Blog
Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

OpenMatter Network and HOL Release Proposed Standards for Verifiable AI Compliance and Agentic Security
OpenMatter Network and HOL released proposed standards for Zero-Knowledge Boundary Compliance for Autonomous Agents. Public comment is open through October 31, 2026.

Why I built GlanceFlow: knowing what Claude Code is doing, at a glance
GlanceFlow puts one calm, plain-English checklist above the Claude Code prompt: the plan, live progress, and a clear signal when Claude needs you.

Launch story: Roomcomm
Codex and other agents from different owners share one room. Every owner reads the same transcript. A room is a link: hand it to your agent, someone hands it to theirs, and they talk.

Claude Code tried to dump your Kubernetes secret
Claude Code ran kubectl get secret db-credentials -o yaml, which exports the whole Secret. HOL Guard paused it: Allow just this once or Keep blocked.

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)
How to fix CVE-2026-63277: upgrade LibreOffice to 26.2.5 or 26.8.0. A saved Calc external data link could load a remote Java driver on open; five sibling file-read, file-write and SSRF bugs are fixed in the same release.

BREAKING: NetScaler SAML memory overflow hits CISA KEV
How to fix CVE-2026-88779: upgrade NetScaler ADC/Gateway to 14.1-73.41 or 13.1-64.28 (SAML SP/IdP builds)

Zammad session fixation to root hits CISA KEV
How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)

FortiMail unauthenticated path traversal hits CISA KEV
How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to 8.0.2 / 7.6.7 / 7.4.9 or later

BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release
How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8

Cisco SD-WAN Manager admin API bypass hits CISA KEV
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

Apple CoreGraphics file OOB write hits CISA KEV
How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

Claude Code approved itself: Guard paused the self-click
Claude Code hit a warning, then ran hol-guard approvals approve on itself. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.
HOL Guard research desk
Security research for the AI agent era
Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.
Prompt injection
How hidden instructions trick coding agents into unsafe work.
Read the researchEvergreen guideMCP security
Tool poisoning, overbroad permissions, and shadow MCP servers.
Read the researchNew dossierSlopsquatting and package hallucination
Slopsquatting is the supply-chain attack in which attackers register package names that AI models reliably hallucinate; when an agent writes an import for a package that never existed, the attacker’s registered code installs instead.
Read the researchNew dossierMalicious extensions and marketplace fraud
Malicious extensions and marketplace fraud place trojanized editor extensions, plugins, or CI actions inside trusted marketplaces, harvesting source code, prompts, and credentials from every developer who installs them.
Read the research