<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss-styles.xsl" type="text/xsl"?><rss version="2.0"><channel><title>Joseph Manzambi · Writing</title><description>Essays and notes on AI security.</description><link>https://www.manzambi.com/</link><item><title>Your Security Scanner Is a Supply Chain Too</title><link>https://www.manzambi.com/writing/your-security-scanner-is-a-supply-chain-too/</link><guid isPermaLink="true">https://www.manzambi.com/writing/your-security-scanner-is-a-supply-chain-too/</guid><description>A post-mortem. The MCP scanner in my local red-team pipeline was defeated by a supply-chain problem, the exact class of risk security tooling exists to catch. One word, two package ecosystems, an acquisition, and weeks of quiet false confidence.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The EU AI Act Delay Is Not Relief</title><link>https://www.manzambi.com/writing/eu-ai-act-delay-is-not-relief/</link><guid isPermaLink="true">https://www.manzambi.com/writing/eu-ai-act-delay-is-not-relief/</guid><description>The Omnibus is set to push standalone high-risk enforcement to December 2027. Every law firm called it relief. Having built the blueprint, I read it as a deadline for a multi-quarter engineering programme — and the clock starts now.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Red-Teaming an LLM on Your Own Laptop: What Actually Breaks</title><link>https://www.manzambi.com/writing/local-redteaming-field-report/</link><guid isPermaLink="true">https://www.manzambi.com/writing/local-redteaming-field-report/</guid><description>A field report from building a fully-local, three-layer AI red-team pipeline on an Apple-silicon laptop: 28 fixes, a two-model nightly run, and the honest gap between a local &apos;pass&apos; and an actual security verdict.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Protocol Will Not Save You</title><link>https://www.manzambi.com/writing/nsa-mcp-csi/</link><guid isPermaLink="true">https://www.manzambi.com/writing/nsa-mcp-csi/</guid><description>Notes on the NSA&apos;s May 2026 MCP Security CSI and practical defensive and adversarial work in this space.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Building a Secure-By-Design AI Agent with MCP Tools</title><link>https://www.manzambi.com/writing/secure-by-design-agentic-v1/</link><guid isPermaLink="true">https://www.manzambi.com/writing/secure-by-design-agentic-v1/</guid><description>How to spend a weekend implementing OWASP, NIST, and CSA guidance, and what I learned about where the real security boundaries live.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item></channel></rss>