This blog has been quiet since 2022. I now publish at notes.dawidbalut.com.
The subject has changed with the work: AI in offensive and defensive security, validating exposure instead of counting issues, and what compliance evidence actually proves. Most of it comes from systems I build and run.
Recent posts:
- Your AI Red Teamer Found 200 Vulnerabilities. Prove One.
- From Evidence Production to Assertion Validation
- Not a Cleaner Backlog. A Shorter Exposure Window.
- AI Security Agents Fail When You Build Six Products at Once
- From Vulnerability Triage to Exposure Validation
- In Legacy Codebases, AppSec AI Is Mostly a Context Problem
RSS: notes.dawidbalut.com/rss/
This site stays up as an archive of posts from 2016–2022.