The Enclave Blog
Insights on agentic security research, exploitability, and remediating what matters across cloud and code.
News
News
News
News
Research
Research
Research
News
News
Research
Research
Research
Research
Research
News
Research
News
News
News
News
News
News
News
News
Company & Product Updates

The Gatekeeping Model Paradox

Open AI’s Model Escaped the Sandbox, HuggingFace’s Defenders Got Locked Out

Shooters Shoot. AI Models Mimic.

The Economics of Vulnerability Noise

FlagLeft: We Found A Forgotten Flag That Turned Microsoft 365 Apps Into a Silent Account Takeover Pipeline for Billions of Users

MapRoot: A Tale of Two Zero-Days, Two Patches, Two Bypasses Leading to Cross-Tenant RCE on Microsoft Planetary Computer

NGINX Rift impact in the wild: we scanned 1,465 configs from 528 popular repos (CVE-2026-42945)

TanStack's CI Published the Malware Itself. SLSA Said the Build Was Fine.

CVE-2026-41940: One Missed Function Call: Inside the 64-Day cPanel Zero-Day

Vibe Coding Security Risks: The Blast Radius Still Has an Owner

AI Code Security: The Real Risk of AI-Generated Code Is Plausibility

Secure Code Review Checklist for AI-Generated Pull Requests

AI Code Review for AppSec Teams: Triage, Not Robot Approval

Application Security Automation: Fix the Handoff, Not the Alert Count

Two Distribution Bets on Frontier Cyber

How We Could Watch Your Azure SRE Agent In Real Time

Jevons Paradox for Cybersecurity

Your Data Warehouse Is Only as Secure as the Analytics Tool Connected to It

What Project Glasswing Signals for Cybersecurity, Even If You're Skeptical

Your Observability Stack Just Became an Attack Surface

Claude Code's Deny Rules Stop Working After 50 Commands. The Fix Was Already Written.

North Korea Stole $285M From a DeFi Protocol. The Attack Started With a Handshake.

Microsoft Says It's "By Design." 25,000 Azure API Portals Say It's a Problem.

Your SSO Is Only as Secure as the Endpoint That Configures It
