Research

Posture teardowns and security essays.

Not every important security story is a vulnerability disclosure. This section is for the pieces that explain how categories, marketing claims, and trust narratives break down under technical scrutiny.

2026-04-20

Anatomy of the Context.ai → Vercel Compromise

A Chrome-Web-Store-shaped hole, a brand collision, and a missing DMARC record. Three pieces that haven't been put together publicly: which Context was actually breached, the attack template most consistent with the evidence, and the posture gap that made the prologue viable.

OAuthSupply ChainDMARCChrome ExtensionsPosture Teardown

2026-04-17

Claude Mythos: Strong Model, Strategic Story

What Anthropic's own 245-page system card says about the model the press is calling "too dangerous to release" — and the footnote on page 14 that the coverage overlooked.

Narrative AnalysisAI SafetySystem CardIPO Disclosure

2026-03-31

The Registry That Chose Not to Enforce

We recovered the axios supply-chain dropper before it could erase itself and tore apart the stage-1 installer without running a single line. One of the first public static teardowns of the actual artifact — and a case study in the policy failure that mattered more than the malware.

Supply ChainnpmStatic AnalysisPackage Registry Security

2026-03-24

The SOC 2 That Was Supposed to Catch This

LiteLLM's supply-chain compromise appears to have succeeded through exactly the kind of CI/CD weaknesses a SOC 2 review is supposed to examine. Its compliance badge came from Delve, which had been accused just days earlier of mass-producing audit reports with near-identical boilerplate.

Supply ChainComplianceCI/CD SecurityPosture Teardown

2026-03-22

We Read What Delve Ships to the Browser

A passive security posture analysis of the YC-backed compliance startup accused of fabricating 494 SOC 2 reports.

Posture TeardownCompliancePassive Recon