Original Research

RedLens Insights

Our own writing on AI security. What our red team actually finds in production systems, what the new standards and advisories really require, and where agentic risk is going next. Researched and written in-house, not aggregated from anywhere.

Published Writing

Read-Only Wasn't: What OpenAI's Wiki Incident Says About the Egress Controls on Your Agents

OpenAI agents bypassed a read-only restriction on a dormant German wiki using GET-based writes and an unvalidated Azure Blob Storage hostname allowlist. What that incident, and OWASP's 2026 Excessive Agency ranking, mean for the egress controls on your own agents.

Read the post →

BAA + Visibility: The Two-Part Test Healthcare AI Teams Keep Skipping

Model evaluation is not HIPAA due diligence. Why every healthcare AI vendor needs a signed BAA and monitored data flow, and how the PHI Egress Scan gives compliance teams a fast, honest first read on what is actually going to each vendor.

Read the post →

MCP Security Is Broken by Default — What the NSA's New Guidance Means for Your AI Agents

Confirmed CVEs, an NSA advisory, and a real supply-chain attack. What actually happened to the Model Context Protocol this year, and what to do about the MCP servers already running in your environment.

Read the post →

More posts as we publish them. Everything above is written here. If you want the industry's own reporting instead of ours, our free Threat Intel feed aggregates it daily from CISA, NIST, OWASP GenAI and the security press, and links every item back to the outlet that published it.

Get New Posts by Email

New posts, straight to your inbox

Original writing on AI security from the people building the platform: agentic risk, red-team findings, and the advisories worth reading in full. A few times a month at most, no sales sequence, and one click to leave.

We use your address for new-post notifications and nothing else. Every email carries an unsubscribe link. See our Privacy Policy.

The Full Picture

Reading about it is step one. Testing for it is step two.

RedLens red-teams the AI systems you've already shipped, then shows you exactly how to close what it finds.