New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

Free weekly newsletter

AI Security Intelligence

What actually breaks, and what to do about it.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

One issue every Wednesday. Practitioner-grounded coverage of LLM and agentic security: prompt injection patterns, MCP attack chains, RAG security, OWASP Top 10 for Agentic Applications 2026. Written for engineers and security teams who want to know what's actually breaking, not vendor positioning.

What you'll get

  • One issue per week, every Wednesday. Roughly 600 to 800 words. Reading time: 4 to 6 minutes.
  • Practitioner-led format. Each issue anchors on something I'm actively building or testing myself. News stories appear when they're evidence for a practitioner question, not as the main event.
  • No vendor PR. I don't write about vendors who haven't published something substantive. I don't run sponsored issues.
  • No em dashes. (You'd be surprised how often this is asked.)

Recent issues

[AI Sec Intel] #22 An attacker ran an agent in YOLO mode against a finance ministry. It's the same toggle your developers use

Jul 28, 2026

Researchers caught an autonomous agent enumerating a government network mid-operation, because the attacker left its output directory on the internet.

Read on Beehiiv →

[AI Sec Intel] #21 OpenAI's model breached Hugging Face to win a benchmark

Jul 24, 2026

17,000 actions over a weekend, and the entire containment failure was one allowlisted package proxy.

Read on Beehiiv →

[AI Sec Intel] #20 466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo

Jul 16, 2026

Alberta reviewed 466M lines of code with 50 Claude agents in 20 hours. Two hackers shipped a profitable autonomous hackbot.

Read on Beehiiv →

[AI Sec Intel] #19 One polite word bypassed the guardrails. The private repos leaked anyway

Jul 13, 2026

GitHub's agentic workflows leaked private repos to anyone who could open an issue. An AI agent ran a ransomware attack nearly end to end.

Read on Beehiiv →

Who reads this

  • Engineering leads at companies deploying LLM products
  • Security engineers and architects working on AI features
  • Privacy and compliance professionals tracking the AI Act intersection
  • Researchers and consultants in the AI security space
  • A growing number of subscribers from US enterprise AI vendors as the EU AI Act enforcement approaches

About the author

I'm Amine. I help teams build LLM systems that don't become security incidents. My background is in securing critical systems across regulated industries. More recently I've been deep in how enterprise teams build and deploy LLM-based systems, and where those systems break. That combination is where this newsletter comes from.

More about me →

Working together

When an issue hits close to home

The newsletter is where I write about what's breaking. Molntek is where I help fix it. If one of these issues describes something you're shipping right now — an agent, an MCP integration, a RAG pipeline you're not sure about — that's exactly the work I do at Molntek. No pressure, and subscribing never puts you on a sales list.

Common questions

Is it really free?

Yes. The newsletter is unsponsored and won't move behind a paywall.

How do you handle my email?

Email used to send the newsletter only. Hosted on Beehiiv. No third-party sales. One-click unsubscribe in every issue.

Will I get sales emails?

No. The newsletter list and Molntek client list are separate. If you want to talk to me about consulting work, you contact me. I don't reach into the newsletter list to sell.

What if I want to read past issues?

Public archive at newsletter.aminrj.com. No subscriber gate.

Can I share an issue?

Yes. Forward, post, quote with attribution. The point is reach.

Subscribe

No spam. Unsubscribe with one click in any issue.