AlpacaX

The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Why AI governance pilots don't survive scale

Insights

Why AI governance pilots don't survive scale

The policy wasn't wrong. It just wasn't sized for agents your other teams stood up without telling you.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · September 7, 2026
Out-of-band approval: why an agent's own channel can never be the one that approves

Insights

Out-of-band approval: why an agent's own channel can never be the one that approves

An AI agent that can approve a review on its own execution channel isn't gated at all. Why out-of-band approval separates the channel, not the person.

Marco Kwak
Marco KwakHead of GTM · August 28, 2026
Kubernetes access control governs access, not commands

Engineering

Kubernetes access control governs access, not commands

Access control checks whether you can reach a Kubernetes pod. It doesn't check whether the kubectl command you type should run.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 27, 2026
Session-scoped sudo: bind OS-level root to a session, not a sudoers file

Engineering

Session-scoped sudo: bind OS-level root to a session, not a sudoers file

A sudoers rule only asks who's allowed to run a command. Sudo reaching Alpacon's command API asks a second question: is this command dangerous.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 26, 2026
Two 2026 CVEs turned security tools into the attack path

Incident

Two 2026 CVEs turned security tools into the attack path

Microsoft Defender and Check Point SmartConsole both became attack paths in 2026, and one patch fell to a bypass a month later.

Marco Kwak
Marco KwakHead of GTM · August 25, 2026
Command filtering fails two ways: GTFOBins, and a shell that rewrites what you matched

Engineering

Command filtering fails two ways: GTFOBins, and a shell that rewrites what you matched

Measured across 1,709 real-world denylists, most don't fully block what they were written to block.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · August 20, 2026
AI agent execution control: what it is, and why AI-native PAM needs it

Insights

AI agent execution control: what it is, and why AI-native PAM needs it

Every agent constraint is either declared or enforced. Execution control is the enforced kind.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · August 18, 2026
AI vendor risk assessment in 2026: the runtime questions your questionnaire is missing

Insights

AI vendor risk assessment in 2026: the runtime questions your questionnaire is missing

Your questionnaire covers who the vendor is and how they store data. It says nothing about what their agent executes on your servers once you authorize it.

Marco Kwak
Marco KwakHead of GTM · August 14, 2026
Alignment isn't enough: containing a misaligned agent's actions takes runtime execution control

Incident

Alignment isn't enough: containing a misaligned agent's actions takes runtime execution control

Model-level alignment lowers the odds an agent misbehaves. It can't drive the odds to zero once the agent is running on real infrastructure.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 12, 2026
AI governance on paper vs. governance during the task

Insights

AI governance on paper vs. governance during the task

A near-miss doesn't change your policy. It changes the question leadership asks about it.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · August 11, 2026
LegacyHive: a Windows zero-day you can't patch your way out of

Incident

LegacyHive: a Windows zero-day you can't patch your way out of

No CVE, no vendor patch, and it works on fully-patched machines. When patch-and-wait isn't a control, what's left is the layer that governs privileged actions as they run.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 7, 2026
AutoJack: one webpage, one MCP socket, host-level access

Insights

AutoJack: one webpage, one MCP socket, host-level access

Microsoft disclosed a three-stage exploit chain in AutoGen Studio that turns an AI browsing session into a remote code execution primitive. No single patch makes the underlying problem go away.

Jungyeon Lee
Jungyeon LeeContent Marketer · July 28, 2026
The gate worked. The database was still dumped.

Incident

The gate worked. The database was still dumped.

Sysdig documented the first in-the-wild LLM agent intrusion: four pivots, every access gate cleared, database exfiltrated. The layer neither covers.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · June 24, 2026
Blog | AlpacaX Blog