Asyraf
Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.
Latest posts
Paste Once, Lose Everything: What ClickLock Teaches About Trusting Your Own Terminal
7/21/2026
A new macOS stealer doesn't exploit a bug: it exploits a habit. ClickLock coerces victims into typing their own password by making the Mac unusable until they comply. Here's the anatomy, and why the scariest attacks need no exploit at all.
I Made Claude Bet the World Cup (With Fake Money), and It Taught Better Risk Lessons Than Most Security Training
7/15/2026
Before the 2026 semifinals, I asked Claude for calibrated predictions and a stake-sizing plan. The AI's most rational recommendation? Barely bet at all. Here's what a football tournament teaches about probability, calibration, and the scams riding the hype.
A DLP Baseline for Small Teams: Stopping Leaks Without a SOC
7/12/2026
Data-loss prevention is usually sold as enterprise tooling. Here's a pragmatic baseline a small team can actually run, built on classification, identity, and a few high-leverage controls.