• +44(0)7855748256
  • bolaogun9@gmail.com
  • London

The BOLA Flaw

The 2026 Lovable security incident represents a defining moment for the “vibe coding” ecosystem. The timeline, root causes, and subsequent fallout highlight the critical tensions between rapid, AI-driven development and traditional security practices. timeline of the incident Technical Analysis of the Vulnerability The Broken Object-Level Authorization (BOLA) Flaw The core vulnerability was a classic Broken Object-Level Authorization (BOLA) flaw. In […]

WARRANT: AI Autonomy Authorisation Gate

Purpose: A meta-framework, a binary, all-or-nothing governance gate that must be satisfied before any AI or automated system is granted execution authority over a production environment, at any level of autonomy. Core principle: Autonomous authority is prohibited by default. A full WARRANT lifts that prohibition. A WARRANT must be earned, not assumed. Not a maturity model. No partial credit. All […]

What the night before Challenger launched teaches DevSecOps engineers about organisational silence

On the evening of 27 January 1986, Roger Boisjoly spread his data across a table in a teleconference room at Morton Thiokol and made his case. The O-rings that sealed the joints of Challenger’s solid rocket boosters had never been tested below 53°F. The forecast for the next morning: 29°F. The correlation between cold and O-ring damage was unmistakable in […]

The infrastructure ratchet: What Web3 teaches AI builders about the coming control stack

On 8 August 2022, the US Treasury sanctioned Tornado Cash. Not its founders. Not its users. The code itself. Forty-four Ethereum smart contract addresses were placed on the OFAC Specially Designated Nationals list, alongside arms dealers and sanctioned regimes. Within hours, Infura and Alchemy cut off API access. Circle blacklisted USDC held inside the contracts. GitHub suspended the repository and […]

Open Agent Provenance (OAP)

Version: 0.1 (draft) Status: Draft for comment. Not a finished standard. Published: 2026-06-30 Predicate type URI: https://oap.dev/RunRecord/v0.1 (illustrative) Licence: intended for an open, vendor-neutral licence (Apache 2.0 or CC BY 4.0) v0.1 is a starting point. The field set and conformance rules will move as producers and consumers appear and as we learn what auditors and agents actually need. Backward-compatible […]

The Leak Already Happened. Will Anthropic Waste the Best Free Code Audit in AI History?

On March 31, Anthropic shipped a source map file to npm. Not a minor config snippet. Not a stale API key. 512,000 lines of TypeScript. 1,900 files. 44 hidden feature flags. Their entire agentic harness. The crown jewels of Claude Code. Reconstructed and forked 82,000+ times before lunch. Anthropic scrambled. They pulled the npm package. Filed DMCA takedowns against GitHub […]