Asyraf
Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.
Latest posts
CVE, CVSS, EPSS, KEV: The Vulnerability Alphabet, Finally Explained
8/20/2026
Four acronyms run the entire vulnerability world: one names the problem, one scores its severity, one predicts exploitation, one confirms it. Untangle them once and every security headline suddenly makes sense.
Your Org Is Hiring Workers You Can't See: An Identity Playbook for AI Agents
8/14/2026
AI agents now open pull requests, answer tickets, and touch production data. And most orgs can't list them, let alone govern them. Here's a practical playbook: inventory, identity, least privilege, observation, and a kill switch.
Secure by Default on Cloudflare Pages: Headers, WAF & Analytics Without a Server
8/9/2026
A static site has no backend to harden, but it still has a security posture. Here's the secure-by-default baseline I run on this blog: response headers, edge WAF, and privacy-friendly analytics.