AlpacaX

The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

HIPAA day-90 audit: what session expiry misses

Insights

HIPAA day-90 audit: what session expiry misses

A HIPAA day-90 audit should review grant history, not just a session's current expiry. Here is what to pull.

Marco Kwak
Marco KwakHead of GTM · August 27, 2026
Session-scoped sudo: bind OS-level root to a session, not a sudoers file

Engineering

Session-scoped sudo: bind OS-level root to a session, not a sudoers file

A sudoers rule only asks who's allowed to run a command. Sudo reaching Alpacon's command API asks a second question: is this command dangerous.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 26, 2026
SSO and MFA verify the login, not what the session does next

Incident

SSO and MFA verify the login, not what the session does next

A five-month Zimbra zero-day shows what happens after an attacker gets inside an authenticated session.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 24, 2026
AgentForger: how one link forged a rogue AI agent with a borrowed employee session

Incident

AgentForger: how one link forged a rogue AI agent with a borrowed employee session

One crafted URL stood up an attacker-controlled AI agent inside the org. No stolen credential, no malware.

Jungyeon Lee
Jungyeon LeeContent Marketer · August 17, 2026
Zero standing privilege by design: make it a property of the session, not the token

Engineering

Zero standing privilege by design: make it a property of the session, not the token

Most vendors make the credential ephemeral. We make the privilege itself session-bounded—so standing privilege can't accumulate, even while a session is live.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · August 13, 2026
A command log won't tell you what your agent actually did.

Insights

A command log won't tell you what your agent actually did.

A command log tells you what ran. An audit has to answer who, why, and with whose approval—for humans and agents alike.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · July 21, 2026
Work Sessions: the audit unit your CISO actually needs

Product

Work Sessions: the audit unit your CISO actually needs

Alpacon's Work Sessions turn fragmented audit timelines into one object—declared intent, approval gate, session-scoped sudo, unified record.

David Calvert
David CalvertDeveloper Advocate · May 7, 2026
Blog | AlpacaX Blog