Research
Posture teardowns and security essays.
Not every important security story is a vulnerability disclosure. This section is for the pieces that explain how categories, marketing claims, and trust narratives break down under technical scrutiny.
2026-04-20
Anatomy of the Context.ai → Vercel Compromise
A Chrome-Web-Store-shaped hole, a brand collision, and a missing DMARC record. Three pieces that haven't been put together publicly: which Context was actually breached, the attack template most consistent with the evidence, and the posture gap that made the prologue viable.
2026-04-17
Claude Mythos: Strong Model, Strategic Story
What Anthropic's own 245-page system card says about the model the press is calling "too dangerous to release" — and the footnote on page 14 that the coverage overlooked.
2026-03-31
The Registry That Chose Not to Enforce
We recovered the axios supply-chain dropper before it could erase itself and tore apart the stage-1 installer without running a single line. One of the first public static teardowns of the actual artifact — and a case study in the policy failure that mattered more than the malware.
2026-03-24
The SOC 2 That Was Supposed to Catch This
LiteLLM's supply-chain compromise appears to have succeeded through exactly the kind of CI/CD weaknesses a SOC 2 review is supposed to examine. Its compliance badge came from Delve, which had been accused just days earlier of mass-producing audit reports with near-identical boilerplate.
2026-03-22
We Read What Delve Ships to the Browser
A passive security posture analysis of the YC-backed compliance startup accused of fabricating 494 SOC 2 reports.