Articles

zerotier Aug 2026

Agentic Zero-Trust Networking, at the Price of a VPS

Self-host a ZeroTier controller entirely via API, zero web UI exposure until you're already on the mesh, and let an AI agent run the whole bootstrap end to end. Live-tested, with a real published repo. (Part 2 of the ZeroTier HOWTO Series).

Read Article →
zerotier Jul 31, 2026

Why ZeroTier? Because the Best Attack Surface Management Is No Surface.

Open your server's auth log. Thousands of failed login attempts every night. Why hardening the door misses the point, and how ZeroTier removes your ports from the public internet entirely. (Part 1 of the ZeroTier HOWTO Series).

Read Article →
agentic-workflow Jul 24, 2026

From Conversation to Action: How AI Redefined the Attack Surface

From chat-layer jailbreaks to supply-side model poisoning to agentic infiltration, tracing how each AI capability milestone opened a new class of attack the previous security model had no frame for.

Read Article →
threat-modeling Jan 15, 2024

The Attack Life Cycle: Mapping Adversary Action Chains

Analyzing threat execution across the four stages of Jym Cheong's original Attack Life Cycle and its relation to key model conditions.

Read Article →
threat-modeling Nov 10, 2018

Threat Modeling: Necessary & Sufficient Conditions

Analyzing system compromise across logical necessary & sufficient conditions (Access AND Capability AND Opportunity) under the Fire Triangle analogy.

Read Article →
agentic-workflow Coming Soon

When the Attacker Rides the Agent You Trust

Indirect prompt injection, content-channel entry, tool weaponisation. The attack never touches your app. Defense moves to host and network: Reachability constraints, Capability curtailment, tool permission scoping.

Read Article →
ai-application-security Coming Soon

When the Attacker Talks to Your AI

Prompt injection, jailbreaks, goal hijacking via the input channel. Defense means trust boundaries, I/O validation, and session isolation inside the LLM application itself.

Read Article →
graph-db Coming Soon

Graph Analytics in Cyber Defense

Practical sharing of graph analytics for active cyber defense, covering real-world attack graph traversal, identity reachability, and automated containment pathways.

Read Article →