AlpacaX

The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

MFA fatigue is a scoping problem, not a user problem

Insights

MFA fatigue is a scoping problem, not a user problem

Prompt-bombing wins when every extra MFA check trains the team to auto-approve the one that matters.

Marco Kwak
Marco KwakHead of GTM · 17 September 2026
HIPAA day-90 audit: what session expiry misses

Insights

HIPAA day-90 audit: what session expiry misses

A HIPAA day-90 audit should review grant history, not just a session's current expiry. Here is what to pull.

Marco Kwak
Marco KwakHead of GTM · 27 August 2026
Session-scoped sudo: bind OS-level root to a session, not a sudoers file

Engineering

Session-scoped sudo: bind OS-level root to a session, not a sudoers file

A sudoers rule only asks who's allowed to run a command. Sudo reaching Alpacon's command API asks a second question: is this command dangerous.

Jungyeon Lee
Jungyeon LeeContent Marketer · 26 August 2026
SSO and MFA verify the login, not what the session does next

Incident

SSO and MFA verify the login, not what the session does next

A five-month Zimbra zero-day shows what happens after an attacker gets inside an authenticated session.

Jungyeon Lee
Jungyeon LeeContent Marketer · 24 August 2026
AgentForger: how one link forged a rogue AI agent with a borrowed employee session

Incident

AgentForger: how one link forged a rogue AI agent with a borrowed employee session

One crafted URL stood up an attacker-controlled AI agent inside the org. No stolen credential, no malware.

Jungyeon Lee
Jungyeon LeeContent Marketer · 17 August 2026
Zero standing privilege by design: make it a property of the session, not the token

Engineering

Zero standing privilege by design: make it a property of the session, not the token

Most vendors make the credential ephemeral. We make the privilege itself session-bounded—so standing privilege can't accumulate, even while a session is live.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · 13 August 2026
A command log won't tell you what your agent actually did.

Insights

A command log won't tell you what your agent actually did.

A command log tells you what ran. An audit has to answer who, why, and with whose approval—for humans and agents alike.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · 21 July 2026
Work Sessions: the audit unit your CISO actually needs

Product

Work Sessions: the audit unit your CISO actually needs

Alpacon's Work Sessions turn fragmented audit timelines into one object – declared intent, approval gate, session-scoped sudo, unified record.

David Calvert
David CalvertDeveloper Advocate · 7 May 2026
Blog | AlpacaX Blog