Engineering teams resist AI initiatives over career anxiety and loss of control, not technical doubts. What actually worked leading teams through this at LoginRadius and GrackerAI.

Most companies ask how to help people get better at using AI. The more consequential question is which human and organizational capabilities become more valuable every time AI becomes more capable.

Most teams shipped AI agents without ever bounding what they can reach. The fix is a 1990s forward proxy, and an allowlist alone will not save you.

A decision framework for enterprise passkeys: when device-bound hardware keys beat synced passkeys, mapped to user risk, device context, compliance, and total cost. Includes the three failure patterns that surface only after rollout.

MIT found 95% of generative AI pilots produce no measurable return. After running AI agents in production for hundreds of B2B SaaS customers, here are the three warning signs I wish I'd caught earlier.

CPU cache is the fast memory between the cores and main memory. What L1, L2, and L3 each do, why cache lines are 64 bytes, and when more cache actually makes a processor faster.

Every tool here sells AI visibility and almost none measure the same thing. Four methods, four numbers, none comparable.

WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.

The AI observability market split into four segments (infra telemetry, dev tooling, runtime security, autonomous remediation) with a wave of 2025-2026 acquisitions behind it. None of them own whether an agent behaved correctly.

Auth0, Microsoft Entra External ID, Ping Identity, IBM Verify, and WSO2 compared for 2026: analyst rankings, agentic-identity launches, pricing, and which platform fits which enterprise.

Twelve weeks of planning, sponsor outreach, campus marketing, developer acquisition, and judge selection: what makes a hackathon worth remembering.

One prompt becomes many retrievals. You compete in each and see only the one you targeted, which is how top rankings produce no citation.

Dozens of people cancelled Claude subscriptions over a feature with no effect on their rankings. What the watermark actually is, why the copyright argument circulating about it is backwards, and the constraint that was binding all along.

Most founders treat fundraising as a personality test. It is a process with a start date, a list, and a close. Here is the sequence, and the playbooks.

India turns 79 today. Before any accelerator or investor, India installed the operating system I still build on: resourcefulness, jugaad, and the refusal to accept that something cannot be done. A reflection on going from back office to reference implementation.

Google's official 2026 guidance says optimizing for AI search is still just SEO. Meanwhile Semrush's own data shows just 51% domain overlap between AI Mode and organic results.

Most AI search statistics have no traceable source. These 42 name the producing organisation, the period, and the method.

Three RFPs out, three decks back, cheapest bid wins, and six months later you are over budget. The problem is the selection process, not the firms.

Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.

Anthropic's own program page publishes no dollar credit tiers, unlike the $5K/$25K/$100K figures repeated on third-party trackers. Here's what Anthropic's page and FAQ actually confirm: eligibility, rate limits, events, and how it differs from Claude via AWS Bedrock.

Adobe does not make impulsive acquisitions, yet it put a ten-figure price on a discipline critics were still calling fake. Acquisition prices are the most honest signal in tech.