Vulnerability management / AI / agents
Manage the risk. Not just the queue.
Practical security thinking for systems that increasingly write, deploy, and operate themselves. Fewer buzzwords. Better evidence. Occasional memes.
Advisory desk
Known exploitation already skipped the prioritization meeting.
Metabase Metabase
An unauthenticated SQL-injection path can lead to Metabase administrator access, exposed database credentials, and data theft.
JetBrains TeamCity
CISA reports that unsafe deserialization in the TeamCity agent polling protocol can permit unauthenticated remote code execution.
IBM Langflow
CISA says default Langflow deployments may permit unauthenticated attackers to achieve full remote code execution.
Latest posts
For the work after the scanner finishes yelling.
A field guide to agentic vulnerability management (with an actual off switch)
A practical operating model for introducing agents without confusing automation, authority, and accountability.
Finding vulnerabilities is getting cheaper. The backlog has noticed.
AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.
The vulnerability ticket is an interface, not a filing cabinet
A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.
