The latest in Playbook
Semantic Kernel, CrewAI, and Claude Code shipped bugs this spring that turn prompt injection into remote code execution. The framework is the attack surface.
Intruder scanned a million AI services in May 2026. 31% of Ollama servers answered with no auth, plus open agent workflows in finance and government.
A backdoored Nx Console extension gave attackers a foothold inside GitHub on May 19. Worm-style spread, CI/CD credentials, 11-minute detection window. The boring hygiene fixes every Copilot/Cursor team owes itself.
Google saw a 32% jump in malicious indirect prompt injection between Nov 2025 and Feb 2026. White-text payloads, font-mapping tricks, and the lethal trifecta — the short version.
Pair programming was two humans at one workstation. The pit crew model is one senior engineer running multiple parallel workstreams with scoped tooling — and a named human reviewer on every merge.
CFOs are asking why a custom vertical AI agent costs less than a human SDR. Here is the six-week build, the math behind FTE-replacement pricing, and where it breaks.