06 / FIELD NOTES

Technology,
under load.

Opinionated notes from Reykjavík on security engineering, AI systems, privacy, and the unglamorous work that keeps all three honest. No trend reports. No fearmongering. Sources included.

01 / PRACTICAL02 / HUMAN03 / SOURCED
01
Security16 Jun 20266 min read

Your AI Gateway Is Holding All the Keys

The LiteLLM vulnerability chain is not just another proxy bug. AI gateways sit between users, models, provider keys, stored credentials, and prompt logs. Treat them like production security infrastructure.

02
AI & systems14 Jun 20264 min read

Your AI Report Needs a Receipt Drawer

KPMG pulled an AI usage report after apparent hallucinations. EFF keeps finding fake staff quoted by AI slop sites. The fix is boring: citations, owners, and a human who checks the receipts.

03
Privacy12 Jun 20265 min read

The AI Act Is Being Weakened Before It Starts

EDRi says the EU AI Omnibus would delay high-risk AI safeguards and reduce public transparency. That is not boring Brussels plumbing. It is where accountability disappears.

04
AI & systems11 Jun 20265 min read

AI Builders Are Production Servers Now

Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.

05
Security07 Jun 20266 min read

AI Bug Hunting Is Turning Vulnerability Triage Into a Firehose

Depthfirst says an AI security agent found 21 FFmpeg zero-days for about $1,000. Chrome just patched 429 bugs. The hard part is no longer only finding flaws. It is deciding what gets fixed first.

06
Security03 Jun 20265 min read

The Comfortable Patch Window Is Gone

Active exploitation and AI-assisted attack tooling have compressed patch timelines. Risk-based prioritisation now matters more than a comfortable monthly schedule.

07
AI & systems01 Jun 20266 min read

Your AI Agent's Memory Is Now an Attack Surface

OWASP Agent Memory Guard is a useful signal: the dangerous part of agent memory is not only what the model remembers. It is who gets to write into that memory, when, and how long the poison survives.

08
Privacy22 Apr 202611 min read

Why Client-Side Scanning Breaks the Promise of Private Messaging

Scanning messages on the device does not preserve end-to-end encryption in any meaningful sense. Europe’s chat-control debate shows why the distinction matters.

09
Security25 Mar 202610 min read

Session-Token Theft: Why MFA Is Not the Last Step

Attackers are bypassing your MFA by stealing session tokens — your browser's proof that you already logged in. Here's how it works and what actually stops it.

10
Security23 Mar 202610 min read

That QR Code Might Be a Trap

QR codes hide their destination until after you scan. That makes stickers, invoices, parking meters, and login prompts useful phishing surfaces.

11
Privacy06 Feb 20267 min read

Why Every Service Should Get a Different Email Address

A unique email alias for each service limits breach fallout, reveals who leaked an address, and lets you disable one identity without replacing them all.

12
Privacy25 Jan 20266 min read

VPNs: When You Actually Need One (And When You Don't)

Cutting through the marketing hype to explain what VPNs actually do and whether you need one.