This site uses a cookie to remember your theme preference. No tracking or third-party cookies are used. See our Privacy Policy for details.

bregg.com — AI Security & Healthcare Insights
  • Home
  • About
  • Learning
  • Search
  • Contact
  • Privacy

Categories

  • AI Agents (9)
  • AI Industry Watch (42)
  • AI Security (63)
  • MCP Security (4)
  • Non-Security (5)
  • Security Tools (1)
  • Threat Intelligence (1)

Tags

Agentic AI (22) AI Ethics (3) AI Governance (38) AI Infrastructure (10) AI Models (12) AI Regulation (12) AI Research (5) AI Security (34) Authentication (7) Authorization (5) Bug Bounty (1) Cybercrime (2) Encryption (2) Enterprise AI (33) Future of Work (8) Healthcare AI (38) Malware (4) OWASP (1) Phishing (2) Secure Code (9) Social Engineering (4) Supply Chain Security (4) Vendor Risk Management (19) Zero Day (4)

Recent Posts

  • Zero Risk Isn't the Job: What Anthropic's CISO Framework Means for Healthcare Security Programs Jul 28
  • Agent Skills, Shadow AI, and MCP Connections: The Attack Surface Healthcare Can't See Jul 27
  • Six Months to Prepare: What ThreatDown's Cybercrime in the Age of AI Report Means for Security Teams Jul 26
  • MCP Goes Stateless on July 28: What the New Spec Means for Healthcare Security Programs Jul 25
  • After the Escape: What the OpenAI/Hugging Face Incident Tells Us About AI Accountability and Containment Jul 24

Theme

© 2026 Bregg Holdings LLC

#RealTalk with Aaron Bregg

Vendor Risk Management

19 articles

AI Security

Zero Risk Isn't the Job: What Anthropic's CISO Framework Means for Healthcare Security Programs

Anthropic's Deputy CISO shares the four-question framework his team uses to evaluate every agentic AI use case — plus a ...

Jul 28, 2026 12 min read
Read More
AI Security

Agent Skills, Shadow AI, and MCP Connections: The Attack Surface Healthcare Can't See

ThreatDown's cybercrime report documents the malicious agent skills attack chain in operational detail — and explicitly ...

Jul 27, 2026 11 min read
Read More
MCP Security

MCP Goes Stateless on July 28: What the New Spec Means for Healthcare Security Programs

The MCP protocol ships its largest revision since launch on July 28. The stateless core is the headline, but the authori...

Jul 25, 2026 12 min read
Read More
AI Security

After the Escape: What the OpenAI/Hugging Face Incident Tells Us About AI Accountability and Containment

OpenAI's AI models escaped their evaluation sandbox and attacked Hugging Face. The timeline is known. What accountabilit...

Jul 24, 2026 11 min read
Read More
AI Industry Watch

Anthropic Formalizes Biometric Identity Verification for Claude Consumer Users — What Healthcare Organizations Need to Know

Anthropic's July 8 privacy policy update makes it the first major US frontier AI lab to formally codify biometric identi...

Jul 21, 2026 9 min read
Read More
AI Industry Watch

Kimi K3: The World's Largest Open-Weight Model Arrives One Month After Fable Was Pulled — What It Means for Healthcare AI Strategy

Moonshot AI released the world's largest open-weight model at near-Fable capability levels — for free download, on July ...

Jul 17, 2026 10 min read
Read More
AI Security

Four Agentic Misalignment Failures Documented by Anthropic's Alignment Team — What Healthcare Security Programs Need to Know

Anthropic's alignment science team published controlled experiments documenting four frontier model failure modes: cover...

Jul 16, 2026 16 min read
Read More
AI Security

Shipped Known Risk: What GPT-5.6 Sol's File Deletions Reveal About Agentic AI Governance

OpenAI's GPT-5.6 Sol deleted files and production databases it wasn't authorized to touch — 14 days after the company's ...

Jul 15, 2026 12 min read
Read More
AI Security

PolinRider: North Korea's Open Source Supply Chain Campaign and What It Means for Healthcare DevSecOps

A North Korean supply chain campaign has compromised 108 open source packages and 1,951 GitHub repositories since Decemb...

Jul 13, 2026 13 min read
Read More
1 2 3
Next