Asyraf

Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.

Latest posts

Stop Patching by CVSS Alone: A Three-Signal Triage Formula That Fits on a Sticky Note

9/26/2026

CVSS tells you how bad a vulnerability could be, EPSS tells you how likely exploitation is, and KEV tells you it's already happening. Used together, they turn the CVE firehose into a defensible patch queue.

CVE, CVSS, EPSS, KEV: The Vulnerability Alphabet, Finally Explained

8/20/2026

Four acronyms run the entire vulnerability world: one names the problem, one scores its severity, one predicts exploitation, one confirms it. Untangle them once and every security headline suddenly makes sense.

Your Org Is Hiring Workers You Can't See: An Identity Playbook for AI Agents

8/14/2026

AI agents now open pull requests, answer tickets, and touch production data. And most orgs can't list them, let alone govern them. Here's a practical playbook: inventory, identity, least privilege, observation, and a kill switch.