Representative Foreword

After the Code, the Structure Remains

The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.

This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

After the Code, the Structure Remains

Detection, Method, Governance

🔥 A Mind That Dissects Systems

🔥 Trust and Culture Beyond Technology

🔥 Code That Fixes, Not Just Runs

Supply Chain Security Does Not End with SBOM: Governing AI Development Tools and Automation Connections

AI IDEs, MCP, and automation connectors are not merely developer convenience tools. They are supply-chain assets that affect the trust path of how code is written, reviewed, and shipped.

May 2, 2026 · 8 min · 1685 words

Security Assessment Becomes a Development Process, Not an Outsourced Event

AI-era security assessment is not primarily about reducing outsourcing cost. It is about embedding repeatable verification into the development process while separating automation candidates from human judgment.

May 1, 2026 · 10 min · 1927 words

The AI Slop Paradox: Why Triage Gets Harder When Vulnerabilities Get Easier to Find

AI lowers the cost of finding vulnerability candidates, but it also increases low-quality reports, duplicates, and false positives. In the AI slop era, triage quality becomes the core security operation.

April 30, 2026 · 7 min · 1480 words

Why Korean Security Governance Does Not Change

A game-theoretic analysis of why Korean security governance stays stuck when NIS, KISA, the Board of Audit, the security industry, CISOs, and policy agencies are each acting rationally.

April 30, 2026 · 7 min · 1352 words

Beyond CVE Response: AI-Era Vulnerabilities Move Before They Get Numbers

AI-era vulnerability response cannot wait for a CVE number. Pre-CVE signals such as issues, commits, PoCs, write-ups, and patch traces now have to be mapped against internal exposure earlier.

April 29, 2026 · 7 min · 1451 words

Korean Security Governance Is Accelerating in the Wrong Direction in the AI Era

Korean security governance in the AI era needs to change not the title of any one agency, but the behavior that evaluation rewards.

April 26, 2026 · 12 min · 2436 words

Why Security Knowledge Transfer Fails — and What to Design Instead

An organizational design report that reframes the security–DevOps problem from failed knowledge transfer to default design, interfaces, exception handling, and alignment.

April 21, 2026 · 25 min · 5279 words

How I Turned 228 Endpoints into 5 Clusters

A practical account of applying dataflow-based clustering to a real codebase — reducing 228 endpoints to 5 reviewable clusters, and finding an RCE chain in the cross-section.

April 15, 2026 · 17 min · 3431 words

Why Account Takeover Never Ends — Dismantling the ATO Supply Chain

How Korea’s CaaS supply chain reproduces itself through the recycling loop of points, gift cards, and crypto — and why defending against it requires reading the entire behavioral network, not just the login page.

April 7, 2026 · 6 min · 1088 words

Structure Builders Will Outlast Vulnerability Finders

18 years of vulnerability hunting distilled into one insight: the shift from individual instinct to scalable structure — and what AI means for those left standing.

April 2, 2026 · 8 min · 1641 words