WebAssembly Security: Same Sandbox, New Risks

I built 30 security probes in Rust/WASM to test what WebAssembly can actually do in a browser. The sandbox is the same one JavaScript lives in — but the binary format creates real analysis gaps. And with WASI taking WASM beyond the browser into containers, edge, and serverless, the security surface is expanding fast.

July 13, 2026 · 10 min · Matt Konda

The Quantum Threat Is Not Theoretical

Most quantum security conversations stop at ‘someday.’ After five years inside a quantum computing company, I can tell you exactly what’s vulnerable, when, and what to do about it.

July 7, 2026 · 3 min · Matt Konda

AI Security: Separating What's Real from What's Marketing

Everyone is selling AI security. Most of it is repackaged application security with a new label. Here’s what actually matters when securing AI systems — and using AI to secure yours.

July 3, 2026 · 4 min · Matt Konda

Security Culture Eats Policy for Breakfast

You can write perfect security policies and still have a terrible security posture. What actually changes behavior is culture — and culture comes from how security leaders show up.

July 1, 2026 · 4 min · Matt Konda