OWASP Top 10 for Agentic Applications
Security teams that spent two years hardening chatbots are now staring at a different problem. The OWASP Top 10 for Agentic Applications,…
FIELD NOTES · 2026 EDITION
721 posts on cloud, security, DevOps and AI.
Security teams that spent two years hardening chatbots are now staring at a different problem. The OWASP Top 10 for Agentic Applications,…
As a security professional who spends most working weeks inside Azure tenants watching automation scale past the point where any human reviews…
As a security architect working across Australian regulated environments, I have watched the 2023-2030 Australian Cyber Security Strategy move from foundation-setting to…
Most security programs were built to protect people. Single sign-on, multi-factor authentication, privileged access management, and quarterly access reviews all assume an…
After running cloud security posture programmes across a range of organisations, I get asked the wiz vs microsoft defender for cloud question almost every…
In June 2025, researchers at Aim Security disclosed EchoLeak, a zero-click vulnerability in Microsoft 365 Copilot tracked as CVE-2025-32711. A single crafted…
As a security professional who spends most days inside the third-party risk programmes of regulated Australian organisations, I read the Tata Electronics…
As an architect who has spent years helping organisations rebuild their Azure identity posture from the ground up, I keep running into…
The Mackay Sugar ransomware attack became public on 10 June 2026, just days after the company’s mills had started rolling for the…
Security framework mapping is one of those activities every security team eventually has to do, but few organisations start with a clear…