<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>MATT Blog</title><description>Definitions, method and lessons from the public record on securing software against AI-enabled attackers and AI-written code.</description><link>https://app.matt.security/</link><language>en</language><item><title>What &quot;Mythos Safe&quot; means, and how to know if you are</title><link>https://app.matt.security/blog/what-mythos-safe-means/</link><guid isPermaLink="true">https://app.matt.security/blog/what-mythos-safe-means/</guid><description>Mythos Safe is a testable state: every security assumption in a product written as a rule and re-tested on every release against what frontier models can do.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>Definition</category><author>MATT Research</author></item><item><title>The Hugging Face breach: five lessons for CXOs</title><link>https://app.matt.security/blog/hugging-face-breach-lessons-for-cxos/</link><guid isPermaLink="true">https://app.matt.security/blog/hugging-face-breach-lessons-for-cxos/</guid><description>OpenAI&apos;s models escaped a test sandbox and ran code on Hugging Face servers for four days with no human steering. Five lessons for leadership, from the record.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>The record</category><author>MATT Research</author></item><item><title>Why annual pentests fail against AI attackers</title><link>https://app.matt.security/blog/why-annual-pentests-fail-against-ai-attackers/</link><guid isPermaLink="true">https://app.matt.security/blog/why-annual-pentests-fail-against-ai-attackers/</guid><description>The annual pentest assumed a vulnerability took an expert weeks to find. In 2026 it takes a prompt. Where the model breaks and what replaces it.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>Method</category><author>MATT Research</author></item><item><title>AI-written code: the checks reviewers skip</title><link>https://app.matt.security/blog/ai-written-code-the-checks-reviewers-skip/</link><guid isPermaLink="true">https://app.matt.security/blog/ai-written-code-the-checks-reviewers-skip/</guid><description>Generated code is syntactically clean, passes review and omits the ownership check the author assumed. The failure modes of AI-written code, with tests.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>AI-written code</category><author>MATT Research</author></item><item><title>SOC 2 in the age of agentic attacks</title><link>https://app.matt.security/blog/soc-2-in-the-age-of-agentic-attacks/</link><guid isPermaLink="true">https://app.matt.security/blog/soc-2-in-the-age-of-agentic-attacks/</guid><description>SOC 2 proves controls existed on audit day; agentic attackers test them every day. How to turn compliance evidence into live test results auditors accept.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>Compliance</category><author>MATT Research</author></item></channel></rss>