The five most-read posts on Path & Payload. A good place to start if you're new here.
Most Security Controls Were Built on Assumptions Agentic AI Violates
Agentic systems are breaking assumptions about identity, observability and recovery that traditional security controls were designed around.An AI Ingredients List Assumes You Know What the Ingredients Are
Where the software bill of materials model works for AI — and where training data, model provenance and runtime behavior make the analogy start to break.The Psychology Behind Vishing — and Why Most Defenses Miss It
Why voice attacks can succeed even against suspicious employees, and why the strongest defenses change the process rather than relying on better judgement.Attackers Have Negotiation Playbooks. Why Don’t Defenders?
Ransomware operators have scripts, intelligence and increasingly sophisticated negotiation support. Many of their victims enter the negotiation with with none of that.The Exploit With a Hallucinated CVSS Score: Breaking Down the First Confirmed AI-Developed Zero-Day
What the forensic artifacts in an AI-developed exploit reveal about where AI-assisted vulnerability research and weaponization have achieved.