-
The Bug That Behaved Perfectly: Why Agentic Apps Are So Hard to Debug
A framework migration left DepsRAG with a redundant orchestrator that was never invoked—yet every answer stayed correct. When a bug produces no symptoms, debugging needs to look at structure, not just behavior.
-
Agentic AI and the Software Supply Chain: New Frontiers, Old Vulnerabilities
As AI agents gain autonomy, the software supply chain faces unprecedented challenges—from context management to dynamically loaded dependencies.
-
Reviewing at S&P 2026: Papers, Patterns, and Lessons
20 papers, 2 acceptances, and a lot to learn about what separates accepted security research from rejected work.
-
From VEX to Critical Bug: How a Single Normalization Mismatch Breaks Supply Chain Trust
A subtle normalization mismatch inside an SBOM tool can break dependency relationships even when all packages are detected correctly.