StepToCyber

One Filter Is Not a Safety Strategy: What the Grok Failure Teaches Every Security Leader About AI Safety
Why model-level filters keep failing, what the research says, and what to build instead.
Apr 18 • StepToCyber
Controlled Openings: How Enterprises Should Actually Let AI Crawlers In
A three-tier playbook for Enterprise AI, app owners, and security teams — closed by default, opened deliberately, governed on a cadence.
Apr 11 • StepToCyber
6 Things to Do Before Your AI Coding Agent Runs Another Command
The Claude Code source leak revealed how AI coding agents actually enforce security. The defaults aren't enough
Apr 3 • StepToCyber

March 2026

I Tried to Threat-Hunt with AI. It Forgot What It Was Doing.
Last week, an active supply chain attack called ForceMemo was compromising hundreds of GitHub repositories in real time.
Mar 17 • StepToCyber
That Decommissioned EC2 Instance? Someone Else Owns Your Subdomain Now.
The subdomain takeover variant your monitoring can't see
Mar 9 • StepToCyber
Block the Bots or Feed the Machine? A Security Leader’s Guide to AI Crawlers
Your marketing team is paying OpenAI for visibility. Your security team is blocking OpenAI for protection. Now what?
Mar 1 • StepToCyber
© 2026 StepToCyber · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture