The Product Security Playbook
Weekly Deep Dives
Join other product security leaders getting deep dives on secure products, AI security, and leadership delivered to their inbox, for free.
The archive
Every Issue
- #028 · How to Defend Against Unexpected Code Execution in AI Agents
- #027 · Feynman is Still Right
- #026 · Defending Against Agentic Supply Chain Attacks
- #025 · How to Stop AI Agents From Abusing Borrowed Identities
- #024 · Why Drones Can Be Authenticated and Still Spoofed
- #023 · Over-Privileged and Under-Supervised
- #022 · How to Prevent AI Agent Goal Hijacking
- #021 · Build the Horse, Not the Car
- #020 · The OWASP Top 10 for Agentic Applications: What Leaders Need to Know
- #019 · How do CISOs deal with the OpenClaw risk?
- #018 · How do I prepare for FedRAMP 20x?
- #017 · Are AI Browsers Safe for the Enterprise?
- #016 · How to Use GitHub Actions Safely
- #015 · Ownership: the Missing Link in Supply Chain Security
- #014 · From Scanners to Systems
- #013 · Breaches Optional?
- #012 · Courageous Security: Lessons from a Nazi Resistance Fighter
- #011 · SMS MFA = Gross Negligence
- #010 · DAST That Doesn’t Suck: A Practical Guide
- #009 · Slay the R.O.U.S - Reports of Unusual Size
- #008 · The Great Seattle Fire of 1889 - A Lesson in Breach Prevention
- #007 · Toothbrushes or Diamonds - Simple Application Risk Assessment
- #006 · The Secret to Better Security Metrics: Think Like a Developer
- #005 · Are You Trusting the Wrong Data? The Case for Input Validation
- #004 · From Chicken Little to Chuck Norris
- #003 · The Easy Button for Orphaned Code
- #002 · Underground Security: Vegas's Underground Tunnels as a Model For Attack Surface Reduction
- #001 · Git - For Fun and Profit