Archives
- 08 Sep Cosine Similarity Is Not a Safety Property
- 01 Sep The Injection That Passes Every Filter
- 29 Aug The Missing Control: A Design Proposal for Tool-Output Redaction in AI Agents
- 22 Aug Agent Identity: What the Standards Fix, and What They Leave Open
- 14 Aug What Prompt Injection Benchmarks Actually Measure
- 10 Aug Finding the Confused Deputy in Your Own Agent: A Taxonomy and Hands-On Test
- 06 Aug What 'Read-Only' Actually Reaches: The Kubernetes Permission Audit Nobody Runs
- 01 Aug The Containment Ladder: Four Rungs That Keep an AI Agent's Mistakes Small
- 28 Jul Sovereignty Isn't a Data Center. It's Who Can Be Compelled.
- 21 Jul Everything or Nothing: The Missing Middle in AI Agent Authorization
- 16 Jul Review the Reviewers: The Security Questions Behind Alberta's 466-Million-Line AI Code Scan
- 07 Jul Clearing Houses Will Win the Agent Era. They'll Also Be Its Biggest Breach
- 29 Jun I Build My Lead Magnets Like Software, Not in Canva
- 27 Jun Stop Paying Per Image: Run FLUX on a GPU You Already Own
- 25 Jun My Personal AI Agent Wakes Its Own GPU When It Needs the Power
- 23 Jun A Competitor Shipped First. It Made My Product Better.
- 20 Jun The WebGoat for Agentic AI Didn't Exist, So I Built It
- 17 Jun Deleting the Malicious MCP Server Doesn't Save You
- 12 Jun Loop Engineering on Your Own Hardware: A Practical Guide to Self-Hosted Coding Loops
- 09 Jun How to Red Team Your AI Agent Before You Ship
- 06 Jun Most teams deploying AI agents are exposed. Here's the proof.
- 05 Jun 7 AI security checks before production
- 02 Jun The Right AI Security Framework Depends on the Question You're Asking
- 28 May How a Malicious MCP Server Can Drain Your Database in 5 Steps
- 25 May 5 Ways AI Systems Break Traditional Threat Model
- 23 May AI Security in Production: A Practitioner's Guide to Threat Modeling Before You Ship
- 20 May MCP Security: One Year In — Notes from OWASP Stockholm
- 04 May The EDPB's Standard Privacy Impact Assessment Template Has Three Blind Spots for Agentic AI
- 03 May The AI Security Validation Crisis Nobody Is Talking About
- 18 Apr Qwen3.6 on 24GB VRAM: Benchmark, Config, and Every Mistake
- 13 Apr Building a Local Multi-Agent Development System
- 02 Apr RSAC 2026 Confirmed It: Agentic AI Security Is the Industry's Next Unsolved Problem
- 02 Apr When Infostealers Meet Agentic AI: The Kill Chain Security Teams Aren't Modeling
- 01 Apr AI Agents Are Widening the EU AI Act Readiness Gap
- 27 Mar RAG Poisoning and EU AI Act Article 10: Data Governance Is Not Optional for Retrieval Pipelines
- 18 Mar GPAI Meets Agentic AI: Why Your MCP Deployment Triggers EU AI Act Obligations
- 16 Mar MCP Security Top 10: A Practitioner's Threat Model
- 15 Mar RAG Stack Security: Defenses That Stop Real Attacks
- 12 Mar RAG Poisoning: How Attackers Corrupt Your AI's Knowledge Base
- 08 Mar RAG Security: Attacks, Defenses & Architecture
- 06 Mar Red Teaming Agentic AI: CISO Playbook with Checklists and Assessment Templates
- 05 Mar LLM Red Teaming Tools: PyRIT & Garak (2025 Guide)
- 04 Mar How I Deployed OpenClaw as an AI Security Researcher: A Practitioner's Guide
- 03 Mar Attacking Docker Desktop via MCP: From Theory to PoC
- 26 Feb Tool Poisoning in MCP: Hidden Instructions, Silent Exfiltration
- 25 Feb MCP's First Year: What 30 CVEs and 500 Server Scans Tell Us About AI's Fastest-Growing Attack Surface
- 24 Feb OWASP Agentic Top 10 in Practice: MCP Tool Poisoning, Cross-Server Attacks, and the DockerDash Incident
- 20 Feb Your AI Agent Just Became an Attack Surface — And Most Teams Don't Know It Yet
- 17 Feb AI Agent Evaluation: Frameworks & Metrics for Production Systems
- 02 Feb LLM Engineering Part 3, From Basic LLM App to Production SaaS MVP
- 31 Jan Build Production-Ready LLM Agents
- 26 Jan LLM-Engineering; Building a Procurements Analyst AI
- 18 Dec One-File Procurement “AI Analyst” with LLM Engineering
- 11 Jul The Hidden Security Risk in AI Integrations
- 21 May The $430,000 Kubernetes Mistake: How Security Debt Nearly Killed My Homelab (And What It Means for Your Business)
- 18 Apr Git-Based Risk Assessments: A Developer-Centric Approach to Security at Scale
- 15 Apr How you Should Deploy and Use Postgres in Kubernetes
- 05 Apr How You Should Manage Secrets in Kubernetes
- 05 Mar Building a Production-Ready Kubernetes Cluster with Infrastructure as Code and GitOps