Introducing Briefings: a daily digest of your riskiest AI agents
Book a demo
RESEARCH & BREAKDOWNS

Real AI agent incidents, mapped as attack paths.

We break down how AI agents and non-human identities actually reach production data, using real breaches, step by step.

GuidesFEATURED

AI agents in critical infrastructure: the agent in the control room.

Since February 2026, an AI agent has been running in German grid control rooms. Why NIS2, the EU AI Act and the BSI already apply, without a single new law, and the six measures operators need.

Sascha Buhle·Jul 30, 2026·8 min read
All Research Guides Product Case Study
Guides

Your AI agent caused a security incident. Your NIS2 report is due in 24 hours.

NIS2 does not care that an AI agent caused it. The 24-hour clock runs anyway.

Sascha Buhle·Jul 9, 2026
Guides

MCP security: the complete practical guide for safe AI agents.

Almost every second MCP server is an entry point. The hardening guide.

Sascha Buhle·Jul 9, 2026
Guides

Non-Human Identities: 50 invisible identities per employee.

Machine identities outnumber humans 50:1, and 68% of identity incidents involve them.

Sascha Buhle·Jul 8, 2026
Research

AI agents in critical infrastructure: hype vs. reality 2026.

AI-accelerated attacks on infrastructure are documented reality. Autonomous ones aren’t, yet.

Sascha Buhle·Jul 8, 2026
Research

s1ngularity: the first supply-chain attack that hunts your AI CLIs.

A compromised npm package turned developers’ own AI CLIs into the secret-stealing thief.

Sascha Buhle·Jul 5, 2026
Research

One stolen OAuth token, 700 companies. The Salesloft–Drift breach was a reachability problem.

One token, 700+ orgs, the canonical non-human-identity supply-chain breach.

Sascha Buhle·Jul 5, 2026
Research

JADEPUFFER: the first end-to-end agentic ransomware ran itself.

A fully LLM-driven ransomware operation that ran itself, in 31 seconds.

Sascha Buhle·Jul 5, 2026
Research

An AI agent deleted a production database in 9 seconds. Here’s the exact path.

It wasn’t jailbroken. It found a root API token in an unrelated file and used it.

Sascha Buhle·Jul 5, 2026
NEWSLETTER

Your riskiest agents, in your inbox.

New research and product notes on AI-agent and non-human-identity security. No noise.

elmoz.

Security for the non-human workforce.

Book a demo
Company
Follow us
© 2026 ElmozImpressumDatenschutzCookiesTerms