Asyraf

Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.

Latest posts

Putting AI on the Blue Team: Where Claude, Codex, and Gemini Actually Earn Their Keep in Defence

10/3/2026

Frontier AI assistants are marketed as security multipliers. Some of that is real. Here's where they genuinely help a defender today, how to choose between them, and the guardrails that keep your defender from becoming your incident.

Stop Patching by CVSS Alone: A Three-Signal Triage Formula That Fits on a Sticky Note

9/26/2026

CVSS tells you how bad a vulnerability could be, EPSS tells you how likely exploitation is, and KEV tells you it's already happening. Used together, they turn the CVE firehose into a defensible patch queue.

CVE, CVSS, EPSS, KEV: The Vulnerability Alphabet, Finally Explained

8/20/2026

Four acronyms run the entire vulnerability world: one names the problem, one scores its severity, one predicts exploitation, one confirms it. Untangle them once and every security headline suddenly makes sense.