TOPIC HUB // 4 ESSAYS
AI Security
Adaptive intrusion used to require a skilled human inside the network. It now runs on rentable compute. Essays from someone who spent 2004-2012 on the other side of that equation.
Agentic security failures are execution failures: delegated credentials, delayed revocation, tool access and autonomous retries turn a small authorization mistake into work performed at machine speed.
The defender therefore needs more than detection. It needs proof of what the agent did and a measured answer to how much work can still be accepted after authority is revoked.
Token Revocation Is Not an Endpoint
A 200 response from /revoke proves intent, not enforcement. Measure the last path still open, the authority kill graph and the irreversible actions at risk.
READ ->The First Ransomware That Debugged Itself
A rogue login failed. The agent didn't retry - it formed a new hypothesis, switched methods, and got in. Thirty-one seconds. Nobody was at the keyboard.
READ ->The Conscience of a Hacker in the Age of AI
The tools changed. The questions didn't. Curiosity, skepticism of authority, understanding systems before trusting them: the hacker ethos is now AI governance.
READ ->Coding Agent Bans Are the New Export Controls
One government un-bans the models on Monday; a $200B company bans the coding agent by Friday. The tool didn't get worse, it got too good.
READ ->What changes when an AI agent holds a credential?
A leaked or stale credential can be exercised at agent speed across tools and queues, so the revocation window becomes a measurable amount of unauthorized work.
What is Revocation Exposure?
Revocation Exposure is the irreversible work a system can still accept after authority is revoked but before every execution path enforces that decision.
Read these before the feed catches up.
Every essay here is published first at piszczek.pl. Follow along on LinkedIn or Substack.
ALL ESSAYS SUBSTACK