AlpacaX

The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Product update: what gets decided before a command runs

Product

Product update: what gets decided before a command runs

Choose how far commands are gated, confirm the server account during approval, and give automation credentials of its own.

Taeyeong Baek
Taeyeong BaekGTM Associate · September 8, 2026
SSO and MFA verify the login, not what the session does next

Incident

SSO and MFA verify the login, not what the session does next

A five-month Zimbra zero-day shows what happens after an attacker gets inside an authenticated session.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 24, 2026
Credential theft: entitlements without purpose

Incident

Credential theft: entitlements without purpose

Storm-2949 turned one compromised identity into a cloud-wide breach—the gap a stolen credential's entitlements can never answer.

Marco Kwak
Marco KwakHead of GTM · August 24, 2026
Offboarding access revocation: what a departing engineer leaves running

Insights

Offboarding access revocation: what a departing engineer leaves running

Disabling the account ends their login. It doesn't touch what they built, or tell you what they ran.

Marco Kwak
Marco KwakHead of GTM · August 19, 2026
AgentForger: how one link forged a rogue AI agent with a borrowed employee session

Incident

AgentForger: how one link forged a rogue AI agent with a borrowed employee session

One crafted URL stood up an attacker-controlled AI agent inside the org. No stolen credential, no malware.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 17, 2026
An autonomous AI agent breached Hugging Face—here's the kill chain, and where execution control bounds it

Incident

An autonomous AI agent breached Hugging Face—here's the kill chain, and where execution control bounds it

An autonomous AI agent ran a real end-to-end intrusion on Hugging Face's production infrastructure. Here is the kill chain, and an honest map of where a runtime execution-control layer bounds it.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 10, 2026
Adding AI agents shouldn't mean adding more security exposure

Insights

Adding AI agents shouldn't mean adding more security exposure

Expanding your attack surface isn't the price of an AI agent. It's an artifact of how you wire it in—and it's avoidable.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · July 9, 2026
Blog | AlpacaX Blog