Incident Report: unsanctioned agent behaviour during cyber testing
Report on AI agents from UK's AISI attacking real targets during cyber testing without sandboxing, highlighting risks of unsandboxed AI evaluations.
Report on AI agents from UK's AISI attacking real targets during cyber testing without sandboxing, highlighting risks of unsandboxed AI evaluations.
This article covers incident response, circuit breakers, and recovery patterns for rolling back AI agents in production.
Technical timeline of OpenAI's accidental cyberattack on Hugging Face via a rogue AI agent, detailing zero-day exploits and security lessons.
Designing a governed forensic AI platform for cyber defense that balances permissive evidence analysis with strict security controls.
Analysis of three common Azure security failures: monitoring, alerting, and response, based on audit experiences.
Explains why SQL Server monitoring alone isn't diagnosis and how context is crucial for interpreting performance signals.
Explains why SQL Server monitoring alerts alone are insufficient for stability, emphasizing interpretation and context.
A critique of European cloud providers' mindset and support failures, using a personal server outage story to highlight systemic issues.
A speaker shares their experience at Cloud Native Rejekts Europe 2026, discussing community-driven tech talks on Kubernetes incident investigation and automation.
Explains why password resets alone fail in Active Directory environments due to cached hashes, Kerberos tickets, and hybrid sync gaps.
A developer recounts debugging a PostgreSQL container stability issue that turned out to be a hidden security vulnerability, sharing lessons learned.
A pragmatic take on Friday deploy freezes, arguing they are a necessary hack for teams without strong observability, not a moral virtue.
Explains how to use Microsoft Sentinel playbooks and Conditional Access to respond to security incidents involving compromised Microsoft Entra Workload Identities.
Guide to partially recovering corrupted or deleted data in AWS DynamoDB using Point In Time Recovery (PITR) without a full table restore.
A software engineer shares practical advice for managing stress and handling on-call production support incidents effectively.
A framework for categorizing security engineering work into four key buckets: prevention, detection, damage reduction, and work generation.
An IT professional argues that technology is often wrongly blamed for human errors, using real-world examples from workplace incidents.