#explainer
-
Anatomy of a Vendor Advisory: Reading What Isn't Said
Vendor advisories from AI providers follow a recognizable shape. Knowing what to look for, and what is left out, turns marketing into usable signal.
-
AI Taxonomy: Incident, Vulnerability, Disclosure, Misuse
A working taxonomy that distinguishes AI incidents, vulnerabilities, disclosures, and misuse by impact, weakness, publication, and intent.
-
NVD CVE Entries for ML Libraries: What Fields Mean
NVD entries for torch, transformers, vLLM, and LangChain are not written for ML engineers. How to read the fields and what to do when metadata is thin.
-
Reading a Model Card for Security Signals
Model cards are written for researchers, not defenders. What to read first, in what order, to judge a model's security posture and disclosure practice.