Insights & Research
Vulnerability research, AI security, and field notes on compliance from the team that breaks systems so attackers can't.

CVE-2026-59822: MCP Authentication Bypass in LiteLLM
LiteLLM's MCP endpoint caught a rejected credential and continued with an anonymous session. The strict check still ran and still failed correctly. Its failure just stopped being terminal.

An Agent ID Is Not an Identity
Wazuh reissues numeric agent ids. In August, two live endpoints in different enrollments both answered to id 001. The fix is not a lookup table. It is admitting the id was never the identity.

ClawdBot Security Risks
Critical RCE vulnerabilities. Plaintext credential storage. Get the full risk breakdown and actionable protection steps for using OpenClaw

AI Security Best Practices: A Penetration Tester's Guide to Securing LLM Applications
Expert AI security practices for LLM applications. OWASP Top 10 coverage, testing methodology, and practical guidance from experienced pen-testers.

Software 3.0 In the Lens of Security
Discover key insights into what makes LLMs one of the most fascinating security products of the modern age.

Understanding LLM Interactions: A Technical Guide
Master LLM prompting basics, avoid blind prompts, and learn how system, user, and assistant modes shape model output for better, more secure results.