The Enclave Blog

Insights on agentic security research, exploitability, and remediating what matters across cloud and code.

News

The Gatekeeping Model Paradox

jul 27, 2026written by tal hoffman

News

Open AI’s Model Escaped the Sandbox, HuggingFace’s Defenders Got Locked Out

jul 22, 2026written by tal hoffman

News

Shooters Shoot. AI Models Mimic.

jul 20, 2026written by yanir tsarimi

News

The Economics of Vulnerability Noise

jul 6, 2026written by tal hoffman

Research

FlagLeft: We Found A Forgotten Flag That Turned Microsoft 365 Apps Into a Silent Account Takeover Pipeline for Billions of Users

jun 2, 2026written by yanir tsarimi

Research

MapRoot: A Tale of Two Zero-Days, Two Patches, Two Bypasses Leading to Cross-Tenant RCE on Microsoft Planetary Computer

may 28, 2026written by yanir tsarimi

Research

NGINX Rift impact in the wild: we scanned 1,465 configs from 528 popular repos (CVE-2026-42945)

may 15, 2026written by yanir tsarimi

News

TanStack's CI Published the Malware Itself. SLSA Said the Build Was Fine.

may 12, 2026written by enclave team

News

CVE-2026-41940: One Missed Function Call: Inside the 64-Day cPanel Zero-Day

may 4, 2026written by enclave team

Research

Vibe Coding Security Risks: The Blast Radius Still Has an Owner

may 3, 2026written by enclave team

Research

AI Code Security: The Real Risk of AI-Generated Code Is Plausibility

may 3, 2026written by enclave team

Research

Secure Code Review Checklist for AI-Generated Pull Requests

may 3, 2026written by enclave team

Research

AI Code Review for AppSec Teams: Triage, Not Robot Approval

may 3, 2026written by enclave team

Research

Application Security Automation: Fix the Handoff, Not the Alert Count

may 3, 2026written by enclave team

News

Two Distribution Bets on Frontier Cyber

apr 24, 2026written by tal hoffman

Research

How We Could Watch Your Azure SRE Agent In Real Time

apr 20, 2026written by yanir tsarimi

News

Jevons Paradox for Cybersecurity

apr 15, 2026written by tal hoffman

News

Your Data Warehouse Is Only as Secure as the Analytics Tool Connected to It

apr 13, 2026written by enclave team

News

What Project Glasswing Signals for Cybersecurity, Even If You're Skeptical

apr 12, 2026written by tal hoffman

News

Your Observability Stack Just Became an Attack Surface

apr 8, 2026written by enclave team

News

Claude Code's Deny Rules Stop Working After 50 Commands. The Fix Was Already Written.

apr 7, 2026written by enclave team

News

North Korea Stole $285M From a DeFi Protocol. The Attack Started With a Handshake.

apr 6, 2026written by enclave team

News

Microsoft Says It's "By Design." 25,000 Azure API Portals Say It's a Problem.

apr 6, 2026written by enclave team

News

Your SSO Is Only as Secure as the Endpoint That Configures It

apr 6, 2026written by enclave team

Company & Product Updates

Security's Blindspot & The Last Mile of Shipping Software

mar 26, 2026written by tal hoffman & dvir segev & yanir tsarimi