This Week in Security - Week 24, June 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

June 8, 2026 · 8 min · Rajen
Observability Is Not Governance

Observability Is Not Governance

Observability Is Not Governance Where your open-source AI stack stops being audit-grade. Observability tells you what happened. Governance controls what’s allowed to happen. Most teams shipping AI features have the first and assume it covers the second. It doesn’t. This post makes three moves. First, it separates the two things people conflate. Second, it borrows a test auditors have used for decades to show exactly where an observability log stops being evidence. Third, it names the two ceilings open-source tooling hits, maps them to SOC 2, and tells you what to do at each one. ...

June 6, 2026 · 6 min · Rajen

This Week in Security - Week 23, June 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

June 1, 2026 · 6 min · Rajen

This Week in Security - Week 22, May 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

May 25, 2026 · 7 min · Rajen

This Week in Security - Week 21, May 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

May 18, 2026 · 4 min · Rajen

This Week in Security - Week 20, May 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

May 11, 2026 · 7 min · GRC Vitrix
MVP threat modeling for SaaS startups — one-page template showing assets, entry points, abuse paths, impact, and controls

MVP Threat Modeling for SaaS Startups: A 60-Minute, One-Page Method

Most SaaS startups don’t fail their first security review because the framework was too hard. They fail because nobody owned login abuse until a customer flagged it. They fail because admin role changes were trusted on the client side. They fail because webhooks weren’t signed and a third party became an attacker. These are not exotic problems. They are basic ones, and they almost always trace back to the same root cause: there was no moment in the build process where someone asked, “how could this be misused?” ...

May 5, 2026 · 16 min · GRC Vitrix
SOC 2 and AI agents — the logging gap between traditional human user logs and AI agent activity that auditors are starting to ask about

SOC 2 and AI Agents: The Logging Gap That Will Show Up in Your Next Audit

For about 20 years, SOC 2 logging worked because it answered one question: who did what, when? User logs in. Developer pushes code. Admin changes a permission. Every meaningful action traced back to a human identity. Every framework — SOC 2, ISO 27001, NIST 800-53 — assumed this. Logging infrastructure was built around it. AI agents are quietly breaking that assumption. If you’re shipping AI features on top of customer data — even just an internal automation that summarizes vendor contracts or routes support tickets — you’re running a system that takes actions, accesses data, and makes decisions. Your SIEM sees the API calls. It does not see what the agent was trying to do, why it picked one file over another, or what it produced as a result. ...

May 5, 2026 · 11 min · GRC Vitrix

This Week in Security - Week 19, May 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

May 4, 2026 · 7 min · GRC Vitrix

This Week in Security - Week 18, April 2026

Weekly security intelligence digest covering the most critical vulnerabilities, threats, and breach news from the past week. ...

April 27, 2026 · 8 min · GRC Vitrix