Recent
- Research noteNX-2026-0146
Authorisation that survives injection
A gap analysis of six MCP software development kits finds authorisation primitives that assume the agent has not been steered by an attacker.
3 minSource: arXiv
- Field reportNX-2026-0145
The safety layer that blocked the cleanup
A prompt injection researcher reports an 80% success rate against a coding agent's automatic mode — and cases where the guard stopped the agent fixing it.
3 minSource: Simon Willison
- AnalysisNX-2026-0144
The defender was the one with rules
Hugging Face says guardrails on hosted models blocked its own forensics, so it ran an open-weight model on its own hardware instead.
SpansAISECFIN
3 minSource: Cointelegraph Magazine
- News briefNX-2026-0143
AI-written exploits aimed at PLCs
An NSA and FBI advisory describes exploitation scripts built with AI assistance and disguised as monitoring tools, targeting Siemens S7 controllers.
SpansAISECFIN
2 minSource: The Record
- Research noteNX-2026-0142
Verifiable inference is the piece that joins all three
A model that can prove what it computed lets a machine be paid for the result. That single capability closes the loop.
SpansAISECFIN
11 min
- AnalysisNX-2026-0136
Model supply chains need the provenance work software already did
Signed artefacts, attested builds, pinned hashes — none of it is new, and almost none of it is applied here.
SpansAISECFIN
7 min
- AnalysisNX-2026-0129
Agents holding keys is a governance problem, not a crypto one
The question is not whether a model can sign. It is who is accountable when it does.
SpansAISECFIN
9 min
- Field reportNX-2026-0122
Compute markets need settlement and attestation together
Either half alone produces a market nobody serious will use.
SpansAISECFIN
8 min