The catalogue is not the boundary of the attack surface
A weakness does not start working on the day it gets an identifier. It was already working. The identifier is just when defenders found out.
Blog
Perspectives on adversarial security, validated exposure and how attack paths cross tool boundaries.
A weakness does not start working on the day it gets an identifier. It was already working. The identifier is just when defenders found out.
Frequency tells you how often a tool runs. Continuity tells you whether security state survives between runs.
A finding matters differently when it exposes a credential, crosses a trust boundary or creates access to sensitive data.
A model can improve on its intended task and regress on a security boundary at the same time.
Most SaaS incidents are not vendor platform breaches. They are customer-side identity, permission and integration failures.
Passwords are only part of effective access. OAuth grants, sessions and service credentials can outlive the credential that started the incident.
Done means the task changed state. Fixed means the security condition changed state.
The interesting question is not whether a model can be talked into saying something. It is what the agent behind it is allowed to do.
A severity score describes a weakness in isolation. An adversary is interested in the third hop, not the first.
Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.