Writing
Articles & essays on AI security.
Most recent work lives on the CrowdStrike blog, research and explainers on prompt injection, agentic tool chains, and the AI Detection & Response approach.
CrowdStrike Blog
Feb 18, 2026
with John Gamble
Introducing AI Unlocked: An Interactive Prompt Injection Challenge
A new immersive simulation that lets security teams experience prompt-injection attacks firsthand through three progressive difficulty levels: Command Center, Data Gateway, and Nexus. Concepts stick when you've had to defend against them.
Read on CrowdStrike →
CrowdStrike Blog
Jan 30, 2026
How Agentic Tool Chain Attacks Threaten AI Agent Security
Three attack vectors (tool poisoning, tool shadowing, and rugpull attacks) manipulate AI agents' reasoning layers. Practical enterprise defense strategies including tool governance, version control, and observability measures.
Read on CrowdStrike →
CrowdStrike Blog
Jan 9, 2026
AI Tool Poisoning: How Hidden Instructions Threaten AI Agents
How attackers embed malicious instructions in the tool descriptions used via Model Context Protocol (MCP): covering hidden instructions, misleading examples, and permissive schemas. Plus the defensive measures that actually hold up.
Read on CrowdStrike →
CrowdStrike Blog
Dec 11, 2025
with Jim Hoagland
Data Leakage: AI's Plumbing Problem
The data leakage problem in AI systems is less about exotic attacks and more about plumbing: pipes that weren't designed to carry the data they're now carrying. What enterprise security teams should be looking for.
Read on CrowdStrike →
Pangea Blog
May 23, 2025
How to Secure MCP Servers with AI Guardrails
Securing Model Context Protocol (MCP) servers with Pangea's AI Guard guardrails, preventing prompt injection and data leakage without modifying existing code.
Read on Pangea →
Pangea Blog
Mar 21, 2025
AI Guard on the Edge
How AI Guard delivers customizable guardrails against prompt injection and data leakage, comparing SaaS and Edge deployment so organizations can run it in the cloud or on infrastructure they control.
Read on Pangea →
Pangea Blog
Jan 17, 2025
Logging: Ensuring Robustness and Transparency in AI Apps
Why robust logging is essential for AI applications: the operational, security, and compliance risks of inadequate logging, and best practices for effective logging frameworks.
Read on Pangea →
Pangea Blog
Oct 29, 2024
Announcing Updated Pangea Extension for GitHub Copilot
Enhancements to Pangea's GitHub Copilot extension: generate code samples, create accounts, and initialize security services directly within VS Code's Copilot Chat.
Read on Pangea →
Pangea Blog
Oct 4, 2024
Mastering HIPAA Access Control Requirements: A Guide for Developers
How healthcare developers can implement effective access control to protect patient data and maintain HIPAA compliance: covering RBAC/ABAC models, MFA, and audit logging.
Read on Pangea →
Pangea Blog
Sep 10, 2024
How to ABAC: Banking Edition
Implementing Attribute-Based Access Control (ABAC) in banking systems with Pangea's authorization service: resources, roles, relationships, and attribute-based rules.
Read on Pangea →
Pangea Blog
Sep 4, 2024
RBAC vs ReBAC vs ABAC: Comparison and Guide
Comparing the three major authorization models (Role-, Relationship-, and Attribute-Based Access Control), their trade-offs, and how to set up RBAC policies with Pangea.
Read on Pangea →
Pangea Blog
Aug 22, 2024
Mastering HIPAA Audit Log Requirements
A developer's guide to HIPAA audit log requirements for enterprise healthcare systems (what to log, retention standards, and best practices) with Pangea's audit log service for tamper-proof records.
Read on Pangea →
Pangea Blog
May 10, 2024
Add "Login with Passkeys" to Your Django App
A tutorial on integrating passkey authentication into Django apps with Pangea's AuthN service, from new project to enabling passkeys in the Pangea console.
Read on Pangea →
Pangea Blog
Mar 5, 2024
SAML Explained: The Foundation of Secure Authentication
SAML as an authentication standard enabling single sign-on and secure credential exchange across apps, and how Pangea supports it.
Read on Pangea →
Pangea Blog
Feb 14, 2024
Pangea at THAT: Texas Edition
A recap of Pangea's time at THAT Conference Texas: networking, talks on cloud design patterns and secure-by-design culture, and raffle winners.
Read on Pangea →
Pangea Blog
Nov 20, 2023
Pangea's GitHub Actions
Integrating Pangea security APIs into GitHub Actions workflows to run secure-coding checks: malicious-URL detection and secrets management via Pangea Vault.
Read on Pangea →