Security field notes
Practical. Proactive. Security.
Field notes on AI, cryptography, and the work of defending real systems. By Matt James.
Written for security practitioners, technical consultants, and small-business leaders.
Subscribe
New writing in your inbox. Free, and you can unsubscribe anytime.
Latest posts
Player-Coach: Why I Still Do the Work
I manage a security team and still do pen tests and threat models. Here's why I think more security leaders should, and what it costs.
We're Still Testing the Wrong Thing: AI Red Teaming in 2026
AI red teaming in 2026 has to test systems, not just models. Here is what changed in nine months and what your program needs to address now.
Where OAuth Goes Wrong in Real APIs: A Step-by-Step Walkthrough
Walking through the OAuth code flow with PKCE step by step, and the validation gaps I keep finding in real APIs at each stage.
Emerging Cybersecurity Trends in 2026
A 2026 retrospective on 2024 security predictions: how AI economics, identity collapse, and quiet compromise replaced the threats we expected.
AI-Driven Social Engineering
How AI-powered social engineering works in 2024: personalization, dynamic adaptation, NLG, and multi-channel attacks, plus what defenders must do differently.
The Evolution from Classical to Post-Quantum Cryptography
Why post-quantum cryptography is the inevitable successor to RSA and ECC, explained through the HTTP-to-HTTPS analogy, with a focus on the transition ahead.