<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The YSecurity Blog</title>
    <link>https://ysecurity.io/blog/</link>
    <atom:link href="https://ysecurity.io/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Security thinking for founders and operators — drawn from The Security Podcast of Silicon Valley and YSecurity client work.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 14 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>AI Agent Governance Starts at Onboarding, Not Runtime</title>
      <link>https://ysecurity.io/blog/ai-agent-governance-onboarding/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/ai-agent-governance-onboarding/</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Most governance tools watch agents that are already deployed and already have access. The harder gap is making agents declare what they need before they ever run.</description>
    </item>
    <item>
      <title>AI Readiness Assessment: The Pre-Flight Check Before You Deploy an Agent</title>
      <link>https://ysecurity.io/blog/ai-readiness-assessment/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/ai-readiness-assessment/</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>More than 60% of AI implementations never reach meaningful ROI — usually because the enterprise was never ready to feed the agent what it needed. Run the check before you sign.</description>
    </item>
    <item>
      <title>Enterprise Browser Security: Why the Browser Is the New Control Point</title>
      <link>https://ysecurity.io/blog/enterprise-browser-security/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/enterprise-browser-security/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>Users spend most of their day in SaaS and AI tools, on encrypted connections your network appliances can&apos;t see into. The browser, not the network, is where the last mile of control now lives.</description>
    </item>
    <item>
      <title>Shadow AI: The Risks, and How to Govern It Without Blocking AI</title>
      <link>https://ysecurity.io/blog/shadow-ai-governance/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/shadow-ai-governance/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>Data you can&apos;t see is data you can&apos;t protect. When staff feed company information into unsanctioned AI tools, it can be stored, logged, or trained on far beyond your control.</description>
    </item>
    <item>
      <title>AI Penetration Testing: Can Autonomous Agents Replace Human Pentesters?</title>
      <link>https://ysecurity.io/blog/ai-penetration-testing/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/ai-penetration-testing/</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <description>A scanner flags an open door. An AI agent walks through it, finds your keys on the counter, and opens the safe. Here&apos;s what autonomous offensive testing can and can&apos;t do yet.</description>
    </item>
    <item>
      <title>AI Cyberattacks Are Going Autonomous: When the Hacker Is a Machine</title>
      <link>https://ysecurity.io/blog/autonomous-ai-cyberattacks/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/autonomous-ai-cyberattacks/</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <description>For a while, AI just wrote cleaner phishing emails. The newest tools run the whole attack — finding weaknesses, exploiting them, and moving deeper with little human input.</description>
    </item>
    <item>
      <title>Harvest Now, Decrypt Later: Why Today&apos;s Encrypted Data Is Tomorrow&apos;s Breach</title>
      <link>https://ysecurity.io/blog/harvest-now-decrypt-later/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/harvest-now-decrypt-later/</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <description>An adversary captures your encrypted traffic today, stores it, and waits for a quantum computer to break it. The attack works against data you already sent.</description>
    </item>
    <item>
      <title>What Is Deep Tech? Why the Hardest Startups Can&apos;t Be Built in a Weekend</title>
      <link>https://ysecurity.io/blog/what-is-deep-tech/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/what-is-deep-tech/</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <description>Deep tech is built on a hard scientific breakthrough, not on assembling parts that already exist. The core advance has to be invented and proven before there&apos;s a product to sell.</description>
    </item>
    <item>
      <title>AI Data Bill of Materials (DBOM): Why AI Security Needs a Data Supply Chain</title>
      <link>https://ysecurity.io/blog/ai-data-bill-of-materials/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/ai-data-bill-of-materials/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>An SBOM tells you what code is in your software. It can&apos;t tell you which customer records ended up in your latest fine-tune. A DBOM makes the data supply chain explicit.</description>
    </item>
    <item>
      <title>Stop Saying No: Enable AI With Data Governance, Not a Blanket Block</title>
      <link>https://ysecurity.io/blog/security-leaders-stop-saying-no/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/security-leaders-stop-saying-no/</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>The fastest way to lose influence as a security leader is to be the person who says no every time the business proposes an AI use case. The fix is visibility, not courage.</description>
    </item>
    <item>
      <title>IoT Device Security: Why Forgotten Devices Are Your Biggest Risk</title>
      <link>https://ysecurity.io/blog/iot-device-security/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/iot-device-security/</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <description>Printers, cameras, badge readers, sensors — the devices that get attacked first are the ones nobody put in the security org chart. Most IoT failures are governance failures with technical symptoms.</description>
    </item>
    <item>
      <title>Printer Security: How One Unsecured Printer Becomes Your Weakest Link</title>
      <link>https://ysecurity.io/blog/printer-security-weakest-link/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/printer-security-weakest-link/</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <description>About 20% of enterprise endpoints are printers. Roughly 99% sit at factory defaults — storing credentials for your email server, file shares, and directory at admin level.</description>
    </item>
    <item>
      <title>Neuro-Symbolic AI: Why Enterprises Need More Than Large Language Models</title>
      <link>https://ysecurity.io/blog/neuro-symbolic-ai/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/neuro-symbolic-ai/</guid>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <description>LLMs handle the fuzzy parts — language, perception, pattern. Symbolic systems handle the parts that must be correct. The enterprises getting AI right are composing both.</description>
    </item>
    <item>
      <title>Why 95% of Enterprise AI Projects Fail — and the Scoping Discipline That Beats the Odds</title>
      <link>https://ysecurity.io/blog/why-ai-projects-fail-scoping/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/why-ai-projects-fail-scoping/</guid>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <description>MIT found 95% of integrated enterprise AI pilots delivered zero measurable P&amp;L impact. The problem isn&apos;t the technology. It&apos;s how enterprises decide what to build, in what order, and with which tool.</description>
    </item>
    <item>
      <title>Deepfake Attacks Keep Working Because We Keep Detecting Instead of Proving</title>
      <link>https://ysecurity.io/blog/deepfake-detection-vs-identity/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/deepfake-detection-vs-identity/</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description>Detection is a classification problem, and its error rate grows as the adversary improves. Cryptographic identity proof doesn&apos;t care how realistic the fake is — it never relies on what someone looks or sounds like.</description>
    </item>
    <item>
      <title>Why Passwords Still Get Stolen: The Case for Device-Bound Credentials</title>
      <link>https://ysecurity.io/blog/device-bound-credentials/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/device-bound-credentials/</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description>88% of web app breaches involve stolen credentials. The security industry responds with more MFA and shorter tokens. Those are mitigations. The real problem is that the secret moves at all.</description>
    </item>
    <item>
      <title>Vibe Coding Security: How to Stop AI Agents From Shipping Vulnerable Code</title>
      <link>https://ysecurity.io/blog/vibe-coding-security/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/vibe-coding-security/</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>AI coding agents trust what they find — in the registry, on the machine, in the context window — often without verifying any of it. That trust is the new attack surface.</description>
    </item>
    <item>
      <title>Why Shift-Left Security Keeps Failing (and What Actually Works)</title>
      <link>https://ysecurity.io/blog/why-shift-left-security-fails/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/why-shift-left-security-fails/</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>Shift-left sounds right: find bugs earlier, fix them cheaper. It keeps failing because security teams push findings to developers who lack the context to prioritize them.</description>
    </item>
    <item>
      <title>Counter-Drone Technology: The Biggest Gap in National Security</title>
      <link>https://ysecurity.io/blog/counter-drone-technology/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/counter-drone-technology/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description>A $500 drone can destroy a $10 million tank. Small drone swarms reshaped warfare overnight, and Western nations don&apos;t yet have adequate defenses against them.</description>
    </item>
    <item>
      <title>How to Build a Defense Tech Startup: Lessons From the Tactical Edge</title>
      <link>https://ysecurity.io/blog/defense-tech-startup/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/defense-tech-startup/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description>Defense tech raised $125 billion from 2020 to 2024. Reveal Technology won military contracts by inverting the playbook — building for the corporal on the ground, not the program manager at a desk.</description>
    </item>
    <item>
      <title>Agentic AI Security: Why Agents Need Least Privilege More Than Humans Ever Did</title>
      <link>https://ysecurity.io/blog/agentic-ai-least-privilege/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/agentic-ai-least-privilege/</guid>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <description>Agents get the same broad permissions humans built up over years — without the judgment or self-control that made those permissions safe enough for people. RBAC was built for humans. It breaks for agents.</description>
    </item>
    <item>
      <title>Authorization Is the Last Layer Companies Still Build From Scratch</title>
      <link>https://ysecurity.io/blog/authorization-last-layer/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/authorization-last-layer/</guid>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <description>Authentication got outsourced a decade ago. Authorization — the logic that decides what a user can see, edit, or delete — is still built in-house at most companies. AI agents make that unsustainable.</description>
    </item>
    <item>
      <title>Building a Cybersecurity Startup: Lessons From Illumio CEO Andrew Rubin</title>
      <link>https://ysecurity.io/blog/building-a-cybersecurity-startup/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/building-a-cybersecurity-startup/</guid>
      <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
      <description>In 2013, Rubin and PJ Kirner founded Illumio on a thesis the industry wasn&apos;t ready to hear: perimeter security alone wouldn&apos;t be enough, breaches would be inevitable, and containment needed a different approach.</description>
    </item>
    <item>
      <title>Immutable Backups and Ransomware Recovery: Why 3-2-1 Isn&apos;t Enough Anymore</title>
      <link>https://ysecurity.io/blog/immutable-backups-ransomware-recovery/</link>
      <guid isPermaLink="true">https://ysecurity.io/blog/immutable-backups-ransomware-recovery/</guid>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
      <description>Ransomware operators go after your backups first. The 3-2-1 rule was built for hardware failures, not for adversaries who study your infrastructure before they strike.</description>
    </item>
  </channel>
</rss>
