
Researcher Aonan Guan hijacked Claude Code, Gemini CLI, and Copilot Agent via PR titles and hidden HTML comments. All three paid bug bounties. None filed a CVE. Here's what that means for your agents.
Logan Kelly

Rolling back agent code is easy. Rolling back agent behavior is something else. Here's why agent versioning is a governance requirement, not just an ops task.
Logan Kelly

An AI agent compromised 600+ firewalls across 55 countries in 5 weeks — without a human approving each command. Here's what enterprise teams building agents need to learn from it.
Logan Kelly

A 4-agent system ran for 11 days and burned $47,000 — with full observability running. Here's why cost alerts aren't enforcement, and what is.
Logan Kelly

The CIS published a major prompt injection threat report in April 2026. Documented attacks are up approximately 340% year-over-year. Two-thirds go undetected for 72+ hours. Here's what it means.
Logan Kelly

96% of enterprises run AI agents — only 12% have centralized control. Here's the technical reality behind the governance gap, and what closing it actually requires.
Logan Kelly

