The Agent Identity Problem: Why OAuth Isn't Enough for MCP

When an AI agent calls a tool, three principals are involved but only one has an identity. OAuth authenticates the user — but not the agent’s intent. Here’s what enterprise auth architecture for MCP actually needs, and how to build toward it without waiting for the ecosystem to figure it out.

July 31, 2026 · 8 min · Matt Konda

The MCP Attack Surface: What Security Teams Are Missing

MCP flips a traditional security assumption — the callee can influence the caller. That’s what makes it powerful, and it’s what your security team needs to understand. A practical catalog of the attack surfaces that matter, with mitigations that don’t slow teams down.

July 24, 2026 · 9 min · Matt Konda

Threat Modeling MCP: 6 Trust Boundaries Your Security Team Should Map

MCP is the right bet for connecting AI agents to enterprise tools. But deploying it well means understanding the trust boundaries. I applied STRIDE to the protocol end-to-end — here’s what to focus on so your team can move fast without getting burned.

July 17, 2026 · 9 min · Matt Konda

WebAssembly Security: Same Sandbox, New Risks

I built 30 security probes in Rust/WASM to test what WebAssembly can actually do in a browser. The sandbox is the same one JavaScript lives in — but the binary format creates real analysis gaps. And with WASI taking WASM beyond the browser into containers, edge, and serverless, the security surface is expanding fast.

July 13, 2026 · 10 min · Matt Konda

The Quantum Threat Is Not Theoretical

Most quantum security conversations stop at ‘someday.’ After five years inside a quantum computing company, I can tell you exactly what’s vulnerable, when, and what to do about it.

July 7, 2026 · 3 min · Matt Konda

AI Security: Separating What's Real from What's Marketing

Everyone is selling AI security. Most of it is repackaged application security with a new label. Here’s what actually matters when securing AI systems — and using AI to secure yours.

July 3, 2026 · 4 min · Matt Konda

Security Culture Eats Policy for Breakfast

You can write perfect security policies and still have a terrible security posture. What actually changes behavior is culture — and culture comes from how security leaders show up.

July 1, 2026 · 4 min · Matt Konda