• +44(0)7855748256
  • bolaogun9@gmail.com
  • London

The BOLA Flaw

The 2026 Lovable security incident represents a defining moment for the “vibe coding” ecosystem. The timeline, root causes, and subsequent fallout highlight the critical tensions between rapid, AI-driven development and traditional security practices. timeline of the incident Technical Analysis of the Vulnerability The Broken Object-Level Authorization (BOLA) Flaw The core vulnerability was a classic Broken Object-Level Authorization (BOLA) flaw. In […]

WARRANT: AI Autonomy Authorisation Gate

Purpose: A meta-framework, a binary, all-or-nothing governance gate that must be satisfied before any AI or automated system is granted execution authority over a production environment, at any level of autonomy. Core principle: Autonomous authority is prohibited by default. A full WARRANT lifts that prohibition. A WARRANT must be earned, not assumed. Not a maturity model. No partial credit. All […]

What the night before Challenger launched teaches DevSecOps engineers about organisational silence

On the evening of 27 January 1986, Roger Boisjoly spread his data across a table in a teleconference room at Morton Thiokol and made his case. The O-rings that sealed the joints of Challenger’s solid rocket boosters had never been tested below 53°F. The forecast for the next morning: 29°F. The correlation between cold and O-ring damage was unmistakable in […]

The SIGNAL Framework

A Practitioner’s Reference for Warning Lifecycle Management in Platform Engineering Version: 1.0Author: Bola OgunlanaClassification: Original framework, Cockpit to Cloud seriesOrigin: Derived from post-mortem analysis of the 1995 Sampoong Department Store collapse, mapped to persistent warning failure modes in cloud and platform engineering operations What SIGNAL Is SIGNAL is a 6-principle operational framework for managing persistent warnings in platform engineering, DevSecOps, […]

The infrastructure ratchet: What Web3 teaches AI builders about the coming control stack

On 8 August 2022, the US Treasury sanctioned Tornado Cash. Not its founders. Not its users. The code itself. Forty-four Ethereum smart contract addresses were placed on the OFAC Specially Designated Nationals list, alongside arms dealers and sanctioned regimes. Within hours, Infura and Alchemy cut off API access. Circle blacklisted USDC held inside the contracts. GitHub suspended the repository and […]

Open Agent Provenance (OAP)

Version: 0.1 (draft) Status: Draft for comment. Not a finished standard. Published: 2026-06-30 Predicate type URI: https://oap.dev/RunRecord/v0.1 (illustrative) Licence: intended for an open, vendor-neutral licence (Apache 2.0 or CC BY 4.0) v0.1 is a starting point. The field set and conformance rules will move as producers and consumers appear and as we learn what auditors and agents actually need. Backward-compatible […]

Claude said no. Forty minutes later, it was writing live exploits against Mexico’s federal tax authority

The prompt came in Spanish. Claude processed it and refused. “Specific instructions about deleting logs and hiding history are red flags,” the model said. The session had barely started. The pushback was unambiguous. Most sessions end there. This one didn’t. Over the next 40 minutes, the operator rephrased the request, rebuilt the context, and loaded a persistent configuration file: a […]

Operating Cloud Infrastructure at the Speed of Intent: The 90-Day Agentic Shift

For the past decade, the holy grail of DevOps and platform engineering has been automation. We wrote bash scripts, compiled complex Jenkins pipelines, and eventually moved toward declarative states with Terraform or OpenTofu. Yet, even with Infrastructure as Code (IaC), a structural bottleneck remained: the human. Engineers still manually analyse logs, approve PRs, triage alerts, and decide when to scale […]