Technology,
under load.
Opinionated notes from Reykjavík on security engineering, AI systems, privacy, and the unglamorous work that keeps all three honest. No trend reports. No fearmongering. Sources included.
Your AI Gateway Is Holding All the Keys
The LiteLLM vulnerability chain is not just another proxy bug. AI gateways sit between users, models, provider keys, stored credentials, and prompt logs. Treat them like production security infrastructure.
Your AI Report Needs a Receipt Drawer
KPMG pulled an AI usage report after apparent hallucinations. EFF keeps finding fake staff quoted by AI slop sites. The fix is boring: citations, owners, and a human who checks the receipts.
The AI Act Is Being Weakened Before It Starts
EDRi says the EU AI Omnibus would delay high-risk AI safeguards and reduce public transparency. That is not boring Brussels plumbing. It is where accountability disappears.
AI Builders Are Production Servers Now
Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.
AI Bug Hunting Is Turning Vulnerability Triage Into a Firehose
Depthfirst says an AI security agent found 21 FFmpeg zero-days for about $1,000. Chrome just patched 429 bugs. The hard part is no longer only finding flaws. It is deciding what gets fixed first.
The Comfortable Patch Window Is Gone
Active exploitation and AI-assisted attack tooling have compressed patch timelines. Risk-based prioritisation now matters more than a comfortable monthly schedule.
Your AI Agent's Memory Is Now an Attack Surface
OWASP Agent Memory Guard is a useful signal: the dangerous part of agent memory is not only what the model remembers. It is who gets to write into that memory, when, and how long the poison survives.
Why Client-Side Scanning Breaks the Promise of Private Messaging
Scanning messages on the device does not preserve end-to-end encryption in any meaningful sense. Europe’s chat-control debate shows why the distinction matters.
Session-Token Theft: Why MFA Is Not the Last Step
Attackers are bypassing your MFA by stealing session tokens — your browser's proof that you already logged in. Here's how it works and what actually stops it.
That QR Code Might Be a Trap
QR codes hide their destination until after you scan. That makes stickers, invoices, parking meters, and login prompts useful phishing surfaces.
Why Every Service Should Get a Different Email Address
A unique email alias for each service limits breach fallout, reveals who leaked an address, and lets you disable one identity without replacing them all.
VPNs: When You Actually Need One (And When You Don't)
Cutting through the marketing hype to explain what VPNs actually do and whether you need one.