Fissure Security · Blog

Field notes & product updates.

What we’re shipping, and what we’re learning about the seams attackers use. Short, technical, and written for people who defend real systems.

Research Decryption baiting An encrypted archive was survivable for thirty years because opening it required a person. We named one after its own password and asked five agents to summarise the folder. All five opened it, none asked first, and one derived the password from the filename before it had evidence the file was even encrypted.
Sep 20, 2026
Research Approved use is the risk The agents you blocked were never going to hurt you much. The one you approved is wired into everything and nobody is watching what it reads or what it sends. Every employee works behind a mail filter, a proxy and DLP. The agent got the permissions and nothing else.
Sep 7, 2026
Product update The agent reads it first A tool call puts file content inside the model before anyone sees a screen. The controls at that boundary check the call, not what comes back. Subtext for MCP inspects the content, and the same engine runs at the gateway for what the client fetches itself.
Aug 17, 2026
Research Prompt injection is not one thing Three different attacks travelled in a single calendar invite and hit five agent products. Only one of them has no marker to detect. Why the file half of this is not being solved by sanitization, and why we redacted every payload in the article.
Aug 16, 2026
Research If it has to phone home to decide, the internet is part of your file security If deciding requires uploading the file, the decision already moved the file off your boundary. For an egress control that is the exact thing you were trying to prevent, performed by the thing you bought to prevent it.
Jul 28, 2026
Research A control you cannot explain is a control you cannot defend The signals are statistical. Of course they are. Determinism means three other things: no drift, no per-user state, and a reason you can read. An unexplainable control does not survive contact with an organization.
Jul 24, 2026
Research You do not need to know a file exists to stop it crossing The dominant model says find everything first, then protect what you found. The map is never finished, and everything not on it is unprotected by definition. A boundary does not need a map.
Jul 23, 2026
Research An agent protects the machines you remembered Bind a control to the device and its coverage is a roster. Rosters are always wrong, and they are wrong in the direction that hurts. Why file enforcement binds to the path, not the endpoint.
Jul 22, 2026
Research The same file is not the same decision A design document between two teams is routine. The same document to a personal drive is an incident. Nothing about the file changed. Why a verdict is a function of content and position, not identity.
Jul 21, 2026
Research A file does not know which direction it is going Security split one problem into two markets. Inbound got twenty-five years of investment; outbound got regular expressions. The same concealment your sandbox catches on the way in walks out unchallenged.
Jul 20, 2026
Research A file’s type is a claim, and your stack treats it as a fact The extension, the MIME type, and the magic bytes are all assertions from an untrusted party. Zero Trust re-verifies every claim a user, device, or network makes, then takes a file’s word for what it is. Content over declaration is where Zero Trust for Files starts.
Jul 16, 2026
Research ClickFix hands the user the payload and asks them to run it The malware never downloads. A fake verification page tells the reader to paste a command and press Enter, and the stack sees a harmless HTML file. Why ClickFix is a content problem, and what reads it.
Jul 13, 2026
Product update Subtext now reads audio and video, not just documents Secrets don’t only travel as text. A password read aloud in a voice memo, or a credential block painted into a spectrogram, is exfil too, so Subtext listens and looks, then reads the result.
Jul 9, 2026
Research Every file is text now, and that changes what a boundary has to check AI ingestion collapsed formats, passwords, and encodings into one thing: text a model will read. The old idea of a “protected” file is gone. Here’s why inspection has to meet the file on that plane.
Jun 24, 2026