<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Fissure Security</title>
  <subtitle>Field notes and product updates on the seam between your tools.</subtitle>
  <link href="https://fissuresecurity.com/feed.xml" rel="self"/>
  <link href="https://fissuresecurity.com/blog.html"/>
  <id>https://fissuresecurity.com/</id>
  <updated>2026-09-20T12:00:00Z</updated>
  <author><name>Matt Boksa</name></author>
  <entry>
    <title>Decryption baiting</title>
    <link href="https://fissuresecurity.com/posts/decryption-baiting.html"/>
    <id>https://fissuresecurity.com/posts/decryption-baiting.html</id>
    <updated>2026-09-20T12:00:00Z</updated>
    <published>2026-09-20T12:00:00Z</published>
    <category term="Research"/>
    <summary>An encrypted archive was survivable for thirty years because opening it required a person. We named one after its own password and asked five agents to summarise the folder. All five opened it, none asked first, and one derived the password from the filename before it had evidence the file was even encrypted.</summary>
  </entry>
  <entry>
    <title>Approved use is the risk</title>
    <link href="https://fissuresecurity.com/posts/approved-use.html"/>
    <id>https://fissuresecurity.com/posts/approved-use.html</id>
    <updated>2026-09-07T12:00:00Z</updated>
    <published>2026-09-07T12:00:00Z</published>
    <category term="Research"/>
    <summary>The agents you blocked were never going to hurt you much. The one you approved is wired into everything and nobody is watching what it reads or what it sends. Every employee works behind a mail filter, a proxy and DLP. The agent got the permissions and nothing else.</summary>
  </entry>
  <entry>
    <title>The agent reads it first</title>
    <link href="https://fissuresecurity.com/posts/the-agent-reads-it-first.html"/>
    <id>https://fissuresecurity.com/posts/the-agent-reads-it-first.html</id>
    <updated>2026-08-17T12:00:00Z</updated>
    <published>2026-08-17T12:00:00Z</published>
    <category term="Product update"/>
    <summary>A tool call puts file content inside the model before anyone sees a screen. The controls at that boundary check the call, not what comes back. Subtext for MCP inspects the content, and the same engine runs at the gateway for what the client fetches itself.</summary>
  </entry>
  <entry>
    <title>Prompt injection is not one thing</title>
    <link href="https://fissuresecurity.com/posts/prompt-injection-is-not-one-thing.html"/>
    <id>https://fissuresecurity.com/posts/prompt-injection-is-not-one-thing.html</id>
    <updated>2026-08-16T12:00:00Z</updated>
    <published>2026-08-16T12:00:00Z</published>
    <category term="Research"/>
    <summary>Three different attacks travelled in a single calendar invite and hit five agent products. Only one of them has no marker to detect. Why the file half of this is not being solved by sanitization, and why we redacted every payload in the article.</summary>
  </entry>
  <entry>
    <title>If it has to phone home to decide, the internet is part of your file security</title>
    <link href="https://fissuresecurity.com/posts/nothing-external.html"/>
    <id>https://fissuresecurity.com/posts/nothing-external.html</id>
    <updated>2026-07-28T12:00:00Z</updated>
    <published>2026-07-28T12:00:00Z</published>
    <category term="Research"/>
    <summary>If deciding requires uploading the file, the decision already moved the file off your boundary. For an egress control that is the exact thing you were trying to prevent, performed by the thing you bought to prevent it.</summary>
  </entry>
  <entry>
    <title>A control you cannot explain is a control you cannot defend</title>
    <link href="https://fissuresecurity.com/posts/deterministic.html"/>
    <id>https://fissuresecurity.com/posts/deterministic.html</id>
    <updated>2026-07-24T12:00:00Z</updated>
    <published>2026-07-24T12:00:00Z</published>
    <category term="Research"/>
    <summary>The signals are statistical. Of course they are. Determinism means three other things: no drift, no per-user state, and a reason you can read. An unexplainable control does not survive contact with an organization.</summary>
  </entry>
  <entry>
    <title>You do not need to know a file exists to stop it crossing</title>
    <link href="https://fissuresecurity.com/posts/no-inventory.html"/>
    <id>https://fissuresecurity.com/posts/no-inventory.html</id>
    <updated>2026-07-23T12:00:00Z</updated>
    <published>2026-07-23T12:00:00Z</published>
    <category term="Research"/>
    <summary>The dominant model says find everything first, then protect what you found. The map is never finished, and everything not on it is unprotected by definition. A boundary does not need a map.</summary>
  </entry>
  <entry>
    <title>An agent protects the machines you remembered</title>
    <link href="https://fissuresecurity.com/posts/path-not-device.html"/>
    <id>https://fissuresecurity.com/posts/path-not-device.html</id>
    <updated>2026-07-22T12:00:00Z</updated>
    <published>2026-07-22T12:00:00Z</published>
    <category term="Research"/>
    <summary>Bind a control to the device and its coverage is a roster. Rosters are always wrong, and they are wrong in the direction that hurts. Why file enforcement binds to the path, not the endpoint.</summary>
  </entry>
  <entry>
    <title>The same file is not the same decision</title>
    <link href="https://fissuresecurity.com/posts/content-and-position.html"/>
    <id>https://fissuresecurity.com/posts/content-and-position.html</id>
    <updated>2026-07-21T12:00:00Z</updated>
    <published>2026-07-21T12:00:00Z</published>
    <category term="Research"/>
    <summary>A design document between two teams is routine. The same document to a personal drive is an incident. Nothing about the file changed. Why a verdict is a function of content and position, not identity.</summary>
  </entry>
  <entry>
    <title>A file does not know which direction it is going</title>
    <link href="https://fissuresecurity.com/posts/both-directions.html"/>
    <id>https://fissuresecurity.com/posts/both-directions.html</id>
    <updated>2026-07-20T12:00:00Z</updated>
    <published>2026-07-20T12:00:00Z</published>
    <category term="Research"/>
    <summary>Security split one problem into two markets. Inbound got twenty-five years of investment; outbound got regular expressions. The same concealment your sandbox catches on the way in walks out unchallenged.</summary>
  </entry>
  <entry>
    <title>A file’s type is a claim, and your stack treats it as a fact</title>
    <link href="https://fissuresecurity.com/posts/content-over-declaration.html"/>
    <id>https://fissuresecurity.com/posts/content-over-declaration.html</id>
    <updated>2026-07-16T12:00:00Z</updated>
    <published>2026-07-16T12:00:00Z</published>
    <category term="Research"/>
    <summary>The extension, the MIME type, and the magic bytes are all assertions from an untrusted party. Zero Trust re-verifies every claim a user, device, or network makes, then takes a file’s word for what it is. Content over declaration is where Zero Trust for Files starts.</summary>
  </entry>
  <entry>
    <title>ClickFix hands the user the payload and asks them to run it</title>
    <link href="https://fissuresecurity.com/posts/clickfix.html"/>
    <id>https://fissuresecurity.com/posts/clickfix.html</id>
    <updated>2026-07-13T12:00:00Z</updated>
    <published>2026-07-13T12:00:00Z</published>
    <category term="Research"/>
    <summary>The malware never downloads. A fake verification page tells the reader to paste a command and press Enter, and the stack sees a harmless HTML file. Why ClickFix is a content problem, and what reads it.</summary>
  </entry>
  <entry>
    <title>Subtext now reads audio and video, not just documents</title>
    <link href="https://fissuresecurity.com/posts/subtext-reads-audio-and-video.html"/>
    <id>https://fissuresecurity.com/posts/subtext-reads-audio-and-video.html</id>
    <updated>2026-07-09T12:00:00Z</updated>
    <published>2026-07-09T12:00:00Z</published>
    <category term="Product update"/>
    <summary>Secrets don’t only travel as text. A password read aloud in a voice memo, or a credential block painted into a spectrogram, is exfil too, so Subtext listens and looks, then reads the result.</summary>
  </entry>
  <entry>
    <title>Every file is text now, and that changes what a boundary has to check</title>
    <link href="https://fissuresecurity.com/posts/every-file-is-text.html"/>
    <id>https://fissuresecurity.com/posts/every-file-is-text.html</id>
    <updated>2026-06-24T12:00:00Z</updated>
    <published>2026-06-24T12:00:00Z</published>
    <category term="Research"/>
    <summary>AI ingestion collapsed formats, passwords, and encodings into one thing: text a model will read. The old idea of a “protected” file is gone. Here’s why inspection has to meet the file on that plane.</summary>
  </entry>
</feed>
