Asyraf

Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.

Latest posts

Secure by Default on Cloudflare Pages: Headers, WAF & Analytics Without a Server

8/9/2026

A static site has no backend to harden, but it still has a security posture. Here's the secure-by-default baseline I run on this blog: response headers, edge WAF, and privacy-friendly analytics.

The Blog Watches the Watchers: Building a Threat-Intel Page With No Servers

7/26/2026

I wanted a live security-feeds page (CISA KEV, fresh CVEs, AI security research) on a static blog with no backend. Here's how it works, and why the hardest part was trusting nothing.

When the Pentester Is the Model: What the OpenAI and Hugging Face Breach Confirms

7/23/2026

A cyber-capability evaluation escaped its sandbox and breached a real company. It is not a new attack so much as a live proof of three things this blog keeps arguing: the lethal trifecta, machine identity, and ungoverned agents.