evidence notebook
Follow the evidence.
Source-backed articles appear below with their review dates. Linked reports belong to their authors. The exercises are synthetic examples, not captured production incidents.
Run the authorization exercise →Your Evaluation Sandbox Holds Production Authority
Reviewed: 2026-09-14
- vendor: Anthropic September 2026 threat intelligence report, GTG-50020
- recommendation: The credential register, broker design, and validation exercise are proposed controls, not a reproduction of the incident.
What Happens Before the SOC Can Respond?
Reviewed: 2026-09-14
- vendor: GreyNoise investigation of the AI-orchestrated PaperCut campaign
- official: PaperCut NG/MF urgent security advisory
- recommendation: The response measures and tabletop exercise are proposed defensive controls, not validated detections for this campaign.
Your Agents Share More Than You Think
Reviewed: 2026-09-08
- independent: METR and Redwood investigation of agent behavior and collaboration
- recommendation: Shared-resource controls and acceptance tests below are my proposed engineering response.
Vendor Approval Is Not Your Authorization Model
Reviewed: 2026-09-08
- vendor: Google Fairwind announcement
- vendor: Anthropic Fable and Mythos 5.1 announcement
- vendor: OpenAI capability and safeguard assessment
- recommendation: The access register and operating controls below are my proposed program design, not vendor requirements.
A Pentest Story Is Not Authorization
Reviewed: 2026-08-31
- vendor: Gambit Security campaign report
- independent: Reuters report on the recovered Cursor sessions
- independent: The Hacker News technical summary
Prompt-Injection Testing Belongs in CI
Reviewed: 2026-08-17
- official: ToolHazard paper
- official: ToolHazard source repository
Disabled Is Not Removed
Reviewed: 2026-08-17
- vendor: PromptArmor document-injection disclosure
- vendor: Varonis RovoBlast disclosure
- independent: The Hacker News comparison of both paths
Telemetry Is an Instruction Channel
Reviewed: 2026-08-17
- vendor: Tenet Security GhostJacking disclosure
- independent: SC Media coverage
- official: agent-jackstop repository
Using MITRE ATLAS to Make AISecOps Threat-Informed
Reviewed: 2026-08-12
- official: MITRE ATLAS knowledge base
- analysis: Practitioner threat-informed program mapping
Using OWASP's Agentic Top 10 to Govern Systems That Act
Reviewed: 2026-08-12
- official: OWASP Top 10 for Agentic Applications
- analysis: Practitioner governance and control mapping
Using the OWASP LLM Top 10 as an Engineering Baseline
Reviewed: 2026-08-12
- official: OWASP Top 10 for Large Language Model Applications
- analysis: Practitioner mapping and engineering recommendations
Using NIST AI RMF to Build an AISecOps Program
Reviewed: 2026-08-12
- official: NIST AI Risk Management Framework
- analysis: Practitioner mapping and program recommendations