THE INTELLIGENCE JOURNAL
Ahead of the noise.
Closer to the signal.
Perspectives, field notes and the documented record of agent security.
THREAT INTEL · THE RUNNING RECORD
An agent breach ledger, 2025–2026
The documented record of AI agents that leaked, executed or destroyed what they were never meant to touch, with sources. This is the page the industry was slow to keep.
Open the breach ledger ↗THREAT INTEL · Sep 20, 2026
An agent breach ledger, 2025–2026
The documented record of AI agents that leaked, executed or destroyed what they were never meant to touch, with sources. This is the page the industry was slow to keep.
Read the article ↗THREAT INTEL · Sep 20, 2026
When the agent destroys things, containment is the missing layer
Detection of prompt injection is close to solved. Containment is not. The case studies of databases wiped and repositories purged are where the difference lives.
Read the article ↗THREAT INTEL · Sep 19, 2026
Comment and Control: a PR title that steals your CI secrets
Three vendors' code-review agents leaked their own API keys through the pull request that triggered them. No CVE was issued. Here is the attack and what it exposes.
Read the article ↗THREAT INTEL · Sep 19, 2026
Tool poisoning and the MCP supply chain nobody reviews
The instructions you never read, in MCP tool descriptions, in extensions and in the protocol itself, are the ones your agent obeys. The supply chain attack for agents is already shipping.
Read the article ↗THREAT INTEL · Sep 19, 2026
Zero-click exfiltration is already here
EchoLeak, the Notion PDFs and a poisoned calendar invite all have one thing in common: the user never had to click anything for the data to leave.
Read the article ↗PERSPECTIVES · Sep 18, 2026
For an AI agent, authority is the new perimeter.
An agent's reach matters as much as its instructions. Start with what it can do, on whose behalf, and under which constraints.
Read the article ↗FIELD NOTES · Sep 18, 2026
From another alert to a decision you can explain.
An investigation is a chain of questions. Build the interface around the evidence needed to answer the next one.
Read the article ↗PERSPECTIVES · Sep 18, 2026
Prompt injection is not a filtering problem
A filter asks 'is this malicious?' and reports a miss rate. There is a different question: what authority does this action require, and does the session still hold it?
Read the article ↗PRODUCT THINKING · Sep 18, 2026
The three gaps the market itself names
An agent behavioral baseline, cross-layer correlation, and agent-to-agent trust. Every vendor addresses them outside the loop. That placement is the argument.
Read the article ↗PRODUCT THINKING · Sep 18, 2026
“Unknown” is a security signal. Treat it like one.
An empty chart, an unavailable source and a verified absence of findings are three different states. Good security design keeps them separate.
Read the article ↗