Asyraf
Security professional by day, builder by night. Based in Singapore, writing about AI risk, enterprise governance, and shipping things in public.
Latest posts
Your Org Is Hiring Workers You Can't See: An Identity Playbook for AI Agents
8/14/2026
AI agents now open pull requests, answer tickets, and touch production data. And most orgs can't list them, let alone govern them. Here's a practical playbook: inventory, identity, least privilege, observation, and a kill switch.
Secure by Default on Cloudflare Pages: Headers, WAF & Analytics Without a Server
8/9/2026
A static site has no backend to harden, but it still has a security posture. Here's the secure-by-default baseline I run on this blog: response headers, edge WAF, and privacy-friendly analytics.
The Blog Watches the Watchers: Building a Threat-Intel Page With No Servers
7/26/2026
I wanted a live security-feeds page (CISA KEV, fresh CVEs, AI security research) on a static blog with no backend. Here's how it works, and why the hardest part was trusting nothing.