Gateway notes

Runtime security, CRA-ready logs, and spend attribution for AI agents in your network. Remediation is a scoped Finding → Fix Spec → PR engagement when you need it.

CRA Annex I Part II: Vulnerability Handling Evidence Checklist

Annex I Part II is vulnerability handling (intake, SBOM, triage, remediation, disclosure) — not Article 14 reporting. Checklist for evidence that usually holds up; main obligations from 11 December 2027.

Kamal Srinivasan

CRA Annex I Part II: Vulnerability Handling Evidence Checklist

Annex I Part II is vulnerability handling (intake, SBOM, triage, remediation, disclosure) — not Article 14 reporting. Checklist for evidence that usually holds up; main obligations from 11 December 2027.

Kamal Srinivasan

CRA Annex I Part II: Vulnerability Handling Evidence Checklist

Annex I Part II is vulnerability handling (intake, SBOM, triage, remediation, disclosure) — not Article 14 reporting. Checklist for evidence that usually holds up; main obligations from 11 December 2027.

Kamal Srinivasan

CRA Article 14: The 24 / 72 / Final Reporting Clocks

CRA Article 14 is reporting — early warning in 24 hours, fuller notification in 72 hours, then a final report — via ENISA’s Single Reporting Platform. Not the Annex I vulnerability-handling checklist.

Kamal Srinivasan
Why Security Engineers Can’t Keep Up With CVEs — and It’s Not a Detection Problem

Why Security Engineers Can’t Keep Up With CVEs — and It’s Not a Detection Problem

Security teams aren’t failing at detection — they’re failing at remediation. With tens of thousands of CVEs published each year and nearly half remaining unpatched, the real challenge is fixing vulnerabilities without breaking production. This post explains why CVE backlogs persist, why developers push back on fixes, and why security engineering needs intent-aware remediation to scale.

Kamal Srinivasan
Security Engineers are the bridge between CTO and CISO

Security Engineers are the bridge between CTO and CISO

As "Vibe Coding" (AI-generated code) accelerates development, a "security-functionality gap" has emerged. Research shows that while AI agents solve 61% of functional tasks, only 10% of those fixes are secure. Unitone addresses this by providing the system-wide context needed for safe, architectural remediation.

Kamal Srinivasan
Developer laptop acting as AI runtime infrastructure using MCP, connecting private code and data to external AI models

The Fastest-Growing Attack Surface Lives on Developer Laptops

Developer laptops have quietly become runtime infrastructure. MCP turns local machines into service planes that broker access between external models and sensitive internal context — source code, configs, credentials, and APIs. Most enterprise security tools still see this as normal developer activity. It isn’t. It’s the fastest-growing attack surface in the enterprise, and it’s largely invisible today.

Kamal Srinivasan
When AI Turns From Leverage Into Chaos: The New Reality for CTOs

When AI Turns From Leverage Into Chaos: The New Reality for CTOs

AI is introducing a shadow layer in your stack. Engineering and security teams are grappling with it already. Today the reality is easier to deal with given that most agents are in experiments, but when they turn to production we will hit an issue. CTOs need to be aware of the agents and the applications they are introducing into their environments.

Kamal Srinivasan
Abstract digital lock made of circuit lines and AI elements on a dark background, symbolizing secure MCP deployments.

Securing Your Model Context Protocol: Top Vulnerabilities and How to Build Enterprise‑Ready MCPs

An enterprise‑grade primer on MCP security that covers Adversa’s Top 25 vulnerabilities, best practices for securing MCP servers and clients, and how UNITONE’s MCP Builder helps you build secure, performant servers.

Kamal Srinivasan
The Great Control Shift: Why AI Agents Break 30-years of security assumptions

The Great Control Shift: Why AI Agents Break 30-years of security assumptions

Three critical questions every CISO must answer about AI agents. Traditional security assumes users and sessions—agents break all those assumptions.

Kamal Srinivasan