This site uses a cookie to remember your theme preference. No tracking or third-party cookies are used. See our Privacy Policy for details.

bregg.com — AI Security & Healthcare Insights
  • Home
  • About
  • Learning
  • Search
  • Contact
  • Privacy

Categories

  • AI Agents (9)
  • AI Industry Watch (48)
  • AI Security (78)
  • Inside The AI Labs (3)
  • Learning Center (3)
  • MCP Security (5)
  • Non-Security (5)
  • Security Tools (1)
  • Threat Intelligence (1)

Tags

Agentic AI (42) AI Ethics (4) AI Governance (53) AI Infrastructure (20) AI Models (17) AI Regulation (15) AI Research (5) AI Security (56) Authentication (9) Authorization (6) Bug Bounty (1) Cybercrime (9) Edge AI (1) Encryption (2) Enterprise AI (37) Future of Work (8) Healthcare AI (62) IDS/IPS (2) Malware (7) MCP Security (1) OWASP (4) Phishing (2) Secure Code (12) Social Engineering (5) Supply Chain Security (13) Threat Intelligence (4) Tutorial (2) Vendor Risk Management (31) Zero Day (11)

Recent Posts

  • Vibe-Coded and Vulnerable: What the METR API Key Theft Teaches Healthcare AI Security Teams Sep 01
  • OWASP Agentic Skills Top 10 — Complete Reference for Healthcare Security Teams Aug 29
  • CISA's Vulnerability Review Is a Warning: AI Is About to Make Your Known Weaknesses Everyone's Problem Aug 28
  • OWASP's Agentic Skills Top 10: The Three Risks Healthcare Teams Need to Understand Now Aug 27
  • A Malicious Webpage Can Poison Your Local Ollama Model — What Healthcare Practitioners Need to Know Aug 26

Theme

© 2026 Bregg Holdings LLC

#RealTalk with Aaron Bregg

Authentication

9 articles

AI Security

Vibe-Coded and Vulnerable: What the METR API Key Theft Teaches Healthcare AI Security Teams

METR lost $600K in AI credits to an attacker who found their vibe-coded dashboard via certificate transparency logs. The...

Sep 01, 2026 11 min read
Read More
MCP Security

MCP's Agent Identity Problem: What the Official Roadmap Tells Healthcare Security Teams

The MCP roadmap openly admits the current auth model wasn't built for agentic workloads — pasted API keys and long-lived...

Aug 25, 2026 9 min read
Read More
AI Security

Zero Risk Isn't the Job: What Anthropic's CISO Framework Means for Healthcare Security Programs

Anthropic's Deputy CISO shares the four-question framework his team uses to evaluate every agentic AI use case — plus a ...

Jul 28, 2026 12 min read
Read More
MCP Security

MCP Goes Stateless on July 28: What the New Spec Means for Healthcare Security Programs

The MCP protocol ships its largest revision since launch on July 28. The stateless core is the headline, but the authori...

Jul 25, 2026 12 min read
Read More
AI Industry Watch

Anthropic Formalizes Biometric Identity Verification for Claude Consumer Users — What Healthcare Organizations Need to Know

Anthropic's July 8 privacy policy update makes it the first major US frontier AI lab to formally codify biometric identi...

Jul 21, 2026 9 min read
Read More
AI Security

Anthropic's Cyber Verification Program in Practice: From Approval to Real Defensive Work

Anthropic's CVP approved in one business day. Here's what the classifier actually unlocks, how Sonnet 5 and Opus 4.8 com...

Jul 08, 2026 11 min read
Read More
AI Security

MCP Gets Its Enterprise Authorization Layer — What the EMA Extension Means for Healthcare AI Governance

The MCP Enterprise-Managed Authorization extension is now stable, with Anthropic, Microsoft, and Okta among the first ad...

Jun 19, 2026 9 min read
Read More
AI Security

Kali365 PhaaS Kit Hijacks Microsoft 365 OAuth Tokens and Bypasses MFA — What Healthcare Security Teams Need to Do Now

The FBI is warning organizations about Kali365, a $250 phishing-as-a-service kit that captures Microsoft 365 OAuth token...

Jun 14, 2026 10 min read
Read More
AI Security

Meta's Instagram AI Vulnerability Fix Was Incomplete: Accounts Still Being Compromised

Users report continued Instagram account compromises hours after Meta claimed the AI chatbot vulnerability was fixed. Se...

Jun 03, 2026 4 min read
Read More