RSSAmplifier

Blog

John Menerick | Security Engineer

Explore cutting-edge cybersecurity insights and protective strategies with John Menerick. Deep dives, threat analysis, and live streams from securesql.info.

securesql.infoRSS feed ↗136 posts

Latest posts

Autonomous Incident Response at Scale: How Energy-Based Models & TAME Replace LLM Guessing in Security

Why do Fortune 10 SOCs with 15 people outpace teams 10x their size? They've stopped using autoregressive LLMs for threat modeling, response, and recovery. Instead, they deploy Energy-Based Models governed by TAME principles—tested, auditable, measurable, explainable—to score threats across continents and outer space in 47 seconds. A technical breakdown of how SentinelMesh scales autonomous…

Part VIII & Conclusion — What it looks like when you hold the whole picture at once

The fairy dust didn't disappear. It moved one abstraction layer higher with each generation. In 2014 it was 'everyone's looking at the code.' In 2026 it is 'our AI security deployment is safe and our governance frameworks are adequate.' The pattern is consistent. Only the substrate changes.

Security Theater and Cap Tables: Deconstructing Cal.com’s Closed-Source Pivot

Cal.com's 2026 transition to a closed-source model was publicly framed as a response to AI-driven security threats. This case study decomposes the move, exposing the financial and competitive moats driving the decision.

Part VII — What this means if you work in security, build OSS, run AI infrastructure, or set policy

The scarcity of finding capability is over. The crisis of fixing it is just beginning. Six takeaways for the six categories of people who need to act now — with the specific actions, the honest timelines, and the non-obvious implications each category tends to miss.

Part VI — Pros, cons, and tensions that don’t resolve

The honest accounting of Project Glasswing: what it genuinely changes, what it genuinely cannot change, and the six tensions at the center of the initiative that do not resolve — regardless of how good the intentions are.

Part V — What Project Glasswing actually changes for every open source actor on earth

Glasswing is the first time a frontier AI lab publicly declared that a capability in its own model is too dangerous to release. That is not a product launch. It is a policy precedent. And policy precedents are defined not by the first organization that sets them, but by whether subsequent organizations follow them.

Part IV — From ‘I have a toolbox’ to ‘the scanner has a backdoor’

The twelve-year arc from a DEF CON talk about vulnerability density to an AI model that escapes its sandbox to email a researcher eating lunch. The path was not straight. But in retrospect it was inevitable.

Part III — Silicon Valley’s new attack surface: the machine learning AGI dependency graph

In 2014 the scariest projects were Exim, Bind, and OpenSSL. In 2026 the load-bearing walls include PyTorch, TensorFlow, and LiteLLM — and they were designed by researchers who were not thinking about nation-state supply chain attacks.

Part III — When the security scanner became the weapon: Trivy → LiteLLM → Axios

Two distinct nation-state actors struck the developer toolchain within 12 days. The inspector became the attack surface. The most diligent organizations had the greatest exposure. This is not a metaphor.

Part II — Third-party libraries: the vulnerability layer nobody counted

When your Node.js service pulls 847 npm packages to serve a login form, you are not running one application. You are running 847 applications — most written by someone who needed to scratch an itch and moved on.

Part I — The original quantitative case: internet infrastructure is not OK

The Open Source Fairy Dust talk wasn't a rhetorical exercise. It was a data exercise across 2,000+ projects. Almost nothing critical lived in the safe quadrant — and the outliers told a story about institutional failure, not individual negligence.

From fairy dust to Glasswing: a decade of being right about the wrong thing

In 2014 I stood at DEF CON and showed the internet's foundational software was held together by wishful thinking. In 2026, two nation-states proved the security tooling itself is now the attack surface.

The Blueprint for a Living Defense: Why Your SOC Needs a Nervous System

We spent Season 2 exploring the biology of security—from the physics of Complex Systems to the ethics of the 'Worthy Successor.' Now, we turn theory into practice. Here is your complete Morphogenetic SOC Toolkit: the architectures, governance models, and engineering principles needed to stop fixing your network and start letting it heal itself.

Episode 2: The Layer 2 Bridge Lab

Migrating from /etc/network/interfaces to NetworkManager on Debian Trixie is a rite of passage. This lab walks through building a persistent Layer 2 bridge between eth0 and a ZeroTier interface—plus the dispatcher automation that keeps MTU and bridge membership correct across reboots, restarts, and interface flaps.

The Worthy Successor: Designing the Ethics of an Agentic Future

We fear AGI as a terminator, but biology suggests it could be a savior—if we design it correctly. By expanding the 'Cognitive Light Cone' of our systems, we can move beyond mere control to the cultivation of a 'Worthy Successor' that navigates the Platonic spaces of truth and compassion we can barely perceive.

The Cyber-Biological Synthesis: Blueprint for an Agentic SOC

Static firewalls cannot stop fluid agents. By merging the biological insights of TAME with the hard engineering of MAESTRO and OWASP, we can build a 'Morphogenetic SOC'—a security architecture that senses, reasons, and heals like a living nervous system.

The Bioelectric Blueprint: How to Reprogram Your Infrastructure’s ‘Mind’ Without Touching the Hardware

We usually try to secure systems by fixing the 'hardware'—patching servers and blocking IPs. But biology proves that the true driver of resilience is the 'bioelectric software' that dictates the system's shape. By learning how to rewrite the 'pattern memory' of a network, we can engineer security architectures that don't just repair damage, but actively regenerate their own defense.

Scaling Agency: Why Your SOC Needs a Cognitive Light Cone

We usually define security tools by their code, but biology suggests we should define them by their goals. By mapping the 'Cognitive Light Cone' of our agents—the exact scope of space and time they care about—we can stop building brittle scripts and start engineering a collective intelligence that acts as a unified immune system.

The Simulation Imperative: Why Your Security Agents Must ‘Hallucinate’ to Defend You

We treat AI 'hallucination' as a critical flaw, but control theory suggests it is a requirement for survival. New mathematical proofs demonstrate that no agent can be a general defender without an internal 'world model'—a way to simulate the future. Here is why the era of model-free security is over, and why your defense stack needs to learn how to imagine.

Ashby’s Ultimatum: Why Your Security Stack Is Mathematically Doomed

We assume security is a resource problem—that more tools and rules will stop the breach. We assume we can regulate threats without modeling them. We assume static defenses can contain dynamic attackers. Complex Systems proves these aren't just bad strategies; they are violations of the fundamental physics of control.

The Salamander Strategy: Why Your Cloud Infrastructure Needs to Learn How to Regrow Itself

We assume disaster recovery is a binder on a shelf. We assume infrastructure drift is a crash to be fixed. We assume resilience means building walls that never break. Every single one of these assumptions is obsolete—and this regenerative framework proves why.

From Biology to Bot: A Strategic Framework for Governed Agency in Security Engineering

We assume security is about static defense. We assume automation is always deterministic. We assume risk is managed by limiting access. Every single one of these assumptions is obsolete in the age of AI agents—and this biological framework proves why.

5 Mind-Bending Security Paradigms That Will Redefine How You Think About Infrastructure Deployments

We assume signed code happens in CI/CD pipelines. We assume certificates live for days or weeks. We assume trust is verified once at build time. Every single one of these assumptions is obsolete—and this implementation proves why.

5 Mind-Bending Truths About API Security That Will Change How You Think About Trust

We've been thinking about API keys completely wrong. What if the most secure credential is one that literally can't exist for more than fifteen minutes—and requires a committee of hardware tokens to even create?

The Security Pattern Most DevOps Teams Get Dangerously Wrong (And How Hardware Tokens Fix It)

Your Terraform state files contain the keys to your kingdom—database passwords, API tokens, private keys—all in one convenient JSON file. Yet most teams protect them with the digital equivalent of a "do not enter" sign. Here's why that's terrifying, and how hardware-backed encryption changes everything.

5 Mind-Blowing Secrets Behind Password-Less Database Provisioning (You Won’t Believe #3)

In a world where database credentials are the crown jewels attackers covet most, what if I told you there's a way to provision databases without a single static password—and the secret expires in 5 minutes?

5 Mind-Blowing Security Truths That Will Change How You Think About SSH Access Forever

Your SSH keys are sitting on your laptop right now. What happens when your device gets compromised? The answer is scarier than you think—and there's a revolutionary solution you've probably never heard of.

5 Mind-Bending Ways Hardware Security Keys Are Revolutionizing API Authentication

We've been thinking about API keys all wrong. What if the secret to unbreakable authentication isn't stored anywhere at all?

5 Mind-Bending Truths About SSH Authentication That Will Change How You Think About Security

We've been doing SSH authentication wrong for decades. What if I told you that your SSH keys, password managers, and even your carefully rotated credentials are all solving yesterday's problem?

Forget HR Systems: Why Your Next Identity Provider Should Be a Piece of Plastic

We've spent decades building complex identity pipelines rooted in databases and HR software. What if the single source of truth for your entire infrastructure was something you could hold in your hand?

5 Surprising Lessons from Building a Cross-Cloud Credential Rotator

Managing secrets across one cloud is hard. Managing them across two, synchronously, is a masterclass in distributed systems engineering.

5 Mind-Blowing Insights About Hardware-Backed Authentication That Will Change How You Think About Cloud Security

We've all been there; another leaked API key, another compromised credential, another midnight emergency call. The traditional approach to cloud security—rotating passwords, managing access keys, praying nobody commits secrets to GitHub—feels like fighting a losing battle.

The Password Crisis Nobody Talks About: 5 Surprising Lessons from Hardware-Rooted Cloud Security

We've all been there - juggling AWS access keys, rotating credentials quarterly, and praying that developer laptop that went missing last month didn't have plaintext keys. The conventional wisdom says "use long, complex passwords" and "rotate regularly." But what if the real solution is to eliminate passwords entirely?

Your Security Agent Isn’t Broken—It’s Just Optimizing the Wrong Universe

We've spent decades perfecting code correctness—yet some of the costliest failures come from agents doing exactly what we told them to do.

Righty Tighty: The “Physics-Compliant” Approach to Cross-Cloud Security

We’ve all been there - juggling long-lived AWS access keys, managing OCI config files, and praying that the "secret" API token committed to a private repo three years ago doesn't come back to haunt us. But what if we treated cloud identity less like a password and more like a physical law?

7 Ways zk-Autograd Reimagines Trust in AI Training (One Gradient Step at a Time)

We talk about “trusting” AI models, but almost no one can prove how they were actually trained. zk-Autograd treats every gradient step like a cryptographic contract.

Why Your Next Security Architecture Should Be Ephemeral (and Why We Built It That Way)

We built a signing service that doesn't trust its own keys. Here's why that's the future of security.

How This Architecture Is Defined By the Next Decade of Security

Today’s security tools were built for a world of static infrastructure, predictable threat models, and manual operations. But that world is gone.

7 Ways Mimir Makes LLMs Safe Enough for People Who Don’t Trust Each Other

In most LLM systems, someone has to trust someone else with raw prompts or weights. Mimir shows what happens when nobody is willing to blink.

GPU Budgets, Global Models, and Real-Time Risk Scoring Infra Deep Dive

It’s one thing to train a model in a notebook. It’s another to scale that model across multiple clouds, regions, and time zones—scoring millions of events in near-real-time. Energy-Based Models give you power. But that power has a price - compute, latency, and orchestration at scale.

⚖️ Can You Trust an AI to Contain a Threat? Legal and Privacy Teams Say Maybe

the moment you say “no human in the loop,” the room changes. “Who’s accountable if something goes wrong?” “How do we prove what happened during an audit?” “Can this system violate a user’s privacy policy?” These aren’t just hypothetical questions—they’re the frontline concerns of your legal, privacy, and compliance stakeholders. And if they’re not addressed head-on, your autonomous response system…

🧬 From Static Rules to Self-Improving Response Playbooks

We’ve all seen it. A detection fires, but the response is ineffective. An alert escalates to the wrong channel. A playbook quarantines the wrong asset. Or worse—nothing happens because the logic broke after a cloud migration. Why? Because traditional playbooks are manually written, rarely tested end-to-end, and drift out of sync with reality. But what if they could test themselves? Better yet what…

No Schema? No Problem. Let AI Handle Your Security Data Onboarding

Data is messy. Engineers are busy. And yet, every new application or microservice adds more logs that need to be parsed, structured, and made useful. This used to be a blocker. Not anymore. For years, one of the hidden pain points in detection engineering has been log ingestion and normalization. Most SOC teams rely on detection rules that assume data shows up in a clean, consistent format.

🔁 Build Once. Learn Always. Inside the Autonomous Detection & Response Loop

Let’s be honest—static playbooks aren’t enough anymore. You can’t write a workflow for every edge case. Threats change. Your infrastructure changes. And every incident teaches you something that gets lost in the backlog. But what if your detection and response system actually learned from every incident?

⚡ What Makes Energy-Based Models So Effective for Anomaly Detection?

Traditional detection systems—rules, heuristics, even many ML classifiers—struggle in this gray zone. But energy-based models were built for it.

🧱 Why Security Operations Can’t Scale Without Automation

Security operations centers were never meant to scale like this. What began as centralized log review has ballooned into an arms race of dashboards, SIEM queries, and tier-1 analysts buried in alert queues. Meanwhile, attackers have automated everything from lateral movement to domain privilege escalation.

Embracing the Cyber Age- The Art of Adaptability in Security Engineering

In the dynamic and ever-evolving realm of digital technology, the need for adaptability in combating cyber threats has never been more pronounced.

Securing the Digital Frontier- The Essential Role of Education in Tech Literacy and Security Awareness

In the rapidly evolving digital landscape, where technology deeply permeates every facet of our lives, the importance of tech literacy and security awareness cannot be overstressed.

The Tightrope Walk- Balancing Security Engineering and Privacy in the Tech World

In the rapidly evolving world of technology, a critical and often controversial issue stands at the forefront the balance between robust security measures and the protection of individual privacy rights.

Embracing Decentralization- The Future of Democratic Oversight and Security Engineering

In an era where digital technology is not just a tool but a societal cornerstone, the concepts of democratic oversight in technology and decentralized security models in security engineering are more relevant than ever.