blog/
34 pages · Updated September 1, 2026
Pages
- SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain
- CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
- Why MCP Governance Isn’t Optional Anymore
- AI Usage Control (AI-UC): How to Prevent AI Misuse
- Persona-based Access Control Implementation in Just 6 Steps
- SaassyCode Post-Disclosure Wave: Five New Extensions, 32,000+ Total Installs
- How to Measure and Audit AI Data Governance
- Primer: AI Security Posture Management (AI-SPM)
- Attribute-Based Access Control (ABAC) Implementation Guide
- Solving the Very-Real Problem of AI Hallucination
- Enterprise GenAI Adoption Mandate: Lessons from America’s AI Action Plan
- AI Adoption in Government & the Department of Defense
- AI Coding Agent Governance Policies That Work
- How AI Assistants Leak Secrets in Your IDE
- New Malicious VS Code Extension Backdoor: Remote Text Fetcher
- Securing Multi-Agent AI Development Systems
- AI Safety vs. AI Security: Explaining the Differences
- How to Detect and Block Malicious IDE Extensions
- The Mechanics Behind MoltBook: Prompts, Skills & Timers
- Primer: AI Governance Roles and Responsibilities
- How Model Context Protocol (MCP) Servers Communicate
- Automating the MCP Servers Discovery with Claude Sonnet 4
- Enterprise AI Tools Know Too Much: The CISO’s Dillema
- How Mental Models are Transforming AI Chaos into Clarity
- The GitHub Breach and VS Code Extensions: Threat Intelligence and Agentic Defense
- DeepSeek’s cutoff date is July 2024: We extracted DeepSeek’s system prompt
- 6 Biggest Shadow AI Risks and How to Mitigate Them
- AI as an Enzyme to Transform Critical Infrastructure
- Primer: How to Spot and Analyze Malicious VS Code Extensions
- From .env to Leakage: Mishandling of Secrets by Coding Agents
- What to Expect When You're Expecting Your GenAI Baby
- OpenAnt: Read the LLM Vulnerability Paper
- Security Platform for AI Agents | Knostic Blog
- Update and Infect: How the SaassyCode Campaign Grew from Two Extensions to Nineteen