Asyraf
Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.
Latest posts
The Blog Watches the Watchers: Building a Threat-Intel Page With No Servers
7/26/2026
I wanted a live security-feeds page (CISA KEV, fresh CVEs, AI security research) on a static blog with no backend. Here's how it works, and why the hardest part was trusting nothing.
When the Pentester Is the Model: What the OpenAI and Hugging Face Breach Confirms
7/23/2026
A cyber-capability evaluation escaped its sandbox and breached a real company. It is not a new attack so much as a live proof of three things this blog keeps arguing: the lethal trifecta, machine identity, and ungoverned agents.
Paste Once, Lose Everything: What ClickLock Teaches About Trusting Your Own Terminal
7/21/2026
A new macOS stealer doesn't exploit a bug: it exploits a habit. ClickLock coerces victims into typing their own password by making the Mac unusable until they comply. Here's the anatomy, and why the scariest attacks need no exploit at all.