Blog
The Loop
Closing the loop on security. Research, perspectives, and field notes on where security is heading - from emerging threats to the ideas closing the gap between finding issues and solving them.

Cantina CEO Hari Mulackal on the Fable Pull: The Only Clock You Control Is How Fast You Fix
News
Read more 
After TrustLaunder: Apex's Other Four Pathling Findings
Research
Read more 
TrustLaunder: How a Healthcare FHIR Server Turned Attacker URLs Into Trusted Patient Data
Research
Read more 
What we learned hunting for bugs in over 1500 codebases with AI
Research
Read more 
Cantina Threat Discovery: swift-crypto X-Wing HPKE Overread
Research
Read more 
Cantina Threat Discovery: Race Condition in Ruby Core
Research
Read more 
Where AI-Generated Code Quietly Fails: A Field Note on False Negatives
Security
Read more 
When AI Writes Half Your Code, Shift-Left Becomes a Volume Problem
Security
Read more 
How One VS Code Extension Took Down ~3,800 GitHub Internal Repos
News
Read more 
Cantina x Swif: iOS 26.5 Security Guide, 2026's Biggest Apple Patch Cycle
Security
Read more 
Translating AI Agent Policy Into Runtime Control: A Working Map
Security
Read more 
What Four CVEs in Fourteen Days Tell Us About AI Infrastructure Risk
Security
Read more 
When a Linux networking flaw lets a local foothold turn into root across major distros
Security
Read more 
The FBI's Cargo-Theft Alert Shows How Load-Board Fraud Becomes Freight Loss
Security
Read more 
Apex Found a 13-Year-Old Bug in WebKit. Apple Patched It Yesterday.
Research
Read more 
AI Agent Governance Is Moving From Policy to Runtime Control
Security
Read more 
When prompt injection turns an AI agent framework into host-level code execution
Security
Read more 
Federal PLC Exploitation Is Turning Exposed Controllers Into Plant Disruption
Security
Read more 
Authorization Bypass in Spring Security 7: XML <intercept-url> Drops servlet-path When Building Path Matchers
Security
Read more 
Why Current Evidence Matters in Incident Response
Security
Read more 
When the Security Tool Becomes the Attack Path
Security
Read more 
When a Git helper inside automation becomes a remote-execution path
Security
Read more 
One Security OS, Now Plugged Into EDR and MDM: Cantina Partners with CrowdStrike and Swif.
Product
Read more 
Healthtech AI Security: What to Control Before You Ship
Security
Read more 
Your Security Stack Doubled. Coverage Stayed Flat.
Security
Read more 
Your Annual SOC 2 Audit Proves Nothing About Your Security Today
Security
Read more 
13 Years of RCE in Apache ActiveMQ: What CVE-2026-34197 Reveals About Your Blind Spots
Security
Read more 
Can Your Security Platform Show Who the Agent Was Acting On Behalf Of?
Security
Read more 
Bitwarden’s npm Incident Was a Publish-Path Compromise
News
Read more 
When Checkpoints Turn Into Code Execution: How Apex Would Unwind LangGraph's Deserialization Trap
Security
Read more 
Healthtech Integration Risk: Where PHI Exposure Becomes Operational Risk
Security
Read more 
How Production Context Changes Which Security Alerts Matter First
Security
Read more 
How Auto-Approve Changes the Control Boundary for Coding Agents
Security
Read more 
Cantina Threat Advisory: How Anthropic’s MCP stdio Model Turns Configuration into Code Execution
Security
Read more 
How to Catch Secret Leaks in AI Coding Workflows Before Commit
Security
Read more 
Vercel’s April 2026 Incident Was an OAuth-to-Control-Plane Breach
Read more
Healthtech Security in 2026: Continuity Is the New Standard
Security
Read more 
Cantina Case Study: Apex Finds 44-Year-Old Bugs in OpenSSH
Research
Read more 
How to Prevent Vibe Coding Vulnerabilities in Software Development
Security
Read more 
AI Agent Governance Readiness Guide
Security
Read more 
AI Act Transparency Starts August 2, 2026: What AI-Powered SaaS Teams Need to Change Now
News
Read more 
MCP Security Checklist: How to Govern Tool Access Before Your AI Agents Do Something Expensive
Security
Read more 
How One Compromised GitHub Action Leaked Thousands of Cloud Secrets
News
Read more 
Cantina: Unified Security and Compliance for AI-Powered SaaS
Product
Read more 
Cantina Case Study: SpEL Injection in Spring AI Explained
Research
Read more 
The Hidden Tax of Tool Sprawl: Why Your 50-Tool Security Stack is Failing You
Security
Read more 
Cantina Case Study: Catching a 15-Year-Old Dependency Bug Before Attackers Did
Research
Read more 
Axios NPM Supply Chain Attack: What Happened
News
Read more 
Defending Against FortiClient EMS Pre-Auth SQLi with Agentic Security
Security
Read more 
Cantina Case Study: How Apex found a high-severity bug in Spring AI
Research
Read more 
Cantina Case Study: How Apex Found a Critical RCE Bug in Spring AI
Research
Read more 
Cantina Case Study: How Apex Found a Silent Privilege Escalation in Anthropic's Claude Code
Research
Read more 
LiteLLM Turned a Package Install Into an Intrusion Path
Security
Read more 
AI security: Best solutions for cyber teams 2026 guide
Security
Read more 
The SOC Analyst Role Is Broken. Here’s How Agentic AI Fixes It.
Product
Read more 
Securing AI Agents: 5 Rules to Stop Autonomous Takeovers
Security
Read more