Posts tagged
#security
20posts
August 2026
July 2026
- 28JulMalaysia's Birdie-X: A Few Hundred Ringgit Per Shot — How a Homegrown Laser Killed the Cost EquationBirdie-X, the RMAF + STRIDE + Benua Defence anti-drone laser unveiled in June 2026, swaps a million-ringgit interceptor missile for a high-powered beam. Cost per engagement drops to a few hundred ringgit. Here is what the field notes say — and what they don't.6 min read
- 27JulMalaysia's Military AI Push: Sovereign Ambition, Cloud-Security Blind SpotsTactiDrone's offline AI is a quiet admission about cloud-dependent C2 risk. The same gaps that plague government cloud security — talent shortage, silos, corruption risk — also bottleneck Malaysia's military AI.9 min read
- 15JulShift-Left → Auto-Remediation → Agentic Remediation: The 2026 Vendor Landscape and a Palo Alto Cortex Cloud Deep DiveFrom Checkov blocking PRs in CI to AI agents executing one-click fixes across code, cloud, and SOC — a vendor-by-vendor map of how cloud security moved from finding issues to fixing them, and where Palo Alto's Cortex Cloud platform sits in the race.9 min read
- 13JulMalaysia's Military AI Infrastructure 2026 — Case Study and Threat ScenariosPSPN 2026-2030, PSEP Cyber Command, STRIDE drone framework, CL-STA-1062 attacks on ASEAN critical infrastructure, TNB AI grid, and NACSA's Cryptology Centre — a case study on how Malaysia is building and defending military AI infrastructure amid real 2026 threats.7 min read
- 12JulThe World Is Writing AI Law — What Engineers Actually Need to KnowEU AI Act enforcement began Feb 2025. Malaysia is finalising an AI Governance Bill. ASEAN has its own frameworks. Regulation is shaping how we build AI — whether we are paying attention or not. A guide for engineers.6 min read
- 11JulGuardrail Vendors vs Production Reality — What AWS, Azure and Google Don't Tell YouAWS Bedrock Guardrails, Azure AI Content Safety, Google Vertex AI Safety — all look solid in documentation. But in production, there are real gaps between vendor promises and actual protection. Data from Palo Alto Unit42, AML bypass research, and production latency benchmarks.7 min read
- 10JulGround TruthEssays and case studies on the global cloud security and AI guardrail engineering landscape — perspective, analysis, and real threat scenarios from a Malaysian and ASEAN context.1 min read
- 10JulIdentity Is the New Perimeter — Lessons from Snowflake, MGM and Scattered SpiderIn 2024, UNC5537 stole data from 165 Snowflake customers without exploiting a single vulnerability. In 2023, Scattered Spider paralysed MGM in a 10-minute phone call. This is not a technical attack story — it is the new era where identity is the only perimeter left.5 min read
- 08JulMalaysia & Defence AI: Left Behind or Being Careful?Singapore has deployed autonomous drones, DSTA runs AI detection systems — and Malaysia? We need to ask this question honestly: where do we stand, and where should we go?7 min read
- 07JulAI on the Battlefield: Project Maven, Drone Swarms & JADC2From thousand-unit drone swarms to AI targeting systems making decisions in milliseconds — AI has transformed warfare. This isn't science fiction. It's happening now.5 min read
- 07JulMilitary AI & DefenceField notes on AI in defence — from autonomous battlefield systems and drone swarms, to the hard question: where does Malaysia stand in this landscape?1 min read
- 06Julopen source AI agent OS — Goose and the 2026 agentic ecosystemGoose by Block (now under Linux Foundation), Alibaba's Anolis AgenticOS, and the open source agentic AI stack shaping how agents run, deploy, and get secured.6 min read
- 06JulAI Guardrail EngineeringField note series on AI Guardrail Engineering — covering the 2026 trend landscape, 6-layer production defense, bypass techniques, and the open source agent OS ecosystem. For Cloud Security and AI engineers.1 min read
- 06JulCloud Security Engineering 2026Field note series on Cloud Security Engineering — shifting skills, modern tooling, and how engineers navigate a landscape that has converged with AI and agentic systems.1 min read
- 05Julhow AI guardrails get hacked — bypass techniques every engineer needs to knowGuardrails aren't walls that can't be broken. These are 7 proven bypass techniques from 2026 — roleplay, crescendo, encoding, prompt overflow — and how to defend against each one.3 min read
- 04JulAI guardrails — 6 layers you must have in productionMost teams install one or two guardrails and call it 'secured'. This is the complete 6-layer reference for LLM production — with tools, frameworks, and the false positive costs vendors never tell you about.5 min read
- 03Julcloud, AI, agentic OS — 2026 trends for Gen ZCloud security has shifted to intent filtering. AI has become an agent. Agents have become an OS. Four trends Gen Z needs to understand now.12 min read
- 02Julcloud security baseline — the foundation that needs to be right from day oneCloud Security Baseline (CSB) is the minimum set of controls that must exist before the first workload deploys. Here's the practical breakdown — from CIS Benchmarks, drift detection, to automatically enforcing baseline.5 min read
- 01Julbecoming a cloud security engineer in 2026 — skills that have shiftedThe role of cloud security engineer has changed more in 2 years than in the 5 years before. Here's an honest breakdown: what's stayed the same, what's changed, and what new skills you need now.7 min read